Freshservice Freshservice

Resources

Products

Manage trusted URLs in Freshservice

Modified on: Mon, 5 Oct, 2026 at 2:57 PM

TABLE OF CONTENTS

Learn how to configure the Trusted URLs setting in Freshservice to control external hyperlink access and safeguard your agents and requesters from unapproved or malicious domains.


Overview

The Trusted URLs service desk setting allows administrators to restrict or monitor external web links clicked from within Freshservice tickets, notes, and conversations.


  • Initial state: The Trusted URLs setting is disabled by default.

  • Default whitelisted domains: All internal in-app navigation links and official Freshworks product-related domains are whitelisted by default and bypass security checks.

  • Verification occurrence: Links are verified only when an external link is clicked within the application. Adding or entering links in private notes or the reply editor is not restricted, and URL validation does not extend to links inside iframes.

  • Browser-level actions: Opening links in a new tab via right-click is governed by the web browser itself and cannot be managed or restricted.


Prerequisites

  • You must have Administrator privileges to modify service desk settings.


Enable and configure trusted URLs

  1. Log in to your Freshservice account.

  2. Go to Admin > Global Settings > Service Desk Settings.

  3. Scroll to the Trusted URLs section and enable the toggle.



  1. Under Action, select the restriction policy to apply when an unlisted domain is clicked.

  • Warn: Displays a warning modal informing the user that the domain is unapproved, but allows them to select Continue anyway.

  • Block: Displays a restriction modal and completely prevents access.

  1. Under Enable for, choose who the rule applies to: Agents, Requesters, or Both.

  2. Under Allowed domains, add the trusted external domains or specific paths.

  3. Select Add allowed domain to add more entries.

  4. Select Save to apply your changes.


Domain syntax and formatting rules

To ensure trusted links are recognized correctly, follow these domain formatting requirements.


Entry type

Syntax pattern

Example entry

Behavior and scope

Wildcard subdomain

*.domain.com

*.acme.com

Matches both http:// and https:// across all subdomains and paths.

Full path URL

https://domain.com/path

https://github.com/Freshworks

Requires https://. Matches the path and any sub-paths (for example, https://github.com/Freshworks/project)


Note: The same full path URLs are not treated identically. For instance, https://github.com and https://www.github.com are treated as different domains.


Important notes on validation:

  • Protocol requirement: Full path entries must start explicitly with https://. An entry for (https://stripe.com) will not match (http://stripe.com).

  • Wildcard placement: Wildcards are supported only at the beginning of an entry (for example, *.domain.com). Trailing wildcards (for example, [https://domain.com/]* are not supported.

  • Internationalized domains: Domains containing non-ASCII characters are automatically converted into Punycode during configuration and verification.

User experience (UX) reference

When an agent or requester clicks an external link:

  • Allowed domain

The link opens immediately without modal prompts or delays.


  • Unallowed domain (Action: Warn)

A dialog opens with a warning message. The user can choose Cancel or Continue anyway.



  • Unallowed domain (Action: Block)

A dialog opens with a blocking message. The user cannot proceed and must select Got it to dismiss the modal.



Upcoming enhancements

  • Bulk add allowed domains: A Bulk Add feature to import and manage multiple allowed domains simultaneously will be introduced in an upcoming release.

  • Content checking during link insertion: Real-time link checking when agents type or paste URLs in reply fields is planned as a future feature.

  • Domains with ports: Support for domains with ports is currently unavailable and will be added in a future update.