Domains used by Granola
Granola is in the Meeting recorder category. These 2 domains and their subdomains identify its traffic in DNS, proxy and firewall logs.
These services join, record or transcribe meetings and keep the transcripts, so it matters who agreed to the recording and where it's stored.
Domain list
| Domain | Covers |
|---|---|
granola.ai | granola.ai and every subdomain (*.granola.ai) |
granola.so | granola.so and every subdomain (*.granola.so) |
granola.ai granola.so
Block or allow Granola
Ready-made entries for common systems. Blocking can break things people rely on, so decide with the teams who use it first.
Plain domain list
One domain per line. Most DNS filters, secure web gateways and firewalls accept this for custom lists; set the list to include subdomains.
# Block list — Plain domain list # Granola (2 domains) # Generated by Shadow AI Finder (shadowaifinder.com) # One domain per line. Most DNS filters, secure web gateways and firewalls accept this for custom lists; set the list to include subdomains. granola.ai granola.so
Wildcard list (*.domain)
Each domain plus a *.domain entry, for gateways that need explicit wildcards.
# Block list — Wildcard list (*.domain) # Granola (2 domains) # Generated by Shadow AI Finder (shadowaifinder.com) # Each domain plus a *.domain entry, for gateways that need explicit wildcards. granola.ai *.granola.ai granola.so *.granola.so
Hosts file
Blocks exact names only; subdomains not listed here still resolve. Use a DNS filter for full coverage.
# Block list — Hosts file # Granola (2 domains) # Generated by Shadow AI Finder (shadowaifinder.com) # Blocks exact names only; subdomains not listed here still resolve. Use a DNS filter for full coverage. 0.0.0.0 granola.ai 0.0.0.0 www.granola.ai 0.0.0.0 granola.so 0.0.0.0 www.granola.so
dnsmasq
address=/domain/ also blocks every subdomain.
# Block list — dnsmasq # Granola (2 domains) # Generated by Shadow AI Finder (shadowaifinder.com) # address=/domain/ also blocks every subdomain. address=/granola.ai/0.0.0.0 address=/granola.so/0.0.0.0
Unbound
Add to unbound.conf under server:. always_nxdomain covers subdomains.
# Block list — Unbound # Granola (2 domains) # Generated by Shadow AI Finder (shadowaifinder.com) # Add to unbound.conf under server:. always_nxdomain covers subdomains. local-zone: "granola.ai." always_nxdomain local-zone: "granola.so." always_nxdomain
BIND response policy zone (RPZ)
Records for a response-policy zone. Add your zone's SOA and NS records at the top.
; Block list — BIND response policy zone (RPZ) ; Granola (2 domains) ; Generated by Shadow AI Finder (shadowaifinder.com) ; Records for a response-policy zone. Add your zone's SOA and NS records at the top. granola.ai CNAME . *.granola.ai CNAME . granola.so CNAME . *.granola.so CNAME .
Pi-hole regex
Add as regex blacklist (or whitelist) entries. Each line matches the domain and its subdomains.
# Block list — Pi-hole regex # Granola (2 domains) # Generated by Shadow AI Finder (shadowaifinder.com) # Add as regex blacklist (or whitelist) entries. Each line matches the domain and its subdomains. (\.|^)granola\.ai$ (\.|^)granola\.so$
Squid dstdomain
A leading dot matches the domain and all subdomains. Use with an acl ... dstdomain "/path/file" rule.
# Block list — Squid dstdomain # Granola (2 domains) # Generated by Shadow AI Finder (shadowaifinder.com) # A leading dot matches the domain and all subdomains. Use with an acl ... dstdomain "/path/file" rule. .granola.ai .granola.so
Check a log for Granola
Paste log lines to see whether Granola shows up and how often. Nothing leaves your browser.
Knowing the domains is step one
A list tells you where traffic goes. Agent Trust Cloud keeps an inventory of AI agents, who owns each, and what it may do, and applies your policy before an agent acts. Discover, the monitor-only tier, is free.