Mac firewall comparison
Little Snitch vs LuLu
Choose Little Snitch for encrypted DNS, automatic profile switching and a long-established network monitor. Choose LuLu for a free, open-source firewall with app and endpoint rules, profiles and a bundled network monitor. Compare the workflow you need, not just the price.
Updated
Published by Outbound, which is also listed below. Facts about Little Snitch and LuLu come from their makers’ pages, checked October 4, 2026. This is a feature comparison, not a benchmark.
At a glance
| Criterion | Little Snitch | LuLu | Outbound |
|---|---|---|---|
| Price and licence | Commercial single, family and multi licences. Check the seller’s order page for the price in your region. | Free; GPL-3.0 licence. | Launch pricing: personal $39 USD one time, $29 for the first 50 licences; family $59 USD one time for 5 Macs. |
| Source availability | Not stated by the vendor | Open source on GitHub. | Closed source. |
| Per-app rules | Allow, deny or ask rules for a specific process. | Allow or block a whole program. | Rules for a signed app or an exact file path. |
| Per-host and domain rules | Server, domain and IP address rules. | Remote address or domain rules. | Host, domain, IP address, CIDR range or local network rules. |
| Alerts | Allow or deny connection alerts; Silent Mode is also available. | Allow or block connection alerts. | Learn, Ask and Strict modes. Ask alerts name the developer from the app’s signing certificate and quote an app’s Internet Access Policy when one is shipped. |
| Network monitor and map | Network Monitor with a geographic connection map. | Bundled Netiquette network monitor. Map: Not stated by the vendor. | Network Monitor grouped by app, with exact bytes per destination for closed connections, a traffic chart with time selection, scoped search and a map of server locations. |
| Blocklists | Hosts, domains and IP address lists. | Allow and block lists containing hosts or IP addresses. | HTTPS hosts, domain or CIDR lists. |
| DNS encryption | Built-in encrypted DNS using DoH, DoT or DoQ. | Not stated by the vendor | Not included in v1. |
| Profiles | Rule profiles with automatic switching when a network is joined. | Profiles group rules and settings. | Rule profiles; switch with outboundctl. No SSID-based switching in v1. |
| CLI or scripting | littlesnitch CLI for preferences, configuration export and logs. | Not stated by the vendor | outboundctl for status, rules, profiles, blocklists, audit export and feed validation. |
| MDM and managed deployment | MDM deployment with centrally managed rules and settings. | Not stated by the vendor | Sample MDM profiles, managed preferences, HTTPS rule feed, optional SHA-256 pinning and JSON Lines audit export. |
| macOS requirement | Little Snitch 6 supports Sonoma, Sequoia, Tahoe and Golden Gate. Legacy downloads cover Ventura and earlier. | macOS 10.15 or later. | macOS 14 or later on Apple silicon or Intel. |
Sources: Little Snitch product page · LuLu product page.
Which should you choose?
Little Snitch suits people who want encrypted DNS, automatic network-based profiles and a long-established network monitor with a map. LuLu suits people who want free, inspectable source alongside app and endpoint rules. Both have connection alerts, profiles, blocklists and a network monitor. Outbound publishes this comparison. The Outbound column describes its stated features, not a hands-on test against either product.
Where Little Snitch is the better choice
Choose Little Snitch if you want to see connections on a map, encrypt DNS requests, or switch profiles automatically as you join different networks. Its command-line tool and MDM deployment documentation also make it worth evaluating for managed Macs. Managed deployment is not an Outbound-only feature. Little Snitch is sold commercially; check its order page for the licence and regional total you need.
Where LuLu is the better choice
Choose LuLu if a free licence and open source are requirements. It can apply a decision to a whole program or a remote endpoint, use domain or address rules, and group rules and settings in profiles. It also has allow and block lists and includes the Netiquette network monitor. Test destination matching with the apps you use before relying on it. A cell marked Not stated by the vendor means the reviewed documentation does not establish that feature, not that the feature is impossible.
Where Outbound fits
Evaluate Outbound if app and destination rules, explicit Learn, Ask and Strict modes, and its managed rule feed and audit export match your workflow. Learn allows unmatched connections and puts them in Review; Ask asks first, and by default allows a connection you do not answer after 8 seconds (UDP) or 60 seconds (TCP), or blocks it if you choose; Strict blocks unmatched connections. Existing rules apply in each mode. Outbound is closed source and paid. Its Network Monitor groups connections by app, with exact bytes per destination for closed connections, a traffic chart where you can select a time window, search scoped by app, host, port, direction or rule, and a map of server locations. Version 1 has no encrypted DNS and no SSID-based profile switching. Personal pricing is $39 USD one time, $29 for the first 50 licences; family pricing is $59 USD one time for 5 Macs.
Switching notes
Keep a backup of your current rules and write down the apps and destinations you need. Outbound has no importer for Little Snitch or LuLu rules, so plan to recreate the relevant rules manually. Begin with a small set and test sign-in, sync, updates and any helper processes before expanding it. Do not assume two filters will behave the same when run together. Outbound’s minimum macOS requirement is not a compatibility test for your VPN or Private Relay setup.
Which one fits you
Choose Little Snitch if
- You want encrypted DNS built in.
- You want profiles to switch automatically when you join a network.
- You want to evaluate its CLI and centrally managed deployment.
Choose LuLu if
- You need a free firewall with open source.
- You want app and endpoint decisions, profiles and allow or block lists.
- You want its bundled Netiquette network monitor.
Choose Outbound if
- You want rules per app and per destination: host, domain, IP range and port.
- You want Learn, Ask and Strict modes with an explicit unmatched-connection policy.
- You want to evaluate an HTTPS rule feed, optional SHA-256 pinning and JSON Lines audit export.