Allow external sharing with only trusted domains

For IT administrators of Google Workspace and Google for Education

Supported editions for this feature: Business Standard and Business Plus; Enterprise; Education Fundamentals, Education Standard, Teaching and Learning Upgrade, and Education Plus; Nonprofits; G Suite Business. Compare your edition

Let your users share only with certain organizations outside of your business or school. Add the organization's domain to your allowlist of trusted domains, and then choose sharing settings for your users.

Google services that work with trusted domains

  • Drive (includes Docs, Sheets, Slides) and Sites: Users can share files only with the domains on the allowlist. Learn more about sharing settings for Drive and Sites, and how to share with non-Google Accounts.
  • Classroom: When you put a domain on the allowlist, your users can join classes in that domain and their users can join your classes. Learn more.
  • Chat: Users in a trusted domain can chat with your organization. Depending on your Google Workspace edition, your users can create or join 1:1 messages or rooms that include users in a trusted domain. Learn about external chat options.
  • Looker Studio: Learn about Looker Studio sharing permissions.

How the allowlist works

  • You have one allowlist that includes all your trusted domains. Drive, Sites, Classroom, Chat, and Looker Studio use the same allowlist.
  • If you have Google Workspace Business Standard or Business Plus: The allowlist applies to all your users. Your users can share externally only with the trusted domains in your allowlist.
  • If you have Google Workspace Enterprise, Education, Nonprofits, or G Suite Business: You can turn the allowlist on or off for a group or organizational unit.

Set up a trusted domain

Open all   |   Close all

Add a trusted domain to your allowlist

Domains you can add to the allowlist

  • You can add a primary or secondary domain, domain alias, or subdomain. For example, if you want to share with users at sales.solarmora.com, add this subdomain to the allowlist.
  • You can add up to 5000 domains (includes domains, domain aliases, and subdomains) to the allowlist.
  • Google Workspace Essentials accounts must be domain-verified (not email-verified) to access Drive files shared with their users. 
  • Google service accounts (domain name ends with "gserviceaccount.com") can't be used as trusted domains. Learn more
  • Your domain cannot have non-English characters, such as á, ñ, ü, and ø, or any character from a non-English alphabet.

Step 1: Add a trusted domain

  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in @gmail.com).

  2. In the Admin console, go to Menu ""and then"" Accountand thenDomains.
  3. Click Allowlisted domains.
  4. Click Add domain.
  5. Enter the domain, subdomain, or multiple domains separated by commas. You can add up to 200 domains at time, and your account can have total of 5000 trusted domains.
  6. Click Add. Repeat to add more domains.
  7. Click Save.

Step 2: Review trusted domains in the allowlist

In Google Drive and Docs, you can check for that the allowlisted domain is set up correctly and uses Google Workspace.

  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in @gmail.com).

  2. In the Admin console, go to Menu ""and then"" Appsand thenGoogle Workspaceand thenDrive and Docs.
  3. Click Sharing settingsand thenSharing options.
  4. Below the Allowlisted Domains setting, click View configured allowlisted domains.
  5. Check for the alert, "Incompatible with allowlisted domains". The domain may not be using Google Workspace, or the domain name is incorrect. ​​​​​

    allowlisted domains alert
 
Set up sharing access for users
Remove a domain from your allowlist

To stop sharing between the domain and your organization, remove the domain from your allowlist. Users do not receive a notification about the change.

  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in @gmail.com).

  2. In the Admin console, go to Menu ""and then"" Accountand thenDomains.
  3. Click Allowlisted domains.
  4. Point to the domain name and click Remove.
  5. Click Remove domain.
Changes can take up to 24 hours but typically happen more quickly. Learn more
To confirm the changes, check your Drive sharing permissions or Classroom class membership.
Troubleshooting

If you can't share with a domain on the allowlist:

  1. Go to the Sharing settings for the service, such as Drive or Classroom.
  2. Below Allowlisted domains, click View configure allowlisted domains.
  3. Check for domains with the alert, "Incompatible with allowlisted domains":

  1. Check the reasons that the domain isn't on the allowlist:
  • The domain name might be misspelled.
  • The domain is a Google Service account (name ends in "gserviceaccount.com"), which isn't supported as a trusted domain. Learn more
  • For Drive: The domain isn't using Google Workspace. Follow steps to allow sharing with non-Google accounts. Or the domain is using an email-verified Google Workspace Essentials edition. Only domain-verified editions can be used in the allowlist.

  • For Classroom: Sharing isn't available because the domain isn't using Google Workspace Education Fundamentals or Google Workspace Education Plus.

  • For Chat: The domain is on the allowlist, but users can't create external spaces. If you've checked the allowlisted domains box for Chat externally, also check this box for spaces.
  • For Looker Studio: Check the sharing settings for Looker Studio.

Was this helpful?
How can we improve it?

Need more help?

Sign in for additional support options to quickly solve your issue

Search
Clear search
Close search
Google apps
Main menu
Search Help Center
true
true
true
true
73010
false
false