Adobe hosted domains:
- *.adobe.com
- *.adobe.io
- *.adobecc.com
- *.adobecces.com
- *.adobeccstatic.com
- *.adobedtm.com
- *.adobeexchange.com
- *.adobegenuine.com
- *.adobegov.com
- *.adobe-identity.com
- *.adobejanus.com
- *.adobelogin.com
Read on to find URLs and domains that must be accessible on ports 80 and 443 for relevant Adobe applications and services to function correctly.
If you are looking for a minimum set of domains to be allowed, allowing the following top-level domains will get you going:
Adobe hosted domains:
Amazon Web Services:
Other third-party domains:
Read on to find exhaustive lists of fully qualified domain names that are required to run specific Adobe services.
You can download the complete list of fully qualified URLs and domains here.
The downloaded file has the timestamp in its name. So each time you download it, you can save the file and use it later to compare it (using any file comparison tool) to a newer version. The comparison will give you a list of domains that Adobe has added or removed.
Following is how you can compare two files to know what has changed:
When you notice a change in the last updated date of the page (mentioned below the page title at the top of the page), download the list again.
The downloaded files have a timestamp in their names.
Use a file comparison tool (like Notepad++) to compare the latest file with the one you used or referred to last.
The difference you see between the two files is what has changed since you last downloaded the allowlist. Domains that are not present in the previously downloaded file, consider adding them to your allowlist.
You may also consider removing or disallowing any domains that Adobe has removed from this list.
If you maintain your own certificate store, ensure it is updated with the latest Amazon Root CAs. Learn more here.
The matrix is arranged by:
Licensing-activation services:
Deployment and fulfillment services:
Adobe-hosted authentication services:
Additional Services used for Adobe IDs:
Adobe Genuine Integrity Service:
Adobe Application Manager:
Sign in user experience:
Updater:
Adobe uses the Secure Websocket protocol (WSS) over HTTPS for connection with adobe.io. Also, the network proxy should allow the Secure WebSocket negotiation headers that are prefixed with Sec-WebSocket*”.
For a list of domains that you must allow for Acrobat, see here.
Click the required Adobe-hosted service to see the domains you must allow:
Applies to: Photoshop
Applies to: Illustrator
Applies to: Adobe Firefly API
Applies to: Illustrator beta
Applies to: Photoshop beta
Applies to: Adobe Stock
Adobe domains:
as.ftcdn.net
Adobe uses the Secure Websocket protocol (WSS) over HTTPS for connection with adobe.io. Also, the network proxy should allow the Secure WebSocket negotiation headers that are prefixed with Sec-WebSocket*”.
Non-adobe domains:
Applies to: After Effects, Dreamweaver, Illustrator, InDesign, Muse, Photoshop, Premiere Pro, Adobe XD
Applies to: After Effects, Illustrator, InDesign, Photoshop, Premiere Pro, Adobe XD
Library Services have a dependency on Adobe Stock Services.
Applies to: After Effects, Illustrator, InDesign, Photoshop, Premiere Pro
Applies to: After Effects, Dreamweaver, Illustrator, InDesign, Muse, Photoshop, Premiere Pro
Applies to: All
Applies to: Adobe Audition, Dreamweaver, Flash, Professional, Illustrator, InCopy, InDesign, Lightroom, Muse, Photoshop, Prelude, Premiere Pro
Applies to: All
Licensing services for desktop applications that use activation services |
|
Services used for registering Adobe IDs that are delegated product |
|
Required by Adobe Application Manager |
|
The site for IT Staff to administer Adobe Enterprise IDs and Creative Cloud for enterprise entitlements |
|
Required by Adobe Genuine Integrity Service |
|
Applies to: After Effects, Premiere Pro, Prelude, Adobe Media Encoder
Applies to: Premiere Pro
Applies to: Photoshop, Behance
Applies to: Lightroom
Applies to: Photoshop
Applies to: Photoshop
Click the required browser-based service to see the list of domains you must allow:
Applies to: All
Applies to: After Effects, Illustrator, InDesign, Photoshop, Premiere Pro, Adobe Bridge
Applies to: Creative Cloud Desktop, Illustrator, InDesign, Photoshop
Applies to: Premiere Pro, Prelude
Applies to: Dreamweaver
Applies to: Creative Cloud Desktop, After Effects, Dreamweaver, Illustrator, InDesign, Muse, Photoshop, Premiere Pro
Applies to: Dreamweaver, Muse
Applies to: InDesign
Applies to: Photoshop, Illustrator, InDesign, After Effects, Flash Pro
To allow access to Frame.io app on the web, or through integrations (such as with Adobe Premiere Pro, After Effects):
*.frame.io |
Frame.io Services |
*.f.io |
|
frameio-assets.s3.amazonaws.com |
Frame.io Uploaded Media & Content |
frameio-application-production.s3-accelerate.amazonaws.com |
|
frameio-assets-production.s3-accelerate.amazonaws.com |
|
frameio-uploads-production.s3-accelerate.amazonaws.com |
If you're unable to allow *.frame.io, you may individually allow the following:
accounts.frame.io |
Authentication Portal |
activate.frame.io |
tvOS Activation Page |
api.frame.io |
Frame.io API |
app.frame.io |
Frame.io Web Application |
applications.frame.io |
OAuth Apps (3rd-party integrations) |
assets.frame.io |
Asset CDN URL |
drm.frame.io |
DRM Proxy Service |
developer.frame.io |
Developer Site |
external-assets.frame.io |
External Assets |
forensic-support.frame.io |
Forensic Watermarking API |
picture.frame.io |
Dynamic Imaging Service |
picture2.frame.io |
New Dynamic Imaging Service |
playback.frame.io |
Video Quality Metrics Service |
preview.frame.io |
Multipage URL |
socket.frame.io |
Websocket for Real-time Notifications |
sockets.frame.io |
Websocket for Real-time Notifications |
sso.frame.io |
SSO Path |
static-assets.frame.io |
Static Assets |
stream.frame.io |
Streaming Service (Watermark/HLS) |
stream-x86.frame.io |
New Streaming Service |
stream-download.frame.io |
Streaming Download Service |
support.frame.io |
Support Site |
transferapp.frame.io |
Transfer App |
translate.frame.io |
Comment Export Service |
us-east-1.edge.arcade.frame.io | Storage Connect Service |
Consider allowing the following external providers in order to utilize certain functions such as product integrations, in-app support chat, analytics, product tours, and application monitoring:
fast.appcues.com |
Product Tours, Announcements, and NPS Surveys |
api.appcues.net |
|
my.appcues.com |
|
d24n15hnbwhuhn.cloudfront.net |
Cloudfront CDN |
google-analytics.com |
Analytics Provider |
js.intercomcdn.com |
In-app Support Chat Provider |
widget.intercom.io |
|
static.intercomassets.com |
|
nexus-websocket-a.intercom.io |
|
nexus-websocket-b.intercom.io |
|
checkout.stripe.com |
Payment Processing for Retail Plans |
js.stripe.com |
|
m.stripe.network |
|
cdn.segment.io |
Analytics Provider |
api.segment.io |
|
sentry.io |
Application Monitoring |
vimeo.com |
Publish to Vimeo Integration |
dropbox.com |
Publish to Dropbox Integration |
These domains can be accessed by one or more of the Creative Cloud creative applications. They are optionally included to complement a user’s experience with Creative Cloud.
Many of the domains listed above use geography-specific aliases or IP addresses. Ensure that your firewall supports aliases.
Also, Adobe services are hosted redundantly across several servers in different regions. These hosts are subject to change for various reasons, such as system load. We do not recommend the use of IP addresses for allowing or blocking access. The IP addresses will likely be incorrect quickly after implementation - potentially within hours. In addition, the IP address information will vary depending on geographical location, and any records used will be incorrect from another location.
If you have any questions or observations about the topics, concepts, or procedures described in this article, join the discussion.