Egress allow-list
An explicit list of the hosts a piece of software is permitted to contact.
Declaring where software may send data turns an unanswerable question into a checkable one. Without it, the honest answer to what can leave is everything.
On this site an egress list is part of the capability manifest, it is compared against observed behaviour during testing, and a listing that contacts something outside it fails.
It is the single most effective control against both SSRF and data exfiltration by prompt injection, and it is cheap to implement.
Listing domains rather than resolving them. A name that resolves to one address during a test and another in production has not been constrained.
Related terms
See Egress allow-list on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue