What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
To whitelist screenshot API traffic, allow the screenshot renderer’s documented outbound IP addresses or CIDR ranges at the firewall protecting the website it needs to capture. Restrict the rule to the required destination and HTTPS on TCP port 443, then make a real capture and verify the source address in your firewall or WAF logs. If you mean traffic from your own application to the screenshot API, that is a different direction and requires a rule at the API provider.
First determine which traffic you need to allow
“Screenshot API traffic” can mean two separate network connections. Identify the blocked connection before changing firewall rules; allowing the wrong source at the wrong destination will not fix it.
| Connection | Source seen by the destination | Where the allowlist belongs |
|---|---|---|
| A hosted screenshot renderer loads your website | The renderer’s outbound (egress) IP address | Your website’s firewall, WAF, reverse proxy, or gateway |
| Your application calls a screenshot API | Your application’s outbound IP address | The screenshot API provider’s network controls, if it offers an allowlist |
| A provider sends a webhook to your application | The webhook sender’s outbound IP address | Your application’s inbound firewall or gateway |
For the common case—an API rendering a page on your site—the renderer is the client and your site is the destination. Your origin therefore sees the screenshot provider’s egress address as the source. Do not substitute your own server’s IP or the screenshot API’s public hostname for that source address.
Find the provider’s current outbound ranges
Use the screenshot provider’s official, current IP-ranges documentation or ask its support team for the ranges used by the rendering service and the relevant region. Confirm whether the list covers all renderers, only a particular region, or a particular product or deployment. A range published for one provider is not valid for another.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
For example, ScreenshotOne’s IP-ranges documentation identifies Google Cloud east-4 ranges, a Hetzner GPU renderer address (95.216.67.59) when applicable, and a New York DigitalOcean range for customers configuring firewall or proxy allowlists. Those are provider-specific details, not universal screenshot-service addresses. Check ScreenshotOne’s current documentation and your own account or deployment details before using them; infrastructure and ranges can change.
Do not infer permanent egress addresses from a DNS lookup unless the provider explicitly guarantees that DNS-based approach. A service hostname may resolve to front-end addresses that are not the addresses its renderers use to connect to your origin.
Build a least-privilege firewall or WAF rule
Once you have confirmed the renderer’s source ranges, add only the entries needed for the site being captured. Where your security product supports it, limit the rule to the relevant hostname, path, or resource pattern as well as the source range. A typical screenshot fetch uses HTTPS over TCP 443, but confirm the destination and traffic requirements for your own service.
Rank #2
- 【Professional Firewall & NAS SERVER】OAKNODE 10gbe Firewall Appliance Mini PC-MGNASN, a powerful professional firewall router pc equipped with a 12th Gen Alder Lake N100 4C/4T up to 3.4GHz TDP only 6W with Intel UHD Graphics which maximizes the performance of the 2.5GbE port & SFP+ port, bring you a smooth secured and encrypted network environment.
- 【Rich I/O to meet your needs】Firewall Appliance MGNASN With HDMI 2.0+DP 1.4+TYPE-C(dp 1.2) Support for 3x4K@60Hz together, Dual DDR4 RAM slot support for up to 1x32GB SO-Dimm laptop DDR5 Ram Maximum 5600Mhz and 1xM.2 NVMe/PCIe 3.0x1 2280 SSD slot +1*SATA 3.0 SSD/HDD slots (install externally), also it support boot from TF card slot and it also support PXE/AWOL/Watchdog/GPIO etc. which is perfect for your firewall appliance、VM、Router、home Server needs.
- 【2xSFP+ 10GbE + 4x2.5GbE】This Firewall Router equipped with 2xIntel 82599ES 10gbe network card and 4*Intel i226-V network card speed maximum up to 2.5GbE(need other device like router, cables etc. also support 2.5Gbe/10gbe)which can bring you more faster and professional network usage(some system not release drivers yet) suggest to install version of below systems: pf-sense plus 23.0X or CE 2.7.X, OPNsense 22.1, OpenWrt, ROS7, ESXI 8 , Proxmox, CentOS etc).
- 【4G LTE Function supported】This model also support 4G LTE function(mini PCIE slot for 4G modem) and SIM card slot which you can use it as a IOT devices for your server.
- 【Quality With Warranty】If you have any questions or requirements(like OS installation/ drives/bios updates etc.) on OAKNODE Firewall mini pc MGNASN, PLEASE feel free to contact us. We offered 12 Months warranty for it and WE'LL REPLY YOUR Questions within 12 hours(during Workdays).
- Use the provider’s documented IP addresses or CIDRs—not an entire cloud provider’s network.
- Permit only the required protocol and port, normally TCP 443 for HTTPS.
- Constrain the destination to the relevant site or service, and use a host, path, or resource-pattern condition when available.
