If your school filters web traffic or scans incoming email, Examplary needs a few domains let through. Otherwise you'll see tests that won't load, images that stay blank, or sign-in codes that never arrive.
This guide lists the domains to allow for web traffic and for email. Everything runs over HTTPS on port 443.
Web traffic
Required
Teachers and students need all of these. If you block any of them, part of Examplary stops working.
| Domain | What it's for |
|---|---|
examplary.ai and subdomains | The Examplary app itself |
examcdn.com | Images, attachments, uploaded files and the building blocks of each question type |
examplary.link | Links to tests |
practice.space | Links to practice spaces |
cognito-idp.eu-central-1.amazonaws.com | Signing in with an email address and password |
examplary-production-media.s3-accelerate.amazonaws.com | Uploading files, including students uploading their answers |
Optional
Examplary still works without these, but a few things will look or behave differently.
| Domain | What happens if you block it |
|---|---|
fonts.googleapis.com and fonts.gstatic.com | The app falls back to standard system fonts |
view.officeapps.live.com | Word, Excel and PowerPoint files can't be previewed |
Depending on how you use Examplary
You only need these if you use the feature in question.
| Feature | Domains to allow |
|---|---|
| Signing in with Google | accounts.google.com |
| Single sign-on | Your own identity provider, such as login.microsoftonline.com for Microsoft Entra ID |
| Entree Federatie | oidcng.entree.kennisnet.nl, plus your school's own sign-in page |
| A custom domain | Your custom domain, such as examplary.example.edu |
| Safe Exam Browser | safeexambrowser.org, to download the browser |
| Schoolyear | *.schoolyear.app |
| Muute | app.muute.com |
Examplary is embedded in your LMS, such as Canvas, through an iframe. That embed loads from the same domains listed above.
Examplary runs behind a content delivery network, and its IP addresses change without notice. Use domain names in your allowlist, never IP addresses.
Examplary sends sign-in codes, password resets, workspace invites, test invites and result notifications by email. If those emails end up in spam or quarantine, students can't sign in.
Almost every email comes from hi@examplary.ai. The easiest fix is to allow the whole examplary.ai sending domain in your email security.
All our email passes SPF, DKIM and DMARC, so you can safely allow it based on those checks.
| What | Value |
|---|---|
| Sending domain | examplary.ai |
| From addresses | hi@examplary.ai, login@examplary.ai |
| Return-path (bounces) | notifications.examplary.ai |
The sender name on most emails is your workspace's name. Invites and result notifications also name the teacher, for example "Jane Smith (via Example School)". Some filters flag this as impersonation, because it looks like a colleague's name on an outside address. If that happens, add an exception for hi@examplary.ai.
Questions we get asked a lot
Do you publish a list of IP addresses? No. Our IP addresses change without notice, so allow by domain.
Do I need to open any ports other than 443? No. Everything, including the WebSocket connection, runs over HTTPS on port 443.
Does Examplary need third-party cookies? No, not when people use the app directly. When Examplary is embedded in an LMS, it signs in with a token instead of cookies.
Something's still blocked. How do I find out what? Open the browser's developer tools on a computer on your school network, go to the Network tab and reload the page. Blocked requests show up in red. Send us what you find at hi@examplary.ai and we'll help.