Mac firewall guides
Does the macOS firewall block outgoing connections?
No. The macOS Firewall settings control incoming connections. They do not provide a per-app outbound destination allowlist.
Updated
Incoming and outgoing are different decisions
An incoming connection starts elsewhere and reaches a service on your Mac. An outgoing connection starts with a process on your Mac contacting a destination. Apple’s Firewall settings guide explains the incoming settings.
What an outbound firewall adds
Outbound combines the process identity with a host, domain, IP address or network range. Rules can also specify ports, protocol, direction and lifetime. That lets an app reach one service while denying another.
A hostname is available when the app connected by name. When the filter receives only an address, the rule and monitor must work with that address.
Where pf fits
pf is a packet-filtering facility with a rules language for network traffic. Its job differs from a graphical list of app decisions. Do not confuse a port or IP block with a rule that identifies one signed application.
Use the control that answers the question
- Control access to a service on your Mac: review the built-in firewall.
- Choose where one app may connect: use an outbound app firewall.
- Administer a network policy: evaluate a packet filter or managed content filter and test it first.
You can keep Apple’s incoming firewall enabled while evaluating an outbound tool. Running multiple third-party content filters needs separate compatibility testing.
Outbound instructions are based on Outbound 1.0 and its command-line help. Download Outbound. External product and platform sources are linked beside the relevant guidance.