Every node has published addresses. Test them yourself.
Every Pulse check originates from one of these machines. Ping them, traceroute to them, or run an MTR from any of them to your own host, right here.
FleetProbe endpoints
Loading the fleet
ToolsMTR from our fleet to any host
Pick a node, give it a public hostname or IP, and it runs a real trace and reports the hops back. Private and reserved ranges are refused. Limits: 3 traces per 10 minutes and 30 per day, per source IP.
AllowlistingLet our checks through
HTTP and TCP checks arrive from the node addresses above. If your WAF or rate limiter is strict, allowlist them and your monitors stay clean. Every node answers ping and traceroute on its hostname, and serves a fast /ping path over HTTPS, so you can verify reachability from your side any time.
Heartbeat monitors are inbound to us, nothing to allowlist. If a hop in the trace tool shows ???, that router simply does not answer ICMP; loss at the final hop is what matters.
The same addresses, one IP per line, v4 then v6, as plain text. Point a cron job or your firewall tooling at it and the allowlist maintains itself.
https://api.pulse.corehost.io/ips.txtcurl -fsS https://api.pulse.corehost.io/ips.txt
Prefer JSON with hostnames and cities? GET /v1/public/fleet returns the full node list. Both endpoints are public, no auth.
The address list loads with the fleet table above.