Network requirements: allowlisting DraftPilot for your firewall or web proxy
Last updated: 19 July 2026
Who this is for: IT / network administrators rolling out the DraftPilot Word add-in across a managed network.
Summary
The DraftPilot add-in runs inside Microsoft Word and relies on a small number of web domains being reachable. On tightly managed corporate networks, a firewall, web proxy, or SSL-inspection (secure web gateway) product can block one or more of these, which stops the add-in from loading. Allowlisting the domains below resolves it.
Domains to allow
Please allow the following hosts over HTTPS (port 443) through your firewall, web proxy, and any SSL-inspection / secure web gateway, for the machines that run the add-in:
Domain
Purpose
appsforoffice.microsoft.com
Microsoft’s Office.js runtime. Word needs this to start any add-in. If it’s blocked, no Office add-in (including DraftPilot) can initialise.
app.draftpilot.ai
The DraftPilot add-in itself (the task pane you see in Word).
api.draftpilot.ai
The DraftPilot API (reviews, document chat, playbooks, etc.).
Region note: the domains above cover our EU and standard deployments. If your organisation is on a dedicated/US deployment, your account manager will confirm any additional hosts.
Symptoms of a blocked network
If one of these domains is blocked, users typically see one of the following in Word:
-
A “can’t load” / blocked screen where the DraftPilot task pane should be (most often when
appsforoffice.microsoft.comis blocked). -
The add-in opens but is missing the “Review” tab or behaves like a plain web page rather than a Word add-in.
-
The task pane sits on a spinner and never finishes loading.
These are network-level blocks, not a problem with your DraftPilot account or licence.
How to confirm and fix
-
Ask your IT/network team to allow the three domains above (and disable SSL inspection for them, or allow the DraftPilot/Microsoft certificates).
-
Have the affected user fully close and reopen Word.
-
The add-in should now load normally.
Still stuck?
If the add-in still won’t load after allowlisting, contact us at [email protected] and let us know:
-
which domain(s) you’ve allowed,
-
whether SSL inspection is in use, and
-
roughly how many users are affected.
We’re happy to jump on a short call with your IT team to work through it.