Outbound for Mac

Frequently asked questions

Straight answers about connection rules, privacy, pricing and what Outbound does when you do not answer an alert.

Does the built-in macOS firewall block outgoing connections?

Apple’s firewall settings control incoming connections. Outbound filters outgoing connections per app and destination. The two serve different purposes.

What happens when I don’t answer an alert?

In Ask mode, unanswered connections are allowed after 8 seconds for UDP or 60 seconds for TCP by default, then added to Review. You can change the wait (15–120 seconds for TCP) or have unanswered connections blocked. Strict mode blocks connections that have no matching rule.

Can I allow an app but block some of its hosts?

Yes. Outbound rules combine an app with a host, domain, IP address, network range or local network, plus ports and protocol. A domain rule also covers its subdomains. Hostnames are shown when the app connected by name; otherwise Outbound shows an address.

Which Macs does Outbound require?

Outbound requires macOS 14 or later on Apple silicon or Intel. This is the minimum requirement, not a claim that every macOS build, VPN or Private Relay configuration has been tested.

How much does Outbound cost?

A personal licence is $39 USD one time, and the first 50 licences are $29 and includes all 1.x and 2.x updates. A family licence is $59 USD for 5 Macs. A personal licence covers 2 Macs. There is no trial.

Does Outbound collect analytics?

Not unless you ask it to. Anonymous crash reports and usage stats are off by default; you can turn them on in Settings. Rules, settings and audit logs are stored on your Mac. The app fetches blocklists you add and, on managed Macs, the rule feed your administrator sets. If you add a cloud model for the Analytics overview, it receives figures only after you turn on Send figures to it. Administrators can export audit logs to a chosen destination.

Is Outbound open source?

No. Outbound is closed source. It includes the Mozilla Public Suffix List under the MPL-2.0 licence to identify registrable domains.

Can my IT team manage Outbound?

Yes. Outbound has sample MDM profiles, managed preferences, an HTTPS rule feed with optional SHA-256 pinning, and JSON Lines audit export. Teams licensing is per seat, billed yearly. Contact us for pricing.

What are the three modes?

Learn allows connections without a matching rule and records them in Review. Ask asks you first. Strict blocks them without asking. Your rules apply in every mode, and a new install starts in Learn.

What does “this domain” mean?

For api.example.co.uk, the registrable domain is example.co.uk. Outbound uses the Mozilla Public Suffix List to find it. A rule for that domain also covers its subdomains.

Can I back up rules or use Terminal?

Yes. The outboundctl command ships inside the app. It can export and import rules, check status, switch profiles, manage blocklists, export audit logs and validate rule feeds. The rule store also keeps a backup of the previous version.

Does Outbound work with a VPN or Private Relay?

No compatibility result is published yet. Outbound uses Apple’s Network Extension content-filter API. Test your particular VPN and macOS build before relying on it. Version 1 installs no DNS proxy.

How do I uninstall Outbound?

Open Outbound, choose Settings › General › Remove Outbound. It removes the network filter, its System Settings entry and the background agent, and can also delete your rules, settings and history; then it offers to move the app to the Trash. Ask your administrator if the controls are managed.

How will app updates arrive?

Outbound checks for updates itself and installs them when you agree (Settings › Updates). Each release is signed and notarized, and its notes are on the changelog. Licences include all 1.x and 2.x updates.

My network stopped working — is it Outbound?

Choose Help › Network Not Working? in Outbound, or that row in the menu bar panel. It shows Outbound’s state with Pause for 15 Minutes and Turn Off, what Outbound blocked in the last 30 minutes with a one-click Allow, other network filters or VPNs that macOS reports, and a note about iCloud Private Relay.

What does Report a Problem send?

Your description of the problem. If you choose, it adds diagnostics: versions, Mac model, macOS, Outbound’s mode and status, rule counts and open problem codes, with no sites, addresses or app names. Only if you tick it, it adds the last 30 minutes of Outbound’s own log, which can name sites. You see exactly what will be sent first, or you can save it to a file instead. Reports go to outboundfirewall.com over HTTPS and are kept only to fix the problem.

Does Outbound show how much data each server used?

Yes. When a connection closes, the filter records exactly how many bytes it sent and received. The Network Monitor shows them under Sent and Received on each destination and domain row and in the inspector. Live per-app traffic comes from sampling.

Can AI apps like Claude or Cursor use Outbound?

Yes, if you add it. Outbound includes a Model Context Protocol server (outboundctl mcp), and Settings › Intelligence has an Add Outbound to button for Claude, Cursor, Codex, Gemini CLI and VS Code. Those apps can ask about your apps, the sites and countries they reach, what was blocked and your rules. They see the same figures as Analytics, never the contents of a connection. They can ask to add, remove, turn on or turn off a rule; Outbound shows you exactly what would change and makes the change only if you allow it. You can switch this off.

Can Outbound use my Claude, ChatGPT, Grok or Cursor subscription instead of an API key?

Yes, from Outbound 1.0.9. In Settings › Intelligence, choose a coding agent installed on this Mac: Claude Code, Codex, Grok, Cursor, Gemini CLI, GitHub Copilot, OpenCode, Factory Droid, Goose, Kimi CLI, Qwen Code, Kilo, Cline, Auggie, or another agent that supports the Agent Client Protocol. Turn on Answer with it, and it answers in Assistant and writes the Analytics overview under your own sign-in, with no API key. It reads Outbound’s figures through Outbound’s own tools and sends them, with your questions, to its company. From Outbound it can’t read your files or run commands, and any rule change it asks for waits for your approval.

Does Outbound send my network data to an AI service?

Not unless you set it up. The Analytics overview is written by Apple Intelligence on your Mac, and a Mac without Apple Intelligence shows a plain summary. If you choose your own model (OpenAI, Anthropic, Google Gemini, OpenRouter, or an OpenAI-compatible server such as Ollama or LM Studio), your key is stored in your keychain and nothing is sent until you turn on Send figures to it. Then it receives totals, app names, website domains and countries for the range, never addresses, full host names, file paths, rules, or what was sent. Show What’s Sent… displays the exact request before anything leaves the Mac. You can instead answer with your own coding agent, such as Claude Code or Codex; it sends your questions and the figures it reads to its company under your own sign-in, only after you turn it on.

Can the map show a globe?

Yes. The Network Monitor map has 2D and 3D, where 3D is a real globe, with Standard, Muted and Satellite styles. The floating globe, turned on in Settings › Labs, can be resized and held to move, with five themes: Graphite, Blue Marble, Midnight, Daylight and Amber. The menu bar panel can show a flat map or a globe.

Can I limit how much data an app uses?

Yes. Set a daily data limit for an app in the inspector. Outbound tells you at 80 % and at the limit, and if you choose Block Until Midnight, it blocks the app until midnight with a rule that removes itself. Smart filters in the search field also find heavy users, new apps, unsigned apps, ad and tracking hosts, and AI apps.

Can I tell Outbound to allow any port for an app?

Yes. The alert lets you choose only this port, any port, or any port and protocol.

Still have a question? Contact support or read the Mac firewall guides.