Skip to main content
Administrator Guide
Last Updated: 2026-01-23
Concept: VNDLY Allowlisting Protocols

Concept: VNDLY Allowlisting Protocols

Email Address Allowlisting

Workday VNDLY is a multi-instance cloud hosted Vendor Management Solution (VMS). VNDLY sends email notifications to authorized users based on certain business process conditions. Example: job posting submissions, timesheet approvals, candidate submissions. These emails are sent from the following email address, which should be allowlisted in the client's corporate email system: noreply@vndly.com.
VNDLY uses DomainKeys Identified Mail (DKIM) and all emails sent by VNDLY are signed using a cryptographic key. An email message that is sent using DKIM includes a DKIM-Signature header field that contains a cryptographically signed representation of the message. A provider that receives the message can use a public key, published in VNDLY's DNS record, to decode the signature. This DNS entry is referenced in the selector record of the DKIM-Signature header. Email providers then use this information to determine whether messages are authentic.

IP Allowlisting

Allowing designated IPs isn’t the recommended method to prevent internet traffic intended for VNDLY from being hijacked or rerouted to a rogue website. VNDLY doesn’t recommend allowlisting because when IPs are added to changes, customers can experience connection interruptions until they update their allowlist databases.
Ingress - VNDLY connecting to client
These IPs are for customers who need to allowlist inbound (ingress) connections from VNDLY servers. Note:
  • If you’re using allowlists for Production 1, please ensure the IP addresses for Production 2 are also included in case a disaster recovery event is needed.
  • If you’re using allowlists for Production 3, please ensure the IP addresses for Production 4 are also included in case a disaster recovery event is needed.
Production 1 (AWS Oregon - US West 2)
  • 52.43.6.70
  • 34.214.224.40
  • 54.188.53.91
  • 35.164.22.135
  • 44.226.63.81
  • 34.217.1.184
Production 2 (AWS Ohio - US East 2)
  • 3.13.20.176
  • 13.59.151.166
  • 18.191.14.169
  • 3.14.208.12
  • 18.190.60.168
  • 3.132.229.237
Production 3 (AWS UK - EU West 2)
  • 18.130.90.0
  • 35.177.199.103
  • 13.41.234.8
  • 18.132.87.198
  • 18.135.213.44
  • 18.168.102.162
Production 4 (AWS Ireland - EU West 1)
  • 52.50.126.26
  • 54.72.135.73
  • 52.214.255.110
Production 5 (AWS Frankfurt - EU Central 1)
  • 3.121.250.19
  • 3.122.70.56
  • 52.59.46.163
Production 6 (AWS Ireland - EU West 1)
  • 34.248.108.93
  • 54.229.189.172
  • 63.32.187.152
Egress - Client Connecting to Workday VNDLY
IPs for customers to need to allowlist outbound (egress) connectors to Workday VNDLY servers:
Endpoint
Public IP
Cryptographic Algorithms
sftp.vndly.com
(US)
52.12.202.235
44.235.231.104
44.233.130.213
3.131.132.136
52.15.179.5
3.13.183.7
Key Types:
  • rsa
  • ecdsa
Host Keys:
  • ssh-rsa
  • rsa-sha2-256
  • rsa-sha2-512
  • ecdsa-sha2-nistp256
  • ecdsa-sha2-nistp384
  • ecdsa-sha2-nistp521
  • ssh-ed25519
SshCiphers:
  • aes128-ctr
  • aes192-ctr
  • aes256-ctr
  • aes128-gcm@openssh.com
  • aes256-gcm@openssh.com
SshKexs:
  • curve25519-sha256
  • curve25519-sha256@libssh.org
  • ecdh-sha2-nistp256
  • ecdh-sha2-nistp384
  • ecdh-sha2-nistp521
  • diffie-hellman-group-exchange-sha256
  • diffie-hellman-group16-sha512
  • diffie-hellman-group18-sha512
  • diffie-hellman-group14-sha256
  • diffie-hellman-group14-sha1
SshMacs:
  • umac-64-etm@openssh.com
  • umac-128-etm@openssh.com
  • hmac-sha2-256-etm@openssh.com
  • hmac-sha2-512-etm@openssh.com
  • hmac-sha1-etm@openssh.com
  • umac-64@openssh.com
  • umac-128@openssh.com
  • hmac-shad2-256
  • hmac-sha2-512
  • hmac-sha1
sftp-dc1a.vndly.com
(US)
44.230.63.7
54.69.232.73
52.34.210.82
Key Types:
  • rsa
  • ecdsa
Host Keys:
  • rsa-sha2-256
  • rsa-sha2-512
