What Outbound does

Rules for each app and each destination, a monitor that shows what connects and how much it sends, a map you can turn into a globe, and the tools to manage many Macs at once. AI apps can ask about your network, and a rule changes only when you allow it.

Every alert names the app and where it wants to go

Alerts name the app and its developer from the app’s Developer ID certificate (“Signed by Google LLC”, “From the Mac App Store”), plus the port and protocol. Outbound shows a hostname when the app connected by name; otherwise it shows the address. It says when a server belongs to the app’s own developer, and says “Outbound doesn’t recognise this server” when it doesn’t.

When an app ships an Internet Access Policy, the alert quotes the developer’s stated purpose and what happens if you deny. This is shown only for apps signed by a developer team or Apple.

Choose Allow or Deny with Once, Until Quit, Until Logout, Until Restart, For 1 Hour or Forever, for only this port, any port, or any port and protocol. VoiceOver announces each alert, and an optional sound can play when one appears.

Outbound connection question: Google Chrome wants to connect to accounts.google.com on port 443, with a choice of how long to remember, a countdown and Allow and Deny, next to a queue of four waiting apps
The Outbound question panel, with example connections.

In Ask mode, unanswered connections are allowed after 8 seconds for UDP or 60 seconds for TCP by default, then added to Review. You can change the wait (15–120 seconds for TCP) or have unanswered connections blocked. Strict mode blocks connections that have no matching rule.

Rules with room for the details

Match a signed app by team and signing ID, or use an exact file path. Combine it with a host, domain, IP address, CIDR range or local network, then set ports, protocol, direction and lifetime. Mark a rule as a priority rule and it wins over other rules.

Outbound Rules: rules grouped by app, written as sentences, with lifetimes, profiles and managed rules
Outbound Rules, with example rules and profiles.

Path rules match exact paths. Wildcard paths are not supported. An updated binary may require reviewing its identity or path rule.

A monitor you can search

The Network Monitor lists connections under the app they belong to, with Sent, Received and Last Seen columns, live traffic bars for each app, and the map of where servers are beside the list (above it in a narrow window). Review what was allowed or denied before changing a rule. More about the network monitor.

Traffic charts draw upload above the centre line in orange and download below it in blue, each half on its own scale. Hover a column to read the time and rates, or drag across the chart to select a time window: the list and map then show only that window. The charts work from the keyboard and with VoiceOver.

When a connection closes, the filter records exactly how many bytes it sent and received, shown on each destination and domain row and in the inspector. Live traffic for each app still comes from sampling.

Search with scoped words such as app:, host:, port:, proto:, country:, direction: and rule:, with quoted values like app:"Google Chrome". A menu in the search field inserts them.

Smart filters narrow the list with tokens for AI apps, ad and tracking hosts, new apps, unsigned apps, Apple services, local network, abroad and heavy users. Set a daily data limit for an app in the inspector, and Outbound tells you when it goes over. Apps, Apple services, command-line tools and websites show their real icons in one rounded tile.

Outbound v1 does not include encrypted DNS.

Outbound main window, Activity: apps grouped with their destinations, allow and block switches, locations, a traffic chart and an inspector explaining why www.apple.com was allowed
Outbound Activity, with example connections.

The inspector says why

Select any connection and the inspector names the rule that decided it, or says no rule did and which mode stepped in. You can change the decision right there.

Apple services without the alert storm

macOS services, iCloud and Apple’s own apps are trusted from the start, matched by Apple’s signature and by where macOS keeps them, so a copy of an Apple tool somewhere else is still asked about.

Right in the menu bar

Status, mode, today’s numbers and the latest connections are a click away, with recent blocks and an Allow button beside each.

Ask about your Mac’s network

On a Mac with Apple Intelligence, ask the on-device assistant about this Mac’s network in plain language. Answers come with the records they used, as charts, a traffic timeline, a map or cards you can click to inspect. It highlights the key records and suggests follow-up questions.

Numbers are checked against the connection records. The assistant explains; it never changes your rules. Nothing leaves the Mac.

