All help topics
Account and securityBusiness and up

Restrict sign-in and access by IP address

Paste the CIDR ranges your team works from and block sign-in, documents, templates and settings from everywhere else. Workspace admins always keep access, so a typo cannot lock the workspace out of its own settings.

Updated Open in app

An IP allowlist limits your workspace to the networks you name. Sign-in, documents, templates and settings all refuse from anywhere else, so a stolen password is useless from a coffee shop. Find the setting at Settings > Advanced features > IP restrictions, under Signing security.

Who can do this

Workspace admins, on Business and above. Admins also bypass the rule once it's live. A mistyped range can't lock your whole team out of its own settings.

Build your IP allowlist

  1. Open Settings > Advanced features and click IP restrictions.

  2. Switch on Enforce IP allowlist.

  3. Paste your ranges into Allowlist (one CIDR per line), one per line. IPv4 and IPv6 both work, up to two hundred entries.

    The IP restrictions page with the allowlist textarea highlighted

  4. Under Current request IP you can see the address this browser is coming from. Add to allowlist appends it as a single-host range, which saves reading it off and typing it wrong.

  5. Leave Also restrict signer access off unless your signers genuinely sit inside the same network. Switching it on means an external recipient outside the allowlist can't open a signing link at all.

  6. Click Save IP allowlist, read the summary, then Apply restrictions.

    The confirmation dialog listing the approved networks before restrictions are applied

Read that confirmation instead of clicking straight through it. It counts the approved networks, repeats them back, and warns you outright when your own address is missing from the list you're about to apply.

How not to lock your team out of the IP allowlist

  • Add your office ranges before you switch enforcement on. Use Add to allowlist from a machine on the network you want to approve, so you're not trusting a number somebody read out over a call.
  • If your team works through a VPN, allowlist the VPN exit addresses. That's the address we see. The laptop's own address never reaches us.
  • Keep home broadband off the list. A dynamic address changes every few weeks, and allowlisting one member's house becomes a support ticket. Route remote people through the VPN.

The admin bypass only helps while an admin can reach the workspace. One admin who is traveling means nobody is left to repair the list, so keep at least two admins.

An allowlist only answers where somebody is signing in from. Pair it with workspace-wide two-factor if you also want proof of who they are.

What a blocked IP address sees

Members outside the list are refused as soon as the rule saves. The app shows Your IP address is not permitted to access this workspace. Sign-in itself, the account lookup that renders the app shell and workspace switching all keep working, so somebody who belongs to a second workspace can still move to it.

With signer restriction on, a recipient outside the list who opens their link is told Signing is restricted to approved networks for this workspace.

Every refusal is recorded in the workspace activity log. A burst of blocks after a network change is easy to spot.

If something goes wrong

  • "Line 3: invalid CIDR" and friends. A line is not valid CIDR notation. Remember the suffix: a bare address needs /32 for IPv4, /128 for IPv6.
  • Save IP allowlist stays grayed out. Enforcement is on with an empty list, or a line is still invalid. Fix the flagged lines or add a range.
  • A member is blocked from a network you thought was allowed. Check the address they actually come out on, which is often an office NAT or a VPN exit.
  • Signers report they cannot open their links. Also restrict signer access is on. Turn it off unless you meant it.
  • You want it off after a downgrade. Switch Enforce IP allowlist off and save. Disabling always works, whatever your plan.
FAQ

Frequently asked questions

Can I lock myself out with a bad allowlist?

Not as an admin. Every workspace admin bypasses the rule on purpose, so you can always reach this page and repair the list even when your own address is nowhere in it. Non-admin members have no such escape. The confirmation dialog warns you when your current IP is missing from the list.

What can a blocked member still do?

Almost nothing. Sign-in, the account lookup behind the app shell and workspace switching stay open so the person is not trapped on a broken screen, but documents, templates and settings all refuse. They see **Your IP address is not permitted to access this workspace.**

Should I turn on the signer option?

Only when every signer really is inside your network, which is rare. Customers and counterparties sign from home broadband and phones, so extending the rule to signing links usually means nobody can open the documents you send. It is off by default for that reason.

How many ranges can the list hold?

Up to two hundred entries, IPv4 and IPv6 mixed freely, one per line. Use /32 to name a single IPv4 address and /128 for a single IPv6 one. Anything that is not valid CIDR notation is flagged with its line number before you can save.

What happens if we downgrade our plan?

An existing allowlist keeps enforcing, and you can always switch it off regardless of plan. That is deliberate, because an office moving to a new IP after a downgrade should never become a permanent lockout. Turning it back on again needs the entitlement.

Does this replace two-factor authentication?

No, and the two work well together. An allowlist says where somebody may sign in from. Two-factor says who they have to prove they are. Networks change and addresses can be spoofed, so an allowlist is one boundary in your access control. Never treat it as the whole.

Related

Keep going

Did not find what you needed?Send us a message