- Keep existing deny rules and their order in mind. Cloudflare’s Browser Rendering API screenshot documentation says, “Reject rules are applied first.” If a reject rule matches, a later allow rule may not have the effect you expect.
- Record the rule owner, source of the ranges, review date, and rollback procedure.
There is no provider-neutral command or exact UI path for this change: firewall and WAF interfaces differ, and the correct CIDRs depend on the renderer and region. In the relevant product, create an inbound rule at the protected destination, set the source to the verified ranges, choose HTTPS/TCP 443, and scope the destination as narrowly as its controls allow. Avoid opening all ports or all traffic from a large hosting provider merely to make one capture work.
Keep IP allowlisting separate from authentication
An IP allowlist is an additional network control, not a replacement for API keys, bearer tokens, authorization checks, or webhook verification. Keep the authentication mechanism required by the service enabled and protect its credentials. Screenshot API documentation may support bearer authentication or an X-Api-Key header; use the method documented for your specific provider and endpoint.
For a site that is intentionally restricted to an allowlisted renderer, remember that this network rule does not decide whether a requested URL is safe or authorized. Your application should still control which URLs may be captured and what data can be reached. Do not use screenshot services to circumvent CAPTCHAs, bot checks, IP bans, or rate limits.
Rank #3
- BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
- COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
- POWERFUL - A dual core ARM Cortex-A53 1.2 GHz delivers near gigabit routing of common home iPerf3 traffic and in excess of 650 Mbps of firewall throughput.
- COMPACT - Low power draw, a compact form factor, and silent operation allow it to run unnoticed when placed on a desktop, wall, or rack.
- FLEXIBLE - Three (3) 1 GbE switched (WAN/LAN/OPT) ports allow you to configure three separate 1 GbE switched ports for upto a gigabit of bi-directional traffic.
Test the rule and verify what happened
- Note the time, target URL, and request or job ID for a real screenshot attempt.
- Inspect the destination firewall, WAF, proxy, and application logs for that timestamp. Find the actual source IP and the action taken.
- Compare the observed source with the provider’s current range list and confirm the request reached the expected hostname and port.
- If the rule was just changed, allow for policy propagation where the platform documents a delay, then retry and check logs again.
- After success, confirm that the rule allows only the intended source and destination. Remove temporary diagnostic exceptions.
Logging is essential: a screenshot failure alone does not prove that an IP rule is responsible. A page can fail because of authentication, a redirect, a timeout, a bot challenge, or an application error. Use the relevant request ID and timestamp to correlate the renderer’s attempt with events at your edge and origin.
Handle calls, renders, and webhooks as separate flows
Your application calling the API
If your application’s request to the screenshot API is blocked, the relevant source is your application’s egress address as observed by the API provider. Check whether the provider actually supports client-IP allowlisting and whether it expects one stable address or CIDRs. An allowlist configured on your own website will not authorize this outbound API call.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The renderer fetching your page
If the API accepts your job but the captured page is blank, incomplete, or inaccessible, investigate the renderer-to-origin path. Check the source ranges at the origin-facing firewall or WAF, and inspect whether a more specific proxy or application rule is rejecting the request.
Rank #4
- 【CPU】Intel Pentium J3710 4-Core/4-Thread processor, up to 2.64GHz, with 2MB L2 Cache and 6W TDP. Supports AES-NI and suitable for firewall, router, VPN and other network applications.
- 【Ports & Expansions】Equipped with 4 x 2.5GbE Intel i226-v LAN ports. Includes 2 x USB3.0, 1 x HDMI. 1 x VGA ports.Supports optional Wi-Fi and 3G/4G module expansion, plus a VESA mounting kit.
- 【Fanless & Low-Power Design】6W fanless design with an aluminum alloy chassis for quiet, low-maintenance operation. Design for 24/7 continuous use and suitable for home networks, small office and network labs.
- 【RAM & Storage】Includes 8G DDR3 RAM and a 128GB mSATA SSD. Supports up to 8GB RAM and 512GB mSATA storage. HDD storage is not supported. Compact 5.27 x 4.98 x 1.43-inch design weighs only apporximately 500g.
- 【Warranty & Support】Tested with pfSense, OPNsense, Ubuntu and other popular open-sourse OS. Supports Proxmox VE for virtualization and home lab applications. Includes a 12-month hardware warranty and lifetime technical support. (Press "DEL" to the BIOS)
Webhook callbacks
A webhook is a separate inbound connection to your application. Apply its own authentication and validation controls, including signature verification when supported; do not assume that allowing renderer IPs also allows or authenticates callbacks. Screenshot API documentation describes webhook delivery but notes that callbacks may be unavailable on a given deployment. If that applies, use synchronous rendering instead of designing around an unavailable callback.