The assistant can instead answer with your own coding agent, such as Claude Code, Codex, Grok or Cursor, on the subscription you already have. Your questions and the figures it reads then go to that agent’s company under your sign-in, and any rule change it asks for waits for your approval. How it works ›

Network Not Working?

In the Help menu and the menu bar. It shows Outbound’s state with Pause for 15 Minutes and Turn Off, the blocks of the last 30 minutes with one-click Allow, other network filters and VPNs macOS reports, and a note about iCloud Private Relay.

Report a Problem

Describe the problem and, if you choose, include diagnostics with no sites, addresses or app names. Outbound’s own log of the last 30 minutes is added only if you tick it. You see exactly what will be sent first, or save it to a file instead.

Outbound setup: a drawn guide to the one switch in System Settings, Network Extensions, with the steps to turn on Outbound Network Filter

Set up in about a minute

macOS asks you to approve a network filter in System Settings. Outbound shows exactly where the switch is, opens the right page for you, and moves on by itself once macOS confirms it.

No kernel extension. Outbound uses Apple’s Network Extension framework.

Map and globe

A flat map, or a real globe

The Network Monitor map has 2D and 3D, with Standard, Muted and Satellite styles. Turn on the floating globe in Settings › Labs and it stays on your desktop: resize it, hold it to move it, and pick a theme.

  • Connection pop-ups spring in, and packets glide along great-circle arcs.
  • The menu bar panel can show a flat map or a globe.
Outbound’s floating globe at two sizes: a dotted globe turned to Europe, Africa and Asia, with app icons at the places they connect to and green and red great-circle arcs between them
The same globe in five themes, left to right: Graphite, Blue Marble, Midnight, Daylight and Amber. On a phone, only the first two are shown.
Five themes
  • Graphite
  • Blue Marble
  • Midnight
  • Daylight
  • Amber

Intelligence

Ask about your network.You pick who answers.

Assistant answers questions about this Mac’s network in plain language, and Analytics opens with a short written overview. Every number in an answer is checked against your own figures; anything that doesn’t match is replaced by Outbound’s own summary.

Apple Intelligence

On this Mac. The default.

Answers are written on your Mac, so nothing you see in Analytics leaves it. A Mac without Apple Intelligence shows a plain summary instead.

Your coding agent

The subscription you already pay for. No API key.

Choose Claude Code, Codex, Grok, Cursor or another agent installed on this Mac. It reads Outbound’s figures through Outbound’s own tools and answers under your own sign-in.

Your own API key

OpenAI, Anthropic, Google Gemini, OpenRouter, or a local server.

Writes the Analytics overview with the model you choose, including Ollama or LM Studio on your own network. Your key stays in your keychain.

Your own agent, kept on a short leash

Outbound talks to the agent over the Agent Client Protocol, the open standard coding agents use with editors. It finds the agents installed on this Mac, and you turn one on in Settings › Intelligence.

  • It can use only Outbound’s tools: your apps, the sites and countries they reach, what was blocked, and your rules.
  • From Outbound it can’t read your files or run commands. It works in an empty folder of its own.
  • Any rule change it asks for waits for your approval.
  • If it needs you to sign in, Outbound says how. If it doesn’t answer, the Analytics overview falls back to Outbound’s own summary.
  • Claude Code
  • Codex
  • Grok
  • Cursor
  • Gemini CLI
  • GitHub Copilot
  • OpenCode
  • Factory Droid
  • Goose
  • Kimi CLI
  • Qwen Code
  • Kilo
  • Cline
  • Auggie
And any other agent that supports the Agent Client Protocol.

Your AI apps can ask. You decide.

Outbound includes a Model Context Protocol server, outboundctl mcp. Claude, Cursor, Codex, Gemini CLI and VS Code can ask about your apps, the sites and countries they reach, what was blocked and your rules. They see the same figures as Analytics, never the contents of a connection.

