Mac firewall guides

outboundctl reference

outboundctl is Outbound’s command-line interface for rules, profiles, blocklists, audit export and managed feed validation. It edits the local store; it does not connect directly to the filter extension.

Updated

Status and version

outboundctl status
outboundctl version
outboundctl --help

Status reports the filter configuration and rule count. An unreadable store is reported as unknown rather than zero. The app picks up changes to the store.

Rules

outboundctl rules list --json
outboundctl rules count
outboundctl rules export rules-backup.json
outboundctl rules import rules-backup.json

Import validates its file and replaces user rules. Managed, blocklist and rule-group rules in the current store are kept. Rules of those types in the import file are ignored.

outboundctl rules add --action deny --remote example.com --path /usr/bin/curl

This example denies curl to an illustrative host and prints a rule UUID. Remove a user rule with outboundctl rules remove <uuid>. Add accepts --ports, --proto tcp|udp|any and either --path or --signing-id with optional --team-id.

Blocklists and profiles

outboundctl blocklist list
outboundctl profile list
outboundctl profile activate none

Activate a profile by name or UUID instead of none. Subscribe with outboundctl blocklist add <https-url>, optionally adding --pin and --name. Remove a subscription with outboundctl blocklist remove <uuid>; its rules are removed too.

Audit and managed feeds

outboundctl audit export --to /path/to/audit-export
outboundctl feed check rule-feed.json

Feed check accepts a local file or HTTPS URL and an optional --pin <sha256>. It prints the rule count on success. Validate feeds before publishing them.

Store and permissions

The default rule store is ~/Library/Group Containers/5GS535L4GD.com.outboundfirewall.outbound/rules.json. The settings file is beside it. OUTBOUND_STORE_PATH selects another rules file.

As root without an override, the tool uses the signed-in console user’s container. If nobody is signed in, it stops. Organization editing restrictions produce exit 77 for user mutations unless run as root. Managed rules still cannot be removed individually, including as root.

Exit statuses

  • 0: success.
  • 1: runtime error.
  • 64: usage error.
  • 65: invalid rule, feed or value.
  • 77: editing not allowed.

Commands are checked against the current development CLI source on October 4, 2026. The installed build’s outboundctl --help is the reference for that build. See managed preferences and samples.

Outbound instructions are based on Outbound 1.0 and its command-line help. Download Outbound. External product and platform sources are linked beside the relevant guidance.