ĀYŌDÈ Whitelisting Instructions for District IT
Purpose
ĀYŌDÈ (CoderMerlin Academy) requires access to specific web domains and email addresses for full functionality. To ensure reliable access within your district’s network environment, we recommend adding our domains to your firewall allow lists and our email addresses to your safe senders list.
This document provides all the technical details your IT team needs to whitelist ĀYŌDÈ for web access and email delivery.
Our Commitment to Security
ĀYŌDÈ follows industry best practices to protect student and educator data:
Infrastructure Security
- Hosted on Amazon Web Services (AWS), which maintains SOC 2, ISO 27001, and FedRAMP certifications
- All data encrypted in transit using TLS 1.2+
- All data encrypted at rest using AES-256
Authentication Security
- Identity management through AWS Cognito with secure token handling
- Support for federated authentication (Google Sign-In) using OAuth 2.0 / OpenID Connect
- Role-based access control (RBAC) with realm-based multi-tenancy
Email Security
- SPF (Sender Policy Framework) to prevent sender address forgery
- DKIM (DomainKeys Identified Mail) for message integrity verification
- DMARC (Domain-based Message Authentication) with quarantine policy for failed messages
- Transactional emails only; no marketing or promotional content
Web Access Domains
Primary Application Domains
Allow HTTPS (port 443) access to the following domains:
| Domain | Purpose |
|---|---|
www.codermerlin.academy |
Main application |
setyourvector.org |
Set Your Vector website |
static-blue-apollo.www.codermerlin.academy |
Static content |
static-green-apollo.www.codermerlin.academy |
Static content |
api-blue-apollo.www.codermerlin.academy |
API services |
api-green-apollo.www.codermerlin.academy |
API services |
assets-blue-apollo.www.codermerlin.academy |
File assets |
assets-green-apollo.www.codermerlin.academy |
File assets |
discourse-apollo.www.codermerlin.academy |
Community forums |
AWS Service Domains
The application uses Amazon Web Services for authentication and file storage:
| Domain Pattern | Purpose |
|---|---|
*.amazoncognito.com |
Authentication (login/signup UI) |
*.s3.us-east-2.amazonaws.com |
File uploads and downloads |
Third-Party Authentication
If your district uses Google Sign-In:
| Domain | Purpose |
|---|---|
accounts.google.com |
Google OAuth |
oauth2.googleapis.com |
Google OAuth API |
Simplified Domain Configuration
For easier firewall management, allow these domain patterns and exact domains:
*.codermerlin.academysetyourvector.org*.setyourvector.org*.amazoncognito.com*.s3.us-east-2.amazonaws.com
Email Whitelisting
Approved Sender Addresses
Add the following addresses to your safe senders or allowed senders list:
| Address | Purpose |
|---|---|
noreply-apollo-production@codermerlin.academy |
Verification codes and system notifications |
support@codermerlin.academy |
Support communications and reply-to |
Email Sending Domains
Allow emails from these domains:
codermerlin.academy(primary domain)outbound.codermerlin.academy(MAIL FROM domain)
Email Service Provider
ĀYŌDÈ uses Amazon Simple Email Service (SES) for transactional email delivery. All outbound emails are authenticated using SPF, DKIM, and DMARC.
Email Authentication Records
These records can be used to verify the authenticity of ĀYŌDÈ emails:
SPF Record (codermerlin.academy)
v=spf1 include:amazonses.com ~all
SPF Record (outbound.codermerlin.academy)
v=spf1 include:amazonses.com ~all
DKIM
DKIM is enabled and managed by Amazon SES. Emails are signed with rotating keys under the _domainkey.codermerlin.academy subdomain.
DMARC
v=DMARC1; p=quarantine; rua=mailto:support@codermerlin.academy
Sending IP Addresses
Amazon SES uses a shared IP pool for sending. Rather than whitelisting specific IP addresses, we recommend allowing emails based on domain and SPF authentication.
If your security policy requires IP-based filtering, allow the Amazon SES IP ranges for the us-east-2 region. These ranges are published in the AWS IP address ranges JSON file under the AMAZON_SES service.
Platform-Specific Instructions
Microsoft 365 / Exchange Online
Email:
- Add
@codermerlin.academyto Allowed Domains or Safe Senders in Exchange Admin Center - Create a mail flow rule to bypass spam filtering for emails from
codermerlin.academy
Web (if using Defender for Endpoint):
- Add
*.codermerlin.academy,setyourvector.org, and*.setyourvector.orgto allowed URLs - Add
*.amazoncognito.comand*.s3.us-east-2.amazonaws.comfor authentication and file transfers
Google Workspace / Gmail
Email:
- Add
codermerlin.academyunder Approved Senders in Admin Console - Configure Email allowlist to include the domain
Web (if using Chrome Enterprise):
- Add
*.codermerlin.academy,setyourvector.org, and*.setyourvector.orgto the URL allowlist policy
Email Security Gateways (Barracuda, Proofpoint, Mimecast)
- Add
codermerlin.academyto your Allowed Domains list - Add
outbound.codermerlin.academyto your Allowed Domains list - Mark ĀYŌDÈ / CoderMerlin as an allowed SaaS vendor for transactional email
- Ensure SPF and DKIM validation passes for allowed domains
Web Content Filters (Lightspeed, GoGuardian, Securly)
- Add
*.codermerlin.academy,setyourvector.org, and*.setyourvector.orgto the allowed list - Categorize as “Education” or “Educational Technology”
- Add
*.amazoncognito.comand*.s3.us-east-2.amazonaws.comfor authentication and file transfers
Expected Email Types
Our addresses send only transactional messages:
- One-time verification codes for login
- Password reset emails
- Essential account notifications
We do not send marketing or promotional emails from these addresses.
Contact and Testing
After completing your whitelist configuration, contact us to verify access:
| Contact | Address |
|---|---|
| Support | support@codermerlin.academy |
We can send a test verification email and confirm web access is working correctly for your district.
Document version: Draft v0.5