Configure your network for Wispr Flow
Last updated: September 19, 2026
Available on: Mac, Windows
For IT teams managing blocked downloads, slow dictation, or approved-network access: firewall rules and your organization's IP allowlist are separate controls. Allowing a service hostname through your firewall does not add a user's network to the IP allowlist.
Allow outbound access to websites and downloads
If your organization restricts outbound traffic, allow these domains:
Domain | Purpose |
wisprflow.ai | Web app and account management. |
admin.wisprflow.ai | Admin portal, team management, and MDM instructions. |
dl.wisprflow.com | Installers, automatic updates, and MDM installer downloads. |
docs.wisprflow.ai | Help-center articles. |
MDM accessibility profiles, update-policy files, and restore-ownership scripts require a separate download host; allowing Wispr domains alone does not cover these downloads.
This is not the complete outbound host list. If you enforce a strict outbound firewall, ask your Wispr representative for the full list.
Fix slow dictation caused by SSL/TLS inspection
Flow respects system proxy settings and organizational root certificates, including TLS inspection, for dictation, uploads, and SSO session management.
Dictation requires valid, self-signed root certificates in macOS System Roots or the Windows root store; malformed or intermediate-only corporate certificates can fail even when other connections work.
On inspecting networks, Flow may use a fallback connection with higher or inconsistent delays. Dictations of 30 seconds or longer have no fallback safety net. Networks that do not intercept the connection do not need this bypass.
Use wildcard rules, including *.wisprflow.com, rather than exact hostnames. That wildcard alone is insufficient; contact support@wisprflow.ai for network-configuration help.
Important: TLS stays enabled. The gateway stops intercepting and re-encrypting these connections; traffic is not sent in the clear. This exception covers Flow's dictation and inference traffic, while other TLS sessions remain subject to your inspection policy.
DLP tools that need decrypted traffic cannot inspect these endpoints. Endpoint DLP, DNS controls, egress-volume monitoring, and other controls that do not require decryption remain available.
Create an SSL/TLS-inspection bypass on outbound port 443 for the complete wildcard destination list.
Apply the bypass wherever inspection runs.
Save a permanent policy covering relevant offices, VPN egress points, and remote-user policies.
Test dictation from the affected network once the policy has propagated.
The policy does not need reapplying per user, device, or session.
If dictation is faster and the network notification disappears, the change is working. If the problem remains, contact support.
If shown, the warning clears after three healthy dictations in one app session; restarting resets that count. Warnings can also be capped or suppressed, so absence alone does not prove recovery.
Restrict organization access to approved networks
IP allowlist controls require an Enterprise plan, admin permissions, and enablement by Wispr. Android users are not currently signed out or shown a lockout screen when blocked; this does not exempt Android traffic from IP restrictions.
Include expected office IPs, VPN exit IPs, and remote locations.
Entries: Up to 64 IPv4/IPv6 CIDRs are accepted; invalid entries, empty lists, 0.0.0.0/0, and ::/0 are rejected.
Saved ranges: Host addresses are converted to network addresses; duplicates are removed, keeping first-occurrence order.
Save requirements: Flow must detect your current IP, and the proposed list must cover it when setting or editing ranges.
If “IP allowlist (locked by Wispr)” appears, changes are disabled; contact support to unlock.
Open the admin portal → Settings → Organization → Data Controls.
Select Configure beside IP allowlist.
Enter CIDRs one per line or comma-separated in Edit IP allowlist.
Select Save.
Changes can take about a minute to affect access.
Disable the IP allowlist
Your current IP must be covered by the existing list. An empty list cannot disable the feature.
Warning: Disabling clears saved IP ranges; you must re-enter them to enable restrictions again.
Turn off the IP allowlist switch.
Confirm “Disable IP allowlist?”.
If rules cannot load, access remains allowed; if a later update fails, the last available rules apply.
If a user sees “Your network isn't allowed”
Flow signs Mac and Windows users out when their network is unapproved or their IP cannot be determined, including accounts added through SCIM. The message names the organization when known and directs users to switch networks or contact their admin.
Warning: Blocking dismisses any in-progress dictation, hides the Flow bar, and prevents further dictation.
Switch to an approved network.
Select Retry to reopen browser sign-in.
An allowed network may sign you straight back in; successful sign-in clears the lockout. A still-disallowed network returns you to the blocked screen. Sign Out instead clears the blocked screen and returns to normal sign-in.
If the expected network is missing, ask your admin to review IP allowlist in Settings → Organization from an allowed network.
Still need help?
Contact Flow support if you cannot identify the inspection layer, dictation stays slow after the rule propagates, your security team needs a DLP/data-handling review, or an admin cannot reach an approved network.
Include your platform, device, security vendor, inspection layers changed, and error details.
Review the Trust Center and Security and compliance FAQ for data-handling information.
Note: Report vulnerabilities through the disclosure form, not direct email. See the coordinated disclosure policy.