---
title: How to set up an Image URL proxy allowlist?
description: Image URL proxy allowlist
---

[Skip to content](https://support.econz.net/customer/how-to-set-up-an-image-url-proxy-allowlist#main-content)

English

Show submenu for translations

[Customer portal](https://support.econz.net/portal?hsLang=en)

![logo.jpg\]](https://support.econz.net/hs-fs/hubfs/logo.jpg?height=40&name=logo.jpg)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Customer portal](https://support.econz.net/portal)
- Go to Econz Website

 Go to Econz Website

 Hello. How can we help you?

- There are no suggestions because the search field is empty.

1. [Help Center](https://support.econz.net/customer?hsLang=en)
2. [Google Workspace](https://support.econz.net/customer/google-workspace?hsLang=en)
3. [Gmail](https://support.econz.net/customer/google-workspace?hsLang=en#gmail)

# How to set up an Image URL proxy allowlist?

## Image URL proxy allowlist

When your users open email messages, Gmail uses Google’s secure proxy servers to serve images that might be included in these messages. This protects your users and domain against image-based security vulnerabilities.

Because of the image proxy, links to images that are dependent on internal IPs and sometimes cookies are broken. The Image URL proxy allowlist setting lets you avoid broken links to images by creating and maintaining an allowlist of internal URLs that'll bypass proxy protection.

When you configure the Image URL proxy allowlist, you can specify a set of domains and a path prefix that can be used to specify large groups of URLs.

#### Configure the Image URL proxy allowlist setting

- In the Admin console, go to **Main menu** \>  **Apps** \> **Google Workspace** \> **Gmail** \> **End User Access**.
- On the left, select your top-level organization.
- Scroll to the **Image URL proxy allowlist** section.

![](https://lh4.googleusercontent.com/NlA0gtJ0UfNcKDSK_-RX5EEiYhQ85hiMWEOHqs5fJL7fcI0zK7wL6qYvUhBLqy7hRatdm94HJHYr0GdBWg_lfU0sOIM47JUl0qp629nBxEd4ev0Vc5VVT0RtewSNq1qnVS2dxldERU_oY7JTAZBAOzE)

- Enter image URL proxy allowlist patterns. Matching URLs will bypass image proxy protection. See the guidelines below for more details and instructions.

![](https://lh6.googleusercontent.com/-HdSDI8Uw-hamF7CHOJWuPxOixt7pVlquz2Qq5D6p6ArxiHRdtSEWaDnVjepxQaDI2t3VS-eT0LmdrjUGEzZTJp8RnKYdkOthbaq5LNWHYm9kgw-6soC50RMKjnrD2_35aQX9NSgvz-lWFQdeO6McQk)

- At the bottom, click **Save**.

#### Guidelines for applying the Image URL proxy allowlist setting

#### **Security considerations**

Consult with your security team before configuring the Image URL proxy allowlist setting. The decision to bypass image proxy allowlist protection can expose your users and domain to security risks if not used with care.

In general, if you have a domain that needs authentication via cookie, and if that domain is controlled by an administrator within your organization and is completely trusted, then allowlisting that URL should not expose your domain to image-based attacks.

**Important:** Disabling the image proxy is not recommended. This option is available to provide flexibility for administrators, but disabling the image proxy can leave your users vulnerable to malicious attacks.

#### **Entering Image URL patterns**

To maintain an allowlist of internal URLs that'll bypass proxy protection, enter the image URL patterns in the Image URL proxy allowlist setting. Matching URLs will bypass the image proxy.

A pattern can contain the scheme, the domain, and a path. The pattern must always have a forward slash (/) present between the domain and path. If the URL pattern specifies a scheme, then the scheme and the domain must fully match. Otherwise, the domain can partially match the URL suffix. For example, the pattern /google.com matches www.google.com, but not gle.com. The URL pattern can specify a path that's matched against the path prefix.

