Synaps Media uses an automated bot to verify custom domain connections. You can allowlist it using any of the following, from least to most rigorous:

1. User-Agent (easiest, but spoofable on its own)

SynapsMedia-Healthcheck/1.0 (+https://www.synapsmedia.com/healthcheck)

2. Source IP (recommended — this is a dedicated, fixed IP we control, not shared hosting)

78.47.190.89

Machine-readable list (for automation):

https://www.synapsmedia.com/assets/healthcheck-ips.txt

3. Forward-confirmed reverse DNS (FCrDNS) — the strongest guarantee. 78.47.190.89 resolves in reverse to proxy.synaps.media, and proxy.synaps.media resolves forward back to 78.47.190.89. If your bot protection supports FCrDNS verification, point it at this.

4. Cryptographic signing (Web Bot Auth / RFC 9421)

Every active probe is signed per the Web Bot Auth profile of RFC 9421 HTTP Message Signatures. Our public key is published as a JWKS directory at:

https://www.synapsmedia.com/.well-known/http-message-signatures-directory

If your bot-management provider supports Web Bot Auth / RFC 9421 verification, you can validate our requests directly against this key — independent of IP or User-Agent.

If you are using Cloudflare, create a Custom Security Rule that skips Bot Fight Mode / Super Bot Fight Mode / Managed Challenge for our IP: