--- title: "Whitelist Whatfix domains on Salesforce Lightning" slug: "whitelisting-whatfix-domains-on-salesforce" updated: 2026-08-13T04:41:26Z published: 2026-08-13T04:41:26Z canonical: "support.whatfix.com/whitelisting-whatfix-domains-on-salesforce" --- > ## Documentation Index > Fetch the complete documentation index at: https://support.whatfix.com/llms.txt > Use this file to discover all available pages before exploring further. # Whitelist Whatfix domains on Salesforce Lightning Whitelisting Whatfix domains on Salesforce Lightning enables Whatfix to communicate with Salesforce Lightning and fetch Whatfix content-related data. If Whatfix domains are not whitelisted, you won't be able to track how your content performs using Whatfix Analytics. > [!WARNING] > your title goes here > > Only Salesforce Lightning Admins can perform the following action. Use the following steps to whitelist Whatfix domains on Salesforce Lightning: 1. Log in to your Salesforce Lightning account. 2. Click the **Settings icon**, and then click **Setup**. ![SF_SETUP](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_SETUP.png) 3. In the left pane, click **Security**. ![SF_security](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_security.png) 4. Click **CSP Trusted Sites**. ![SF_CSP_sites](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_CSP_sites.png) 5. Click the **New Trusted Site** button. ![SF_new_trusted_site.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_new_trusted_site.png) 6. In the **Trusted Site Name** field, enter a name for the site. For example, enter **WhatfixDomain**. ![SF_site_name.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_site_name.png) > [!WARNING] > Note > > This field does not accept spaces in the name. You need to whitelist 4 domains and the procedure for each is mentioned. > [!NOTE] > your title goes here > > - Whitelist Google Analytics (GA) domains only if you have it configured for your account. > - For more information on trusted Whatfix domains to whitelist, see [What are the trusted Whatfix domains to whitelist?](/studio/docs/what-are-the-trusted-whatfix-domains-to-whitelist) **For https://whatfix.com** 1. In the **Trusted Site URL** field, enter **https://whatfix.com**. ![SF_trusted_site_url.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_trusted_site_url.png) 2. In the **CSP Directives** section, check the **Allow site for connect-src** and **Allow site for frame-src** checkboxes as the directives. ![salesforce_settings_CSP_directives](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/salesforce_settings_CSP_directives.png) > [!WARNING] > your title goes here > > By default, the **Allow site for connect-src** & **Allow site for frame-src** checkboxes are disabled. 1. Click **Save & New**. ![SF_save_and_new_button](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_save_and_new_button.png) The CSP Trusted Sites section displays the list of whitelisted Whatfix domains: ![SF_CSP_list.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_CSP_list.png) **For https://cdn.whatfix.com** 1. In the **Trusted Site URL** field, enter **https://cdn.whatfix.com**. ![salesforce_settings_CSP_whatfix_CDN_url](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/salesforce_settings_CSP_whatfix_CDN_url.png) 2. In the **CSP Directives** section, check the **Allow site for connect-src** and **Allow site for frame-src** checkboxes as the directives. ![salesforce_settings_CSP_directives](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/salesforce_settings_CSP_directives.png) > [!WARNING] > your title goes here > > By default, the **Allow site for connect-src** & **Allow site for frame-src** checkboxes are disabled. 1. Click the **Save & New** button. ![SF_save_and_new_button](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_save_and_new_button.png) You can see the list of whitelisted Whatfix domains in the CSP Trusted Sites section. ![SF_CSP_list.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_CSP_list.png) > [!WARNING] > your title goes here > > The following domains also need to be whitelisted if you have configured Google Analytics for your account. > > - https://www.google-analytics.com > - https://analytics.google.com **For https://www.google-analytics.com** 1. In the **Trusted Site URL** field, enter **https://www.google-analytics.com**. ![salesforce_settings_CSP_GA_site_URL](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/salesforce_settings_CSP_GA_site_URL.png) 2. In the **CSP Directives** section, check the **Allow site for connect-src** checkbox as one of the directives. ![JSintegration_Salesforce_CSPdirectives](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/JSintegration_Salesforce_CSPdirectives.png) > [!WARNING] > your title goes here > > By default, the **Allow site for connect-src** checkbox is disabled. 1. Click the **Save & New** button. ![SF_save_and_new_button](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_save_and_new_button.png) You can see the list of whitelisted Whatfix domains in the CSP Trusted Sites section. ![SF_CSP_list.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_CSP_list.png) **For https://analytics.google.com** 1. In the **Trusted Site URL** field, enter **https://analytics.google.com** ![salesforce_settings_CSP_GA_analytics_site_URL_](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/salesforce_settings_CSP_GA_analytics_site_URL_.png) 2. In the **CSP Directives** section, check **Allow site for connect-src** checkbox as one of the directives. ![JSintegration_Salesforce_CSPdirectives](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/JSintegration_Salesforce_CSPdirectives.png) > [!WARNING] > your title goes here > > By default, the **Allow site for connect-src** is disabled. 1. Click the **Save & New** button. ![SF_save_and_new_button](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_save_and_new_button.png) The CSP Trusted Sites section displays the list of whitelisted Whatfix domains: ![SF_CSP_list.png](https://cdn.document360.io/a268766e-d74d-4619-9613-e2472f809ffb/Images/Documentation/SF_CSP_list.png) ## Related - [What are the trusted Whatfix domains to whitelist?](/what-are-the-trusted-whatfix-domains-to-whitelist.md)