#### **Examples of Image URL pattern**

The following patterns are examples only.

The following patterns:

http://rule\_fixed\_scheme\_domain.com/  
rule\_flex\_scheme\_domain.com/  
rule\_fixed\_subpath.com/cgi-bin/

... will match the following URLs:

http://rule\_fixed\_scheme\_domain.com/  
http://rule\_fixed\_scheme\_domain.com/test.jpg?foo=bar#frag  
http://rule\_fixed\_scheme\_domain.com  
rule\_flex\_scheme\_domain.com/  
t.rule\_flex\_scheme\_domain.com/test.jpg  
http://t.rule\_flex\_scheme\_domain.com/test.jpg  
https://t.rule\_flex\_scheme\_domain.com/test.jpg  
http://rule\_fixed\_subpath.com/cgi-bin/  
http://rule\_fixed\_subpath.com/cgi-bin/people

**Note:** The URL scheme (http://) is optional. If the scheme is omitted, the pattern can match any scheme, and allows partial matches on the domain suffix.

#### **Previewing the image URL patterns**

Click **Preview** to see if the URLs match the image URL patterns you've set. If the image URL matches a pattern, you'll see a confirmation message. If the image URL does not match, an error message appears.

 

Please check the below-supporting article for your further reference: 

[Set up an image URL proxy allowlist - Google Workspace Admin Help](https://support.google.com/a/answer/3299041?hl=en)

 

- [Google Workspace](https://support.econz.net/customer/google-workspace?hsLang=en#main-content)

