How to Whitelist Atarim When Your Site Uses Firewalls, WAF Rules, or IP Restrictions
Ensure Atarim loads and works correctly—even on websites protected by firewalls or maintenance mode.
If your website uses security measures such as Cloudflare, Wordfence, Sucuri, IP whitelists, or maintenance mode, you may notice that Atarim cannot load the page or generate screenshots for collaboration. This is because these tools often block automated or external access — including Atarim’s remote workers and screenshot engine.
This guide walks you through the officially supported methods to ensure Atarim can connect to your website: domain-level whitelisting, header-based exceptions, and the Atarim browser extension.
Why Your Site May Block Atarim
Common causes include:
How Atarim Connects to Your Site
Option 1 — Whitelist Atarim by Domain (Recommended)
To load your website and generate screenshots, Atarim uses the domains below. Add each of them to your firewall or WAF allowlist:
*.atarimworker.io and *.atarimworker.dev.
This solves most issues, including:
Option 2 — Whitelist Atarim by Request Headers
If domain whitelisting doesn’t work and your firewall supports header rules, Atarim includes two permanent identifiers:
User-Agent Contains: atarim-worker
Custom Header: Proxied-For: Atarim
Create rules that:
Supported by:
Cloudflare Configuration
Cloudflare is the most common source of blocking. Typical issues include:
Step 1: Create Bypass Rules
Go to: Security → WAF → Custom Rules → Create Rule
Allow:

Step 2: Add Header-Based Exceptions
If domain exceptions alone don’t work:
IF: Proxied-For = Atarim
THEN: Skip WAF / skip challenge
OR
IF: User-Agent contains atarim-worker
THEN: Allow request


Step 3: Fix Screenshot Issues
If screenshots show a Cloudflare JS challenge:
Whitelist urlbox.com.
urlbox.com. It solves most screenshot-related errors immediately.
Option 3 — Use the Atarim Browser Extension
Use the extension when:
The extension loads the website directly from your browser and bypasses all external restrictions safely. Learn More About Installing The Atarim Chrome Extension
Malwarebytes / ThreatDown False Positives
Some users reported Malwarebytes/ThreatDown flagging:
ancillary-proxy.atarimworker.dev — detected as Phishing.Web.
What You Should Do
What Atarim Cannot Support
Atarim cannot:
Common issues
1. Site loads maintenance or login page
✔ Use the Browser Extension
✔ Or disable maintenance mode temporarily
2. Cloudflare test page in screenshots
✔ Whitelist urlbox.com
✔ Add header bypass rules
3. Cloudflare blocking non-US IP traffic
✔ Add domain exceptions for Atarim domains
✔ Add header exceptions if needed
4. Wordfence/Sucuri blocking Atarim
✔ Whitelist all Atarim domains
✔ Allow the user-agent atarim-worker
5. Threatdown blocks Atarim
✔ Safe to whitelist
✔ Customer must file a false-positive report
Conclusion
To ensure Atarim can access and collaborate on protected websites:
- Start with domain whitelisting
- Add header-based firewall exceptions
- Use the Atarim Browser Extension if all else fails
With one of these three supported options, your team can reliably collaborate on any website — even behind enterprise-grade security.