Desktop client
The client also needs three further hosts: the fallback for the backend, licence validation on sign-in, and the host the installers are downloaded from. We send the full list, with the purpose of each and what breaks if it is blocked, by email. Ask at support@reclaimtime.com and we will reply with the exact hosts for your organisation.
Clients before 8.0 connected to what is now the fallback host directly, with no fallback of their own. If you have a mixed fleet mid-rollout, both backend hosts are in use at once, which is another reason to allow the pair.
Dashboard
The dashboard is reached from a browser only. It does not need anything installed and does not open connections back to the client.
Version files
If your policy allow-lists paths rather than hosts, these are the version files the client reads. The installer download paths come with the host list.
Organisations on a dedicated channel have their own equivalents. Ask us for yours.
Installers are code signed as FocusMe (Reclaim Time Ltd) and timestamped, so check the signature rather than the host a file came from. See Code signing and tamper resistance.
Endpoint protection
Two behaviours regularly trip up endpoint protection and are worth exempting rather than investigating each time:- The client restarts itself if it is closed or ended. That is intentional. It is what stops tracking being ended by closing a window.
- Updates download an executable and run it silently. This is the normal update path, not an unexpected download.
Quick test from a machine
If a client is not reporting and you want to know whether the network is the reason, these should succeed from the machine itself:Test-NetConnection against each host on the list we send you, substituting your own backend pair if you have a dedicated one. If the first command returns a version number and the rest connect, the network is not the problem, and the answer is on First login and SSO.
Checked against ReclaimTime client 8.0.0.9 and dashboard V3 on 5 September 2026.

