How to manage internal domains in Dropbox Protect

Admins Updated Aug 05, 2026

In this article

person icon

The information in this article applies to Dropbox Protect users.

Internal domains tell Dropbox Protect which company domains are treated as internal. Protect uses up to 25 domains to organize owners, collaborators, and shared content as internal, external, or outside.

Use this setting if your organization has multiple company domains, subdomains, or if your internal domains have changed.

How to view your internal domains

  1. Log in to Dropbox Protect. Learn more about accessing Protect.
  2. Click your avatar (profile picture or initials) in the bottom-left corner.
  3. Select Admin console from the dropdown menu. The admin console opens with the Protect section already expanded, and you'll see Settings under ProductsProtect.
  4. Find the Internal domains row under Security and click  Edit.
  5. Review your current domains and subdomains.
  6. Click Cancel.

How to add an internal domain

  1. Log in to Dropbox Protect. Learn more about accessing Protect.
  2. Click your avatar (profile picture or initials) in the bottom-left corner.
  3. Select Admin console from the dropdown menu. The admin console opens with the Protect section already expanded, and you'll see Settings under ProductsProtect.
  4. Find the Internal domains row under Security and click  Edit.
  5. In the Add domain field, enter your company domain (for example, yourcompany.com) and any additional domains.
    • If you have Microsoft OneDrive connected to Protect, Microsoft generated domains are automatically considered internal.
  6. Click  Add, then Save.

Tips for adding internal domains

When adding internal domains, keep the following rules in mind:

  • Enter bare domains like “yourcompany.com” or “subdomain.yourcompany.com”
  • Each domain can only appear once in the list.
  • A maximum of 25 internal domains can be added.
  • If you have Microsoft OneDrive connected to Protect, these Microsoft generated domains will automatically be considered internal:
    • yourcompany.sharepoint.com
    • yourcompany-my.sharepoint.com
    • yourcompany.onmicrosoft.com
    • yourcompany.sharepointonline.com
  • Formats that aren’t supported:
    • URLs (for example, https://yourcompany.com)
    • Email addresses (for example, user@yourcompany.com)
    • Wildcards (for example, *.yourcompany.com)
    • The @ symbol on its own
    • Personal email domains (for example, gmail.com, yahoo.com, outlook.com)
highlighter icon

Notes:  

  • You’ll see items from the newly added domains immediately in Protect.
  • Microsoft generated domains are read-only and can’t be edited separately. They update automatically when you add or remove base domains, and don’t count toward the internal domain limit.

How to remove an internal domain

  1. Log in to Dropbox Protect. Learn more about accessing Protect.
  2. Click your avatar (profile picture or initials) in the bottom-left corner.
  3. Select Admin console from the dropdown menu. The admin console opens with the Protect section already expanded, and you'll see Settings under ProductsProtect.
  4. Find the Internal domains row under Security and click  Edit.
  5. Click [remove] next to the domain you want to delete.
  6. Click Save.
highlighter icon

Note: One domain must be listed for Protect to organize items correctly. After removing a domain, content previously marked as internal for that domain will be listed as external in Protect reports.

Was this article helpful?

Let us know how why it didn't help:

Thanks for letting us know!

Thanks for your feedback!