School networks filter the web, and they should. But a filter that has never heard of Nurture can quietly break it: a tab in Teams or Canvas that stays blank, a Signal session that never loads for students, or a join screen that spins forever on student devices while working fine on staff Wi-Fi.
This page is for whoever manages your school’s web filter or firewall — Smoothwall, Linewize, Lightspeed, FortiGuard, or whatever your network runs. Which Nurture domains to allow depends on the region your school is hosted in; allow your region’s list below and Assessments, Signal and Learn all work everywhere on your network, including student devices.
Using wildcards? Nurture’s own domains all sit under gonurture.com, so a
*.gonurture.com rule covers them in one entry. Each region’s list also
includes a few third-party endpoints — for sign-in and real-time data — that
still need allowing individually.
All Nurture traffic is HTTPS on port 443 — there are no unusual ports to open. If your filter performs SSL inspection and Nurture loads but live sessions drop, exempting the Nurture domains from inspection is the first thing to try.
Domains to allow per region
Every region
app.gonurture.comthe Nurture applicationstart.gonurture.comthe get-started flow for schools setting upwww.gonurture.comthis website and the tutorials teachers followgonurture.comthe apex domain
🇦🇺 Australia
signal.gonurture.comNurture Signalau.gonurture.comthe Nurture application (Australia)au-api.gonurture.comthe Nurture API (Australia)api.clerk.comsign-in and authenticationapi.instantdb.comreal-time data for live sessionsinstant.icypebble-39af03d3.australiaeast.azurecontainerapps.ioreal-time data, hosted in Australia East
🇪🇺 Europe
We are finalising this list. Contact us for more information.
🌐 Global (default region)
We are finalising this list. Contact us for more information.
Endpoints you likely already allow
Nurture signs people in with the account the school already runs, so its
sign-in flow touches your identity provider’s endpoints, not new ones. Schools
running Microsoft 365 already allow login.microsoftonline.com and Microsoft’s
published endpoint list; schools on Canvas already allow their Canvas
instance’s domains.
Tutorial videos on this site are hosted on YouTube, so they play only where the school network allows YouTube. Nothing in the product itself depends on it.
How to test
The quickest proof is the real path, on the filtered network, on a student device:
- Open
app.gonurture.comin a browser on the school network — the sign-in page should load. - Have a teacher start a Signal session and a student join it from a student device on the student network.
- Have the student submit a response and confirm the teacher sees it arrive live.
- If teachers launch Nurture from Teams or Canvas, open it from there too — the tab should load, not sit blank.
If staff Wi-Fi works and the student network does not, the difference is almost always a filtering policy applied only to student traffic.
Still blocked?
Write to hello@gonurture.com with the filtering product you use and what you see — a blank tab, a spinner, a block page — and we will pinpoint the entry your allowlist is missing.
