To ensure uStudio functions reliably within your organization, several network and security settings should be configured before rollout. These settings allow users to access the platform, authenticate successfully, receive email notifications, and consume content without interruption.
Most organizations complete these tasks once during application deployment.
Without proper whitelisting, users may experience:
- Issues loading audio, video, or live streams
- Login or authentication failures
- Broken or inaccessible content links
- Missing email notifications (invites, new content, digests)
| IN THIS ARTICLE |
|---|
Allowing uStudio Network Traffic
Why this is required
uStudio relies on several cloud services to deliver audio and video content, authenticate users, upload media, and provide administrative tools. Your organization's network must allow users to communicate with these services for uStudio to function correctly.
Without these exceptions, users may experience:
- Content that will not load
- Login or authentication failures
- Live streaming issues
- Upload failures
- Missing images or application resources
Who typically completes this work
Network Engineering or Information Security
Where this work is performed
Within your organization's network security controls that manage access to external internet services (e.g., firewall, proxy, secure web gateway, or other network security infrastructure)
Standard configuration
For most organizations, allowing the following domains is sufficient:
- ustudio.com or *.ustudio.com
- *.ustudiopages.com
- ustudioinc.auth0.com:443 (audience authentication)
- reports.crashlytics.com (support & diagnostics)
- app-measurement.com (support & diagnostics)
- e.crashlytics.com (support & diagnostics)
- settings.crashlytics.com (support & diagnostics)
If these are not allowed, the platform will not function correctly.
Advanced configuration (for restricted environments)
Some organizations prefer to allow only specific endpoints instead of all subdomains. If your organization follows this approach, whitelist the services below.
| Domain | Purpose |
| app.ustudio.com | Hub: admin tool for managing players |
| podcast-admin.ustudio.com | Management console: admin tool for managing podcasts |
| podcast-web.ustudio.com | Web app for audience content consumption |
| podcast-api.ustudio.com:443 | Core podcast API the platform is built on |
| podcast-configurations.ustudio.com:443 | Podcast configuration endpoint |
| progressive-cdn.ustudio.com | Progressive content delivery |
| secure-progressive-cdn.ustudio.com:443 | Secured progressive content delivery |
| adaptive-cdn.ustudio.com | Adaptive content delivery |
| live-streaming.ustudio.com | Live streaming endpoint |
| secure-live-streaming.ustudio.com:443 | Secured live streaming endpoint |
| live-events-app.ustudio.com | Podcast Live endpoint |
| rtmp-ingest-a.ustudio.com / rtmp-ingest-b.ustudio.com (ports 1935 or 443 for RTMPS) | Live streaming ingest endpoints |
| auth.ustudio.com:443 | Player SSO authentication |
| player-sso.ustudio.com | SSO player endpoint |
| ustudioinc.auth0.com:443 | Audience authentication |
| upload-app-01 through upload-app-24.ustudio.com | Content upload buckets |
| sftp.ustudio.com:22 | Optional SFTP content upload |
| poster-images.ustudio.com:443 | Content artwork |
| stats.ustudio.com | Analytics ingest |
| metadata-file-fields.ustudio.com | Platform metadata file fields |
| embed.ustudio.com | Platform embeds |
| authorized-embed.ustudio.com | Secured platform embeds |
| player-resources.ustudio.com:443 | Player resources |
| player-themes.ustudio.com | Player themes |
| playground.ustudio.com | Player editor |
| static.ustudio.com | Static resources |
|
Domains: noreply@ustudio.com and notifications@ustudio.com Sender: o1.app-mail.ustudio.com IP: 198.37.150.35 |
Email notifications |
Allowing Content Embedding
Why this is required
Show and episode embeds allow users to listen to or watch content directly within the applications they already use, eliminating the need to switch between systems while preserving the same analytics and engagement reporting available in the uStudio app.
Creating an embed is a light lift for administrators. In most cases, it is as simple as copying an embed code from the uStudio Management Console and pasting it into the destination application. Organizations commonly embed uStudio content into SharePoint, Salesforce, learning management systems (LMS), sales enablement platforms, and other internal business applications to significantly increase the visibility and reach of their content.
Many business applications restrict which external domains are permitted to provide embedded content as part of their security model. The administrator of the destination application may need to allow uStudio as a trusted source for embedded content.
Who typically completes this work
The administrator of the destination application
Where this work is performed
Within the configuration or security settings of the application where you plan to embed uStudio content (e.g., SharePoint, Salesforce, or your learning management system)
Required configuration
Allow the following domains:
- player-sso.ustudio.com
- authorized-embed.ustudio.com
- embed.ustudio.com
If these are blocked, embedded players will not load.
Allowing Email Traffic
Why this is required
uStudio uses email to help employees get started with the platform and stay informed about new content.
Most organizations use email security tools to protect employees from unwanted or malicious email. To ensure uStudio emails are delivered reliably, your email administrators should configure uStudio as a trusted sender. Otherwise, important emails may be delivered to spam or quarantine folders—or blocked before they reach users.
Who typically completes this work
Email Administrator or Messaging Team
Where this work is performed
Within your organization's email system or email security platform
Required configuration
Allow emails sent from:
- From address: noreply@ustudio.com
- Sender domain: o1.app-mail.ustudio.com
- Sender IP: 198.37.150.35
After configuration, verify delivery by following the Email Testing Guide.
Ensuring Links Open in the uStudio App
One of the easiest ways to increase engagement is to remove unnecessary steps between an email notification and the content it promotes. uStudio content links are designed to take users directly into the app when it's installed, making it quick and easy to access the content you've shared.
Some organizations use email security tools that rewrite links before they are delivered. While these tools improve security, they can unintentionally disrupt this experience. A modified link may open in a web browser or prompt users to download the app instead of launching the installed uStudio app. Adding friction at this high-intent moment can reduce engagement by causing users to abandon the journey before they reach the content.
To ensure uStudio content links work properly, your email or security IT team should add exceptions to any security tools that rewrite, scan, or proxy URLs.
Who typically completes this work
Email Administrator or Security Team
Where this work is performed
Email security platforms such as Microsoft Defender for Office 365 Safe Links, Proofpoint URL Defense, Mimecast URL Protect, and similar URL protection services.
Required configuration
Create an exception for your organization's uStudio link domain:
- companycode.podcast-links.ustudio.com:443 (replace with your company code)
After configuration, verify link behavior by following the Email Testing Guide.


