Start your 7-day free trial, card not charged until it ends

For your hosting provider

Allowlist our scanners

If TLDTrack reports your site as down or your security scan is incomplete, your host or security software is likely blocking us. Allowlist the IPs below so our checks get through.

01 · Allowlist

Our IP addresses

Required for monitoring

18.168.0.190

Uptime monitoring from London. Only sends GET requests; never scanner-shaped traffic.

Recommended

35.178.155.62

TLDTrack dashboard server. Runs content checks and a confirming check before a downtime alert goes out. This address can change; if it does, we update this page.

Optional

18.135.126.230

Security scanner. Sends WPScan + Nuclei + ZAP traffic. Only allowlist if you want our security scans to work; uptime monitoring does NOT use this IP anymore.

The uptime IP is separate from the scanner IP, so if your firewall flags our scanner, uptime monitoring keeps working. Some checks run from AWS addresses that change between runs: the US East and Singapore uptime confirmations, visual captures and journey tests.

02 · How-tos

Common blockers and how to fix them

Imunify360

Default on many LiteSpeed / cPanel hosts. Most common cause.

WHM (GUI):

  1. WHM → Plugins → Imunify360
  2. Click Incidents tab, find any entries with IP 18.135, 18.168 or 35.178, click the IP and choose Allowlist
  3. Then go to Firewall → Allowlist and add all three IPs manually

CLI (SSH as root):

imunify360-agent ip-list local add --ip 18.168.0.190   --comment "TLDTrack uptime"
imunify360-agent ip-list local add --ip 35.178.155.62 --comment "TLDTrack dashboard"
imunify360-agent ip-list local add --ip 18.135.126.230 --comment "TLDTrack scanner"

ConfigServer Firewall (CSF)

Ships with most cPanel / DirectAdmin servers.

WHM (GUI):

  1. WHM → Plugins → ConfigServer Security & Firewall
  2. Quick Allow: paste each IP, add reason "TLDTrack", click Quick Allow

CLI (SSH as root):

csf -a 18.168.0.190   "TLDTrack uptime"
csf -a 35.178.155.62 "TLDTrack dashboard"
csf -a 18.135.126.230 "TLDTrack scanner"
csf -r

LiteSpeed Web Server / LiteSpeed Cache

Bot detection or IP throttle may block our user-agents.
  1. WHM/cPanel → LiteSpeed Web Cache Manager → IP Throttle → add IPs to allowlist
  2. Or edit /usr/local/lsws/conf/httpd_config.conf, find the accessControl block, and add:
    allow 18.168.0.190, 35.178.155.62, 18.135.126.230
  3. Reload: systemctl reload lsws

Wordfence (WordPress)

Blocks scanners that hit wp-login or /?author=N enumeration.
  1. WP Admin → Wordfence → Tools → Diagnostics → search for "18.135", "18.168", or "35.178" and unblock any matches
  2. Wordfence → All Options → "Allowlisted IP Addresses that will bypass all rules" → paste all three IPs, save

Solid Security (formerly iThemes Security)

Blocks repeat-offender IPs from scanning.
  1. WP Admin → Solid Security → Settings → Lockouts → remove any 18.135 / 18.168 / 35.178 lockouts
  2. Then → Settings → Allowlist → add all three IPs

Cloudflare

Use a WAF skip rule. Bot Fight Mode silently challenges our requests.
  1. Cloudflare Dashboard → pick your site → Security → WAF → Custom rules
  2. Create rule: When incoming requests match...
    (ip.src eq 18.168.0.190) or (ip.src eq 35.178.155.62) or (ip.src eq 18.135.126.230)
  3. Action: Skip → tick "All remaining custom rules", "All managed rules", "Rate limiting rules", "Bot Fight Mode"
  4. Deploy. The rule should be at the top of the list.

Sucuri

Cloud WAF blocks bot user-agents by default.
  1. Sucuri Dashboard → pick site → Access Control → Whitelist IP Addresses
  2. Paste each IP and add comment "TLDTrack", save

Plain Linux firewall (iptables / nftables)

For self-managed VPS without a control panel.
# iptables (insert at top of INPUT chain)
iptables -I INPUT -s 18.168.0.190   -j ACCEPT
iptables -I INPUT -s 35.178.155.62 -j ACCEPT
iptables -I INPUT -s 18.135.126.230 -j ACCEPT

# UFW (Ubuntu)
ufw allow from 18.168.0.190
ufw allow from 35.178.155.62
ufw allow from 18.135.126.230

# firewalld (RHEL/Rocky/Alma)
for ip in 18.168.0.190 35.178.155.62 18.135.126.230; do
  firewall-cmd --permanent --add-rich-rule="rule family=ipv4 source address=$ip accept"
done
firewall-cmd --reload

fail2ban

Common reason for transient timeouts and TCP resets.

Edit /etc/fail2ban/jail.local and append to the [DEFAULT] section:

ignoreip = 127.0.0.1/8 ::1 18.168.0.190 35.178.155.62 18.135.126.230

Then systemctl restart fail2ban

How to confirm it worked

  • In TLDTrack, if the domain page shows a Monitoring limited notice, use its Test connectivity now button to re-test from our servers.
  • Click Run security scan and the pre-flight readiness checklist should show all checks passing.
  • Or from anywhere: curl -s -o /dev/null -w "%{http_code}" -A "Mozilla/5.0 (compatible; TLDTrack-Uptime/2.0; +https://tldtrack.com/uptime)" https://your-domain/ - should print 200 or a 3xx redirect.

Still seeing blocks after allowlisting? Get in touch and we'll help debug.