  • ecdsa-sha2-nistp256
  • ecdsa-sha2-nistp384
  • ecdsa-sha2-nistp521
  • shh-ed25519
SshCiphers:
  • aes128-gcm@openssh.com
  • aes192-ctr
  • aes256-ctr
  • aes256-gcm@openssh.com
SshKexs:
  • curve25519-sha256
  • curve25519-sha256@libssh.org
  • diffie-hellman-group16-sha512
  • diffie-hellman-group18-sha512
  • diffie-hellman-group-exchange-sha256
SshMacs:
  • hmac-sha2-256
  • hmac-sha2-256-etm@openssh.com
  • hmac-sha2-512
  • hmac-sha2-512-etm@openssh.com
sftp-uk.vndly.com
(UK)
18.134.78.80
18.132.253.240
18.135.142.203
54.194.254.236
52.48.198.217
54.217.252.123
Key Types:
  • rsa
  • ecdsa
Host Keys:
  • ssh-rsa
  • rsa-sha2-256
  • rsa-sha2-384
  • ecdsa-sha2-nistp256
  • ecdsa-sha2-nistp384
  • ecdsa-sha2-nistp521
  • ssh-ed25519
SshCiphers:
  • aes128-ctr
  • aes192-ctr
  • aes256-ctr
  • aes128-gcm@openssh.com
  • aes256-gcm@openssh.com
SshKexs:
  • curve25519-sha256
  • curve25519-sha256@libssh.org
  • ecdh-sha2-nistp256
  • ecdh-sha2-nistp384
  • ecdh-sha2-nistp521
  • diffie-hellman-group-exchange-sha256
  • diffie-hellman-group16-sha512
  • diffie-hellman-group18-sha512
  • diffie-hellman-group14-sha256
  • diffie-hellman-group14-sha1
SshMacs:
  • umac-64-etm@openssh.com
  • umac-128-etm@openssh.com
  • hmac-sha2-256-etm@openssh.com
  • hmac-sha2-512-etm@openssh.com
  • hmac-sha1-etm@openssh.com
  • umac-64@openssh.com
  • hmac-sha2-256
  • hmac-sha2-512
  • hamc-sha1
sftp-dc2a.vndly.com
(UK)
3.10.240.72
18.170.175.172
35.176.210.71
Key Types:
  • rsa
  • ecdsa
Host Keys:
  • rsa-sha2-256
  • rsa-sha2-512
  • ecdsa-sha2-nistp256
  • ecdsa-sha2-nistp384
  • ecdsa-sha2-nistp521
  • ssh-ed25519
SshCiphers:
  • aes128-gcm@opensh.com
  • aes192-ctr
  • aes256-ctr
  • aes256-gcm@openssh.com
SshKexs:
  • curve25519-sha256
  • curve25519-sha256@libssh.org
  • diffie-hellman-group16-sha512
  • diffie--hellman-group18-sha512
  • diffie-hellman-group-exchange-sha256
SshMacs:
  • hmac-sha2-256
  • hmac-sha2-256-etm@openssh.com
  • hmac-sha2-512
  • hmac-sha2-512-etm@openssh.com
sftp-eu-dc3.vndly.com
(Germany)
3.77.99.81
3.76.232.251
18.193.188.83
52.19.97.205
34.249.104.180
52.208.210.45
Key Types:
  • rsa
  • ecdsa
Host Keys:
  • ssh-rsa
  • rsa-sha2-256
  • rsa-sha2-512
  • ecdsa-sha2-nistp256
  • ecdsa-sha2nistp384
  • ecdsa-sha2-nistp521
  • ssh-ed25519
SshCiphers:
  • aes128-ctr
  • aes192-ctr
  • aes256-ctr
  • aes128-gcm@openssh.com
  • aes256-gcm@openssh.com
SshKexs:
  • curve25519-sha256
  • curve25519-sha256@libssh.org
  • ecdh-sha2-nistp256
  • ecdh-sha2-nistp384
  • ecdh-sha2-nistp521
  • diffie-hellman-group-exchange-sha256
  • diffie-hellman-group16-sha512
  • diffie-hellman-group18-sha512
  • diffie-hellman-group14-sha256
  • diffie-hellman-group14-sha1
SshMacs:
  • umac-64-etm@openssh.com
  • umac-128-etm@openssh.com
  • hmac-sha2-256-etm@openssh.com
  • hmac-sha2-512-etm@openssh.com
  • hmac-sha1-etm@openssh.com
  • umac-64@openssh.com
  • umac-128@opensh.com
  • hmac-sha2-256
  • hmac-sha2-512
  • hmac-sha1
sftp-dc3a.vndly.com
(Germany)
18.197.166.31
18.194.57.30
3.78.65.231
Key Types:
  • rsa
  • ecdsa
Host Keys:
  • rsa-sha2-256
  • rsa-sha2-512
  • ecdsa-sha2-nistp256
  • ecdsa-sha2-nistp384
  • ecdsa-sha2-nistp521
  • ssh-ed25519
SshCiphers:
  • aes128-gcm@openssh.com
  • aes192-ctr
  • aes256-ctr
  • aes256-gcm@openssh.com
SshKexs:
  • curve25519-sha256
  • curve25519-sha256@libssh.org
  • diffie-hellman-group16-sha512
  • diffie-hellman-group18-sha512
  • diffie-hellman-group-exchange-sha256
SshMacs:
  • hmac-sha2-256
  • hmac-sha2-256-etm@openssh.com
  • hmac-sha2-512
  • hmac-sha2-512-etm@openssh.com
[tenant].vndly.com
VNDLY uses AWS Cloudfront, which means all Cloudfront IPs need to be allowlisted. This process is documented on Amazon's website.
Please contact the Workday VNDLY Product Support team Monday through Friday 7:00 AM ET to 7:00 PM ET, with additional questions or concerns.