IP Allowlist
IP Allowlist
You don't have to open your database to the internet to use DBMigratePro. Every connection we
make to your database — scheduled backups, migrations, restores, and connection tests — originates from a
small, static set of IP ranges. Allow those ranges in your database firewall and nothing else
needs to be reachable.
The ranges
74.220.50.0/24, 74.220.58.0/24
Also available as JSON for scripting: GET https://dbmigratepro.com/api/egress-ips.
These are stable. If they ever need to change (for example, a hosting region move), we will
announce it well in advance — your firewall rules will never silently stop matching.
Honest caveat: these are shared egress ranges at our hosting provider, not addresses
dedicated solely to us. Allowing them is a dramatic improvement over a database open to the
world, but combine it with the strong password and TLS you already use — the firewall rule is a
second lock, not the only one.
Where to paste them
- AWS RDS / Aurora — add an inbound rule per range to the instance's security group
(Type: PostgreSQL or MySQL/Aurora, Source: the CIDR).
- DigitalOcean Managed Databases — Settings → Trusted Sources → add each range.
- Azure Database — Networking → Firewall rules → add the range's start and end addresses.
- Google Cloud SQL — Connections → Networking → Authorized networks → add each CIDR.
- Render Postgres — Access Control → add each CIDR.
- Supabase — Project Settings → Database → Network Restrictions → add each CIDR.
- Self-hosted — allow the ranges in your firewall (e.g.
ufw allow from <CIDR> to any port 5432)
and, for Postgres, in pg_hba.conf.
After adding the rules, use Test connection on the connection form to confirm we can reach
the database.