    - [Reset and recover passwords](https://support.econz.net/customer/google-workspace?hsLang=en#reset-and-recover-passwords)
    - [Email issue](https://support.econz.net/customer/google-workspace?hsLang=en#email-issue)
    - [catch-all address](https://support.econz.net/customer/google-workspace?hsLang=en#catch-all-address)
    - [Download Google Data](https://support.econz.net/customer/google-workspace?hsLang=en#download-google-data)
    - [Gmail](https://support.econz.net/customer/google-workspace?hsLang=en#gmail)
    - [MX Records](https://support.econz.net/customer/google-workspace?hsLang=en#mx-records)
    - [Company Logo](https://support.econz.net/customer/google-workspace?hsLang=en#company-logo)
    - [Sharing drive files to the trusted domains](https://support.econz.net/customer/google-workspace?hsLang=en#sharing-drive-files-to-the-trusted-domains)
    - [Mobile Device Management](https://support.econz.net/customer/google-workspace?hsLang=en#mobile-device-management)
    - [Restrict emails based on a size](https://support.econz.net/customer/google-workspace?hsLang=en#restrict-emails-based-on-a-size)
    - [Create Google Calendar Event](https://support.econz.net/customer/google-workspace?hsLang=en#create-google-calendar-event)
    - [less secure app](https://support.econz.net/customer/google-workspace?hsLang=en#less-secure-app)
    - [Drive & Docs](https://support.econz.net/customer/google-workspace?hsLang=en#drive-docs)
    - [Users](https://support.econz.net/customer/google-workspace?hsLang=en#users)
    - [Install GCPW](https://support.econz.net/customer/google-workspace?hsLang=en#install-gcpw)
    - [Add email aliases for user from google admin console](https://support.econz.net/customer/google-workspace?hsLang=en#add-email-aliases-for-user-from-google-admin-console)
    - [Set up Google Workspace user signatures in Gmail](https://support.econz.net/customer/google-workspace?hsLang=en#set-up-google-workspace-user-signatures-in-gmail)
    - [Add or remove printers](https://support.econz.net/customer/google-workspace?hsLang=en#add-or-remove-printers)
    - [New updates to Google Workspace](https://support.econz.net/customer/google-workspace?hsLang=en#new-updates-to-google-workspace)
    - [DNS](https://support.econz.net/customer/google-workspace?hsLang=en#dns)
    - [DNS Records](https://support.econz.net/customer/google-workspace?hsLang=en#dns-records)
    - [Admin roles](https://support.econz.net/customer/google-workspace?hsLang=en#admin-roles)
    - [Security](https://support.econz.net/customer/google-workspace?hsLang=en#security)
    - [Forms & Surveys](https://support.econz.net/customer/google-workspace?hsLang=en#forms-surveys)
    - [password](https://support.econz.net/customer/google-workspace?hsLang=en#password)
    - [Calendar](https://support.econz.net/customer/google-workspace?hsLang=en#calendar)
    - [Google vault](https://support.econz.net/customer/google-workspace?hsLang=en#google-vault)
    - [har file](https://support.econz.net/customer/google-workspace?hsLang=en#har-file)
    - [Cloud Data Sync](https://support.econz.net/customer/google-workspace?hsLang=en#cloud-data-sync)
    - [LDAP](https://support.econz.net/customer/google-workspace?hsLang=en#ldap)
    - [Routing](https://support.econz.net/customer/google-workspace?hsLang=en#routing)
    - [Data Migration](https://support.econz.net/customer/google-workspace?hsLang=en#data-migration)
    - [Organizational Unit(OU)](https://support.econz.net/customer/google-workspace?hsLang=en#organizational-unitou)
    - [License and subscription](https://support.econz.net/customer/google-workspace?hsLang=en#license-and-subscription)
    - [GWSMO](https://support.econz.net/customer/google-workspace?hsLang=en#gwsmo)
    - [Report and Audit](https://support.econz.net/customer/google-workspace?hsLang=en#report-and-audit)
    - [SMTP](https://support.econz.net/customer/google-workspace?hsLang=en#smtp)
    - [GWMME](https://support.econz.net/customer/google-workspace?hsLang=en#gwmme)
    - [password sync](https://support.econz.net/customer/google-workspace?hsLang=en#password-sync)
    - [Google Sites](https://support.econz.net/customer/google-workspace?hsLang=en#google-sites)
    - [Google services](https://support.econz.net/customer/google-workspace?hsLang=en#google-services)
    - [jamboard](https://support.econz.net/customer/google-workspace?hsLang=en#jamboard)
    - [Google Add-ons](https://support.econz.net/customer/google-workspace?hsLang=en#google-add-ons)
    - [GCPW](https://support.econz.net/customer/google-workspace?hsLang=en#gcpw)
    - [Keep](https://support.econz.net/customer/google-workspace?hsLang=en#keep)
    - [outlook](https://support.econz.net/customer/google-workspace?hsLang=en#outlook)
    - [Devices](https://support.econz.net/customer/google-workspace?hsLang=en#devices)
    - [Apps](https://support.econz.net/customer/google-workspace?hsLang=en#apps)
    - [Spam, phishing, and malware](https://support.econz.net/customer/google-workspace?hsLang=en#spam-phishing-and-malware)
    - [Windows](https://support.econz.net/customer/google-workspace?hsLang=en#windows)
    - [Meet Hardware](https://support.econz.net/customer/google-workspace?hsLang=en#meet-hardware)
    - [user settings](https://support.econz.net/customer/google-workspace?hsLang=en#user-settings)
    - [Google takeout](https://support.econz.net/customer/google-workspace?hsLang=en#google-takeout)
    - [Chrome Device Management](https://support.econz.net/customer/google-workspace?hsLang=en#chrome-device-management)
    - [networks](https://support.econz.net/customer/google-workspace?hsLang=en#networks)
    - [Chrome Enterprise Management](https://support.econz.net/customer/google-workspace?hsLang=en#chrome-enterprise-management)

[![](https://support.econz.net/hs-fs/hubfs/econz%20logo.png?width=600&height=164&name=econz%20logo.png)](http://econz.cloud)

Help Center

Copyright © 2026, Econz IT Services Pvt Ltd