IP address restriction lets you control account access based on the network you're signing in from. When it's configured, a sign-in attempt is allowed or denied depending on whether it comes from an IP address you've added to the restriction. You can set this up for your own individual account, or, if you manage an organization, enforce it for all your users.
When you set up IP address restriction, you choose one of two modes:
- Allow added IP addresses: sign-in is allowed only from the IP addresses you add. Every other IP address is denied.
- Deny added IP addresses: sign-in is denied from the IP addresses you add. Every other IP address is allowed.
You choose this mode the first time you set up the restriction, and it applies to every IP group you add afterward. To switch modes later, you need to delete all currently added IP groups and set up the restriction again.
IP address groups
You add IP addresses as named groups, for example, Office IP or Home IP. Each group can contain multiple IP addresses, including a mix of different types, and has its own restriction scope and expiration. You can add as many groups as you need under the same restriction, and each one is edited, deleted, or reviewed as a single unit.

IP address types
Within a group, you can add an IP address in any of the following ways:
- Current IP: the IP address you're currently signed in from.
- Individual IP: a single static IP address.
- IP Range: a range of IP addresses, specified with a from address and a to address.
- CIDR Block: a block of IP addresses specified using CIDR notation (for example, 203.0.113.0/24). Supported prefixes range from /0 to /32.
Warning: Make sure the IP addresses you add are static gateway IP addresses. Dynamic IP addresses change over time, and adding one could lock you out of your account.
Restriction scope
For each IP group, choose which sign-in paths the restriction applies to:
- Browser and app sign-ins: covers access from browsers, Zoho apps, and connected apps.
- POP/IMAP clients: covers access by POP/IMAP-based third-party apps and extensions, such as third-party mail and calendar clients.
You can select one or both. Selecting POP/IMAP clients as well is recommended, so the restriction also covers sign-ins from third-party mail and calendar apps, in addition to browsers and connected apps.
Expiration
You can optionally set an expiration date and time for each IP group. Once a group's expiration passes, it's automatically disabled and no longer applies to sign-in attempts.
Set up IP address restriction for your account
- Sign in to accounts.zoho.com.
- Under Security, go to Allowed IP Address.
- Click Set up IP Restriction.
- Select a restriction mode: Allow added IP addresses or Deny added IP addresses.
Warning: You can't change the restriction mode later without deleting all the IP groups you've added and setting up the restriction again from the start. - Click Continue.
- In the IP Name field, enter a name for this IP group (for example, Office IP).
- From the IP Type dropdown, select an IP type (Current IP, Individual IP, IP Range, or CIDR Block), then enter the required address details. To add more addresses to the same group, click +.
- Click Next.
- Under Apply this restriction to, select the required restriction scope: Browser and app sign-ins, POP/IMAP clients, or both.
- (Optional) Enable the Set expiration toggle, then specify the expiration date and time.
- Click Enable IP Restriction.
You can add more IP groups to the same restriction, for example, a separate Home IP group alongside an existing Office IP group. Every group you add follows the same restriction mode.
- Under IP Address Restriction, click + Set up IP Restriction.
- Follow steps 6 through 11 of Set up IP address restriction to name and configure the new group.
Warning: Changing the restriction mode deletes every IP group you've currently added. You'll need to add them again after switching.- Under IP Address Restriction, click change restriction mode.
- Select the new mode: Allow added IP addresses or Deny added IP addresses.
- Click Continue.
To view a group's name, added IP addresses, applied scope, and expiration, click the group under IP Address Restriction.
- To edit a group, click its Edit icon, or click Edit IP Address Group in the group's details.
- To delete a group, click its Delete icon, or click Delete IP Address Group in the group's details.
What to do if you get locked out of your account
- If you set up the restriction yourself and have account recovery options available, you can remove or reconfigure it without signing in. Refer to How to remove IP restriction.
- If the restriction is enforced by your organization, contact your administrator to help you recover access.
If you still can't resolve the issue, contact
support@zohoaccounts.com. Our support team disables the IP restriction after verifying your identity. You can write to us from any email address, but be sure to mention your account's email address in the message.