Remote Headshots · for IT
What to allow before the sessions
One page. Print it or forward it as is.
| Sending domain | mail.remote-headshots.com (transactional mail from [email protected]) |
|---|---|
| SPF | See the Resend dashboard for the current SPF record. |
| DKIM | See the Resend dashboard for the current DKIM record. |
| DMARC | v=DMARC1; p=quarantine; rua=mailto:[email protected] |
| Safe Links / URL rewriting | Allow-list portal.remote-headshots.com and mail.remote-headshots.com. Our sign-in link needs a button press on the page, so a scanner that pre-opens links cannot sign anyone in — but rewriting can still break the 15-minute expiry. |
| Camera policy origin | https://portal.remote-headshots.com must be allowed to use the camera and microphone in the browser (Chrome, Edge, Safari, Firefox). An MDM policy that blocks getUserMedia stops the session dead. |
| Video | LiveKit Cloud: allow *.livekit.cloud on TCP 443 and UDP 50000–60000 (it falls back to TURN over TCP 443). One 720p WebRTC call per session. |
| Uploads | Browser to Supabase Storage over HTTPS, resumable. Roughly 100 MB per 15-minute session. |
| In-app browsers | The Slack, Teams and LinkedIn in-app browsers cannot use the camera. The portal detects them and asks for a real browser. |