Concept: VNDLY Allowlisting Protocols
Email Address Allowlisting
Workday VNDLY is a multi-instance cloud hosted Vendor Management Solution (VMS). VNDLY sends email notifications to authorized users based on certain business process conditions. Example: job posting submissions, timesheet approvals, candidate submissions. These emails are sent from the following email address, which should be allowlisted in the client's corporate email system: noreply@vndly.com.
VNDLY uses DomainKeys Identified Mail (DKIM) and all emails sent by VNDLY are signed using a cryptographic key. An email message that is sent using DKIM includes a DKIM-Signature header field that contains a cryptographically signed representation of the message. A provider that receives the message can use a public key, published in VNDLY's DNS record, to decode the signature. This DNS entry is referenced in the selector record of the DKIM-Signature header. Email providers then use this information to determine whether messages are authentic.
IP Allowlisting
Allowing designated IPs isn’t the recommended method to prevent internet traffic intended for VNDLY from being hijacked or rerouted to a rogue website. VNDLY doesn’t recommend allowlisting because when IPs are added to changes, customers can experience connection interruptions until they update their allowlist databases.
Ingress - VNDLY connecting to client
These IPs are for customers who need to allowlist inbound (ingress) connections from VNDLY servers. Note:
- If you’re using allowlists for Production 1, please ensure the IP addresses for Production 2 are also included in case a disaster recovery event is needed.
- If you’re using allowlists for Production 3, please ensure the IP addresses for Production 4 are also included in case a disaster recovery event is needed.
Production 1 (AWS Oregon - US West 2)
- 52.43.6.70
- 34.214.224.40
- 54.188.53.91
- 35.164.22.135
- 44.226.63.81
- 34.217.1.184
Production 2 (AWS Ohio - US East 2)
- 3.13.20.176
- 13.59.151.166
- 18.191.14.169
- 3.14.208.12
- 18.190.60.168
- 3.132.229.237
Production 3 (AWS UK - EU West 2)
- 18.130.90.0
- 35.177.199.103
- 13.41.234.8
- 18.132.87.198
- 18.135.213.44
- 18.168.102.162
Production 4 (AWS Ireland - EU West 1)
- 52.50.126.26
- 54.72.135.73
- 52.214.255.110
Production 5 (AWS Frankfurt - EU Central 1)
- 3.121.250.19
- 3.122.70.56
- 52.59.46.163
Production 6 (AWS Ireland - EU West 1)
- 34.248.108.93
- 54.229.189.172
- 63.32.187.152
Egress - Client Connecting to Workday VNDLY
IPs for customers to need to allowlist outbound (egress) connectors to Workday VNDLY servers:
Endpoint | Public IP | Cryptographic Algorithms |
|---|---|---|
sftp.vndly.com (US) | 52.12.202.235
44.235.231.104 44.233.130.213 3.131.132.136 52.15.179.5 3.13.183.7 | Key Types:
Host Keys:
SshCiphers:
SshKexs:
SshMacs:
|
sftp-dc1a.vndly.com (US) | 44.230.63.7
54.69.232.73 52.34.210.82 | Key Types:
Host Keys:
SshCiphers:
SshKexs:
SshMacs:
|
sftp-uk.vndly.com (UK) | 18.134.78.80
18.132.253.240 18.135.142.203 54.194.254.236 52.48.198.217 54.217.252.123 | Key Types:
Host Keys:
SshCiphers:
SshKexs:
SshMacs:
|
sftp-dc2a.vndly.com (UK) | 3.10.240.72
18.170.175.172 35.176.210.71 | Key Types:
Host Keys:
SshCiphers:
SshKexs:
SshMacs:
|
sftp-eu-dc3.vndly.com (Germany) | 3.77.99.81
3.76.232.251 18.193.188.83 52.19.97.205 34.249.104.180 52.208.210.45 | Key Types:
Host Keys:
SshCiphers:
SshKexs:
SshMacs:
|
sftp-dc3a.vndly.com (Germany) | 18.197.166.31
18.194.57.30 3.78.65.231 | Key Types:
Host Keys:
SshCiphers:
SshKexs:
SshMacs:
|
[tenant].vndly.com | VNDLY uses AWS Cloudfront, which means all Cloudfront IPs need to be allowlisted. This process is documented on Amazon's website. |
Please contact the Workday VNDLY Product Support team Monday through Friday 7:00 AM ET to 7:00 PM ET, with additional questions or concerns.