# Egress blocklist

**Policy → Egress blocklist** controls which network destinations the Endpoint Suite
allows AI tools to reach directly, outside the Gateway.

Use **Download blocklist** to get the current list, and **Copy** to take it into your own
tooling. **Send test** verifies the alerting path end to end.

This is a containment control, not a firewall: it constrains the tools Sentilai manages
on machines running the Endpoint Suite. It is not a substitute for network egress
controls at your perimeter.

<!-- shot:egress-page -->
![The Egress blocklist section on Policy — generated from your providers and routed endpoints, with Download and Copy for your network team.](https://docs.sentilai.com/uploads/images/gallery/2026-08/ODUegress-page.png)
*The Egress blocklist section on Policy — generated from your providers and routed endpoints, with Download and Copy for your network team.*