Skip to main content
Question

Requesting Google reCAPTCHA domain set

  • December 2, 2025
  • 2 replies
  • 45 views

berniebrownsf

Hi, 

We are in the process of setting up Google reCAPTCHA and are facing an issue related to URL filtering on our Palo Alto firewall. We created URL filtering rules to allow only recaptchaenterprise.googleapis.com, but reCAPTCHA is still not functioning as expected.
 

During troubleshooting, access began working immediately after we removed the URL filtering restrictions, which confirms that the firewall had been blocking one or more additional Google domains required for reCAPTCHA validation.
 

However, when we re-enabled the URL filtering policy and permitted only recaptchaenterprise.googleapis.com, the issue returned. This indicates that reCAPTCHA Enterprise relies on multiple backend Google domains, and allowing just this single URL is not sufficient for the complete validation workflow.
 

To fully restore functionality, we may need to allow the complete Google reCAPTCHA domain set as recommended by Google, instead of permitting only a single hostname.

 

Please advise on the exact list of domains and URLs required by reCAPTCHA Enterprise so that we can update our allow-list accordingly. 

Thanks

2 replies

asendogdular
  • New Member
  • December 4, 2025

Hi, 

We are in the process of setting up Google reCAPTCHA and are facing an issue related to URL filtering on our Palo Alto firewall. We created URL filtering rules to allow only recaptchaenterprise.googleapis.com, but reCAPTCHA is still not functioning as expected.
 

During troubleshooting, access began working immediately after we removed the URL filtering restrictions, which confirms that the firewall had been blocking one or more additional Google domains required for reCAPTCHA validation.
 

However, when we re-enabled the URL filtering policy and permitted only recaptchaenterprise.googleapis.com, the issue returned. This indicates that reCAPTCHA Enterprise relies on multiple backend Google domains, and allowing just this single URL is not sufficient for the complete validation workflow.
 

To fully restore functionality, we may need to allow the complete Google reCAPTCHA domain set as recommended by Google, instead of permitting only a single hostname.

 

Please advise on the exact list of domains and URLs required by reCAPTCHA Enterprise so that we can update our allow-list accordingly. 

Thanks

 

Also I’ve got same problem with you and I cannot find any solutions yet.


CoryKramer
Staff
Forum|alt.badge.img+2
  • Staff
  • December 4, 2025

The address recaptchaenterprise.googleapis.com is correct for the call to the backend.

Though you’ll also want to add the endpoints for the frontend part of the integration:

  • https://www.google.com/recaptcha/ (Main loader script)

  • https://www.gstatic.com/recaptcha/ (Dependencies, executable code, and resources)

  • https://www.recaptcha.net/ (Alternative/Global domain often used for failover or specific network configs)

These are also relevant if the site has CSP configured as mentioned in https://docs.cloud.google.com/recaptcha/docs/faq#csp-configuration