ĀYŌDÈ Whitelisting Instructions for District IT

Purpose

ĀYŌDÈ (CoderMerlin Academy) requires access to specific web domains and email addresses for full functionality. To ensure reliable access within your district’s network environment, we recommend adding our domains to your firewall allow lists and our email addresses to your safe senders list.

This document provides all the technical details your IT team needs to whitelist ĀYŌDÈ for web access and email delivery.

Our Commitment to Security

ĀYŌDÈ follows industry best practices to protect student and educator data:

Infrastructure Security

Authentication Security

Email Security


Web Access Domains

Primary Application Domains

Allow HTTPS (port 443) access to the following domains:

Domain Purpose
www.codermerlin.academy Main application
setyourvector.org Set Your Vector website
static-blue-apollo.www.codermerlin.academy Static content
static-green-apollo.www.codermerlin.academy Static content
api-blue-apollo.www.codermerlin.academy API services
api-green-apollo.www.codermerlin.academy API services
assets-blue-apollo.www.codermerlin.academy File assets
assets-green-apollo.www.codermerlin.academy File assets
discourse-apollo.www.codermerlin.academy Community forums

AWS Service Domains

The application uses Amazon Web Services for authentication and file storage:

Domain Pattern Purpose
*.amazoncognito.com Authentication (login/signup UI)
*.s3.us-east-2.amazonaws.com File uploads and downloads

Third-Party Authentication

If your district uses Google Sign-In:

Domain Purpose
accounts.google.com Google OAuth
oauth2.googleapis.com Google OAuth API

Simplified Domain Configuration

For easier firewall management, allow these domain patterns and exact domains:


Email Whitelisting

Approved Sender Addresses

Add the following addresses to your safe senders or allowed senders list:

Address Purpose
noreply-apollo-production@codermerlin.academy Verification codes and system notifications
support@codermerlin.academy Support communications and reply-to

Email Sending Domains

Allow emails from these domains:

Email Service Provider

ĀYŌDÈ uses Amazon Simple Email Service (SES) for transactional email delivery. All outbound emails are authenticated using SPF, DKIM, and DMARC.

Email Authentication Records

These records can be used to verify the authenticity of ĀYŌDÈ emails:

SPF Record (codermerlin.academy)

v=spf1 include:amazonses.com ~all

SPF Record (outbound.codermerlin.academy)

v=spf1 include:amazonses.com ~all

DKIM

DKIM is enabled and managed by Amazon SES. Emails are signed with rotating keys under the _domainkey.codermerlin.academy subdomain.

DMARC

v=DMARC1; p=quarantine; rua=mailto:support@codermerlin.academy

Sending IP Addresses

Amazon SES uses a shared IP pool for sending. Rather than whitelisting specific IP addresses, we recommend allowing emails based on domain and SPF authentication.

If your security policy requires IP-based filtering, allow the Amazon SES IP ranges for the us-east-2 region. These ranges are published in the AWS IP address ranges JSON file under the AMAZON_SES service.


Platform-Specific Instructions

Microsoft 365 / Exchange Online

Email:

  1. Add @codermerlin.academy to Allowed Domains or Safe Senders in Exchange Admin Center
  2. Create a mail flow rule to bypass spam filtering for emails from codermerlin.academy

Web (if using Defender for Endpoint):

  1. Add *.codermerlin.academy, setyourvector.org, and *.setyourvector.org to allowed URLs
  2. Add *.amazoncognito.com and *.s3.us-east-2.amazonaws.com for authentication and file transfers

Google Workspace / Gmail

Email:

  1. Add codermerlin.academy under Approved Senders in Admin Console
  2. Configure Email allowlist to include the domain

Web (if using Chrome Enterprise):

  1. Add *.codermerlin.academy, setyourvector.org, and *.setyourvector.org to the URL allowlist policy

Email Security Gateways (Barracuda, Proofpoint, Mimecast)

  1. Add codermerlin.academy to your Allowed Domains list
  2. Add outbound.codermerlin.academy to your Allowed Domains list
  3. Mark ĀYŌDÈ / CoderMerlin as an allowed SaaS vendor for transactional email
  4. Ensure SPF and DKIM validation passes for allowed domains

Web Content Filters (Lightspeed, GoGuardian, Securly)

  1. Add *.codermerlin.academy, setyourvector.org, and *.setyourvector.org to the allowed list
  2. Categorize as “Education” or “Educational Technology”
  3. Add *.amazoncognito.com and *.s3.us-east-2.amazonaws.com for authentication and file transfers

Expected Email Types

Our addresses send only transactional messages:

We do not send marketing or promotional emails from these addresses.


Contact and Testing

After completing your whitelist configuration, contact us to verify access:

Contact Address
Support support@codermerlin.academy

We can send a test verification email and confirm web access is working correctly for your district.


Document version: Draft v0.5