> you can set your exit policy to a whitelist on ip/port basis, but iirc > not on a dns-name/port basis (which means you should enumerate all the > IPs belonging to a load-balanced website if you want to allow exit > access to it). Keep in mind that exit enclaves only work on the one IP your relay uses for its ORPort.