Troubleshoot common allowlist failures
| Symptom | Likely cause | What to check or change |
|---|---|---|
| The screenshot request is rejected, but the site still works in a browser | The origin blocks the renderer’s egress IP, or the wrong direction was allowlisted | Inspect origin/WAF logs, identify the observed source, and compare it with the renderer’s current documented ranges. |
| The allow rule exists but the request is still denied | A reject rule, different hostname, proxy, or narrower path rule takes precedence | Check rule order and the full request path through the edge. Cloudflare documents that reject rules are evaluated first for its screenshot method. |
| A previously working capture starts failing | Provider ranges or rendering infrastructure may have changed, or a stale rule remains | Re-check the provider’s authoritative range list and correlate the failed request with current logs before editing rules. |
| The API returns HTTP 401 | It may be an authentication failure, but an IP allowlist can also cause an authorization response | Check the response body and provider logs. OpenAI’s documented allowlisting behavior uses ip_not_authorized for a blocked source; do not assume every 401 is a bad API key. |
| A just-added allowlist entry has no effect | The change may not have propagated, or the entry may not match the actual source address | Verify the configured CIDR and source in logs. OpenAI says changes to its documented allowlisting implementation may take up to 15 minutes to propagate; that timing should not be generalized to other providers. |
| The page still fails after network access is allowed | The failure may be application-level, or the site may present a CAPTCHA, bot check, or other access challenge | Review the capture response and origin logs. Do not try to bypass access controls; obtain legitimate access or adjust the site’s own authorized integration path. |
Maintain the allowlist as infrastructure changes
Provider ranges, regional routing, webhook availability, and acceptable-use rules can change. Assign an owner to review the range source on a schedule and when captures begin failing. Keep the source URL or documentation name, date checked, affected firewall rule, and rollback steps in change control. Remove obsolete entries rather than leaving old ranges open indefinitely.
When choosing a provider or reviewing an existing integration, compare whether it publishes maintainable egress ranges, supports regional routing, provides request IDs and useful logs, and documents authentication and webhook verification. These operational details matter as much as whether an endpoint can return an image.
Best Value
- 【CPU Optimized for Firewall Mini PCs】This firewall appliance is powered by Intel Quad-Core Celeron J1900, 64-bit, up to 2.0 GHz, supporting software-based encryption. Energy-efficient and reliable, it runs 24/7 for home or small office networks, handling VPNs, multi-WAN routing, and basic firewall tasks efficiently.
- 【4×Intel i210 Ports】Equipped with four Intel i210 network controllers, each delivering up to 1 GbE for reliable multi-WAN routing, VPN connections, VLAN management, and stable performance in small office or home firewall deployments
- 【Memory & Storage】This Firewall Mini PC comes with 4 GB DDR3L RAM and a 64 GB mSATA SSD, providing reliable performance for basic networking tasks. AMI BIOS with ACPI support ensures stable system operation and energy-efficient 24/7 use
- 【Flexible System Compatibility】Compatible with Windows 10, Linux, and professional firewall systems such as pfSense, OPNsense, and VyOS, ensuring stable network management for home or small office use
- 【After-Sales Support:】This compact, fanless, and silent firewall keeps your network secure. Includes lifetime technical support and a 30-day money-back guarantee!
Or skip the browser setup
ScreenshotNeo is a screenshot API and MCP server from Yorker Media. Its documented product facts here do not include published renderer egress IP ranges, so do not add guessed ScreenshotNeo addresses to an origin allowlist; consult its current documentation or support if your network policy requires fixed renderer sources. If you can call an API endpoint directly, a single request can capture a URL without setting up a browser locally. See the ScreenshotNeo API documentation.
cURL example:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
The same endpoint can be called from Python or Node.js:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo removes supported cookie and consent banners, newsletter popups, and chat widgets before capture, with each step optional. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed; response headers identify the page verdict and billing status. Its MCP server provides screenshot and PDF tools for AI agents. The free plan includes 1,000 screenshots per month without a card; paid plans start at $5 for 3,000 shots. For network-restricted deployments, confirm the egress-range requirements before relying on any allowlist.
Sign up for ScreenshotNeo’s free plan: 1,000 screenshots a month, no card required.
Frequently Asked Questions
Does whitelisting an IP mean my screenshot API key is no longer needed?
No. Treat network allowlisting and API authentication as separate controls; retain and protect the credentials required by your provider.
Can I allowlist a screenshot service’s domain name instead of IP ranges?
Only if your firewall supports that safely and the provider documents it as a supported model. A hostname lookup is not a reliable substitute for a provider-guaranteed renderer egress list.
Should I whitelist a screenshot service to get past a CAPTCHA or IP ban?
No. Do not use a screenshot service to circumvent CAPTCHAs, bot detection, IP bans, or rate limits.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

