To ensure ImmerseMe functions correctly, please allow the following outbound connections through your firewall, web proxy, DNS filter and content filtering systems.
Required domains and ports
- https://*.immerseme.com — TCP 443 (HTTPS and secure WebSockets)
- https://*.speech.microsoft.com — TCP 443 (Microsoft Azure speech recognition and text-to-speech)
- https://*.livekit.cloud — TCP 443 (AI Chat signalling)
- https://*.turn.livekit.cloud — TCP 443 (TURN over TLS fallback)
- https://*.host.livekit.cloud — UDP 3478 (TURN / UDP)
For the best AI Chat audio performance, also allow outbound UDP ports 50000–60000 and TCP port 7881. Where UDP is restricted, LiveKit can fall back to TCP 443.
SSL inspection and application filtering
SSL/TLS inspection, HTTPS decryption or deep packet inspection can interfere with speech recognition, WebSockets and real-time audio. If users experience these issues, exclude the domains above from inspection.
Some next-generation firewalls also block traffic by application classification even when a domain is allowlisted. Please permit Microsoft Azure Speech / Azure Custom Speech traffic. On Palo Alto Networks firewalls, this may appear as the App-ID azure-custom-speech.
Important notes
- Allowlist by domain/FQDN or recognised application/service rather than fixed IP address. Cloud-service IP addresses can change.
- Browser microphone permission must also be enabled for ImmerseMe.
- If ImmerseMe works on a personal hotspot but not the school network, a firewall, proxy, DNS filter, SSL inspection or application-control rule is likely blocking the connection.
If problems continue, contact hello@immerseme.com with the affected feature, firewall or filtering product, approximate test time, and a screenshot or export of any blocked event.