  • Each app has an Add Outbound to button in Settings › Intelligence.
  • An AI app can ask to add, remove, turn on or turn off a rule. Outbound shows you exactly what would change and makes the change only if you allow it.
  • You can switch rule changes off, so AI apps can only read.
Outbound asking about a change from an AI app: “Claude Code” wants to change a rule, Block a connection. The rule reads Deny connections to segment.io and its subdomains on any port for any app, with the AI app’s reason below it and Don’t Allow and Allow buttons

What stays on your Mac, and what goes only where you send it

Stays on your Mac

  • Your rules and connection history.
  • Answers from Apple Intelligence, and the check of their numbers.
  • Server locations, from a database stored on the Mac.

Goes only where you point it

  • Your questions and the figures your coding agent reads, to its company under your sign-in, once you turn it on.
  • Figures to the model behind your API key, after you turn on Send figures to it. Show What’s Sent… shows the exact request first.
  • The same figures as Analytics, and your rules, to AI apps you add.

Never sent

  • The contents of any connection.
  • To a model behind an API key: addresses, full host names, file paths or rules.
  • Anything at all, until you choose an AI and turn it on.

See the privacy policy for the details.

Also in the app

Smaller things you will notice

  • Highlights

    A privacy score with a daily streak, awards, a network passport of the countries your Mac has reached, and a Year in Review. Share cards are previewed before you share them. Nothing is shared automatically.

  • AI Agents in Analytics

    See which AI apps connect, which AI services they reach, and the countries those servers are in.

  • Smart filters

    Search tokens for AI apps, ad and tracking hosts, new apps, unsigned apps, Apple services, local network, abroad and heavy users.

  • Daily data limits per app

    Set a daily limit in the inspector. Outbound tells you at 80 % and at the limit, or blocks the app until midnight if you choose.

  • Official icons everywhere

    Apps, Apple services, command-line tools and websites show their real icons in one consistent rounded tile.

  • A command line in the app

    The outboundctl command ships inside Outbound: status, rules, ai ask and mcp.

Less repetition

Control it from your keyboard

outboundctl ships inside the app. It checks status, manages rules and blocklists, activates profiles, exports audits and validates feeds. outboundctl ai ask asks a question about your network, and outboundctl mcp starts the server that your AI apps connect to. The CLI edits the rule store; it does not speak directly to the extension.

Read the command reference ›
outboundctl status
outboundctl rules list
outboundctl profile list
outboundctl rules export rules.json
outboundctl mcp

Command examples.

How it differs from the macOS firewall

The firewall built into macOS handles incoming connections. Outbound decides where your apps can connect out.

What you needmacOS firewallOutbound
Incoming connectionsBuilt into macOSRules include direction
Outgoing app and host rulesNot its purposeApp, host, domain, address, port
How unknown connections are handledIncoming permissionsLearn, Ask or Strict
See where apps connectPer-app totals in Activity Monitor, no destinationsActivity, map and traffic per app
Managed deploymentApple firewall payloadMDM profiles, rule feed, audit export
PriceIncluded with macOS$39 USD personal, one time ($29 for the first 50)

Apple describes its firewall in Firewall settings. Compare Outbound with Little Snitch, LuLu and more ›

Tech specs

Compatibility
macOS 14 or later.
Apple silicon and Intel.
The assistant, health summary and written overview need a Mac with Apple Intelligence (macOS 26 or later). Other Macs show a plain summary.
Architecture
Network Extension content filter.
No kernel extension. No DNS proxy.
Unanswered questions
In Ask mode, unanswered connections are allowed after 8 seconds for UDP or 60 seconds for TCP by default, then added to Review. You can change the wait (15–120 seconds for TCP) or have unanswered connections blocked. Strict mode blocks connections that have no matching rule.
Privacy
Crash reports and usage stats are opt-in and off by default. Rules and history are local. Figures go to a cloud model only if you add one and turn on Send figures to it.
Locations
Optional offline database, IP Geolocation by DB-IP (CC BY 4.0).
Licence
$39 USD one time for 2 Macs, $29 for the first 50 licences.
Family licence for 5 Macs, $59.
Outbound app icon

Be one of the first 50

Outbound is $29 for the first 50 licences, then $39. Pay once, use it on 2 Macs.

  • 2 Macs per licence
  • One-time, no subscription
  • macOS 14 or later