This guide contains only the whitelisting instructions needed for the proper functioning of the Awareness platform (training, videos, communications).
For whitelisting related to the Phishing Simulation service (sending simulated attacks, smishing, phishing landing pages), please refer to the dedicated guide for that service.
Purpose of Whitelisting
Proper and complete whitelisting configuration is essential to ensure the full functionality of the Awareness platform. Whitelisting should also be applied to perimeter security systems such as antispam and firewalls.
Specifically, it allows you to:
- Receive functional emails (e.g., password resets) and Student Caring emails (periodic communications to encourage user participation in training programs);
- Properly access training video content and view the platform correctly, avoiding blocks, slowdowns, or restrictions caused by network filters or security tools.
1. Receiving Functional and Student Caring Communications
The platform can send two types of communications:
- Transactional emails, such as password recovery emails;
- Student Caring emails, designed to support and motivate users throughout their training journey (e.g., notifications about new modules being released).
To ensure these communications are received correctly, you need to configure the following addresses as trusted senders:
- support@libracyber.com
- no-reply@cyberguru.eu
as well as the following IP addresses:
- 159.183.238.150
- 159.183.237.241
Note: If you want to use a custom sender address (e.g., a company domain), please contact LibraCyber support for configuration (support portal).
2. Proper Access to Training Content
The following domains must be allowed to enable access to training content. This whitelisting should be applied to all systems that affect web browsing (e.g., proxy, firewall, DNS filters, endpoint security solutions).
Note: These domains are only related to web browsing and content access — they are not related to emails.
If a domain is preceded by an asterisk (e.g., *.domain.ext), you must keep the asterisk format, as it is needed to include all dynamically generated third-level subdomains from the platform. If the domain is listed without an asterisk (e.g., domain.ext), just enter that domain.
LibraCyber Domains
| Domain | Function |
| *.cyberguru.eu | Awareness platform and loading images, CSS, and other content |
| cdn.cyberguru.it | Content CDN |
| channel.cyberguru.it | Video streaming |
| drblhbunht495.cloudfront.net | Content CDN |
| d257plavcdcryb.cloudfront.net | Content CDN |
Vimeo Domains (Training Videos)
Training video content is delivered via Vimeo. To ensure proper playback, you need to allow the following domains:
| Domain | Function |
| *.vimeo.com | Vimeo player and services |
| *.vimeocdn.com | Vimeo CDN |
Additional CDN Domains (Optional)
The Vimeo player uses a multi-CDN architecture that, depending on geographic location and network conditions, may deliver video content through third-party CDNs. If you experience video playback issues after allowing the previous domains, also allow the following domains:
| Domain | Function |
| *.akamaized.net | Akamai CDN (used by Vimeo) |
| *.cloudfront.net | Amazon CloudFront CDN (used by Vimeo) |