Box Zones customers connect to a Zone-specific set of Box hostnames, in addition to the standard Box domains. If your organization uses Box Zones, your firewall or proxy allowlist must include the hostnames for every Zone your people are assigned to, or those people may lose access to Box.
This article explains what each Zone-specific hostname is used for, lists every Zone’s actual hostnames, and is updated whenever Box launches a new Zone or activates a capability that changes which hostnames you need to allowlist.
Important: Action is required for France and Canada by September 15, 2026. Box is activating in-region compute for the France and Canada Zones. If your organization has any users assigned to either Zone, you must add that Zone’s endpoints (see the table below) to your firewall or proxy allowlist before September 15, 2026. Endpoints not allowlisted by that date will cause those users to lose the ability to upload, download, and otherwise work with files in Box starting September 16, 2026. This is a hard cutover, with no grace period. Add the endpoints now, even if your organization has used the France or Canada Zone for a while without needing them: see How this reference changes over time below for why.
Understanding the Zones endpoint types
Every Box Zone exposes the same four kinds of endpoint. Each Zone (except US, which uses Box’s original, unprefixed domains) has its own Zone code — for example euc1 for the EU Zone — substituted for {zone} in the patterns below.
If a person in your organization is assigned to a Zone whose hostnames are not allowlisted, they may be unable to upload or download files, even though they can otherwise sign in to Box.
Complete endpoint reference, by Zone
Only allowlisting SFTP for a specific Zone? Choose the Correct SFTP Endpoint for Your Region covers that single column on its own.
How this reference changes over time
Two recent, real changes to Box Zones show how this table is kept current:
-
July 2026: Three new Zones launched. Switzerland, Singapore, and Israel joined Box Zones as entirely new Zones, bringing the total to ten. Each arrived as a new row in the table above, with its own complete, brand-new set of hostnames — that is why the table already lists real endpoints for all three, not placeholders.
-
September 2026: An existing Zone activates a new capability. France and Canada have been available Zones for longer, but until now only for content storage location — uploads, downloads, encryption, and previews for people assigned to those Zones ran outside the Zone itself. Starting September 16, 2026, Box activates in-region compute for France and Canada: that processing now runs inside the Zone, over the Zone-specific endpoints already listed in the table above (
fupload-euw9.*, nan2.boxcloud.com, and so on), instead of wherever it ran before.
This same mechanism extends to future capabilities: when one requires hostnames that are not already in the table above, Box adds it as one new column, filled in per Zone as the capability becomes available there. A Zone that does not yet have the capability shows “Not yet available” rather than a hostname, so the table also communicates rollout status at a glance. Box announces changes like these through product announcements.
Configuring a Firewall for Box Applications and Services
Choose the Correct SFTP Endpoint for Your Region
About Box Zones
Assigning Zones through the Admin Console
New Box Zones in Switzerland, Singapore, and Israel, with expanded in-region processing for France and Canada