Network monitor for Mac

See which apps connect, where, and how much

Outbound lists every app that reaches the network, each host it talks to, the port, how often, how much data went up and down, when it was last seen, and where the server is. Select a connection and it tells you why it was allowed or blocked.

Get Outbound All features ›

Outbound main window, Activity: apps grouped with their destinations, allow and block switches, locations, a traffic chart and an inspector explaining why www.apple.com was allowed

What you get

Each app gets one row, with every destination under it

  • Grouped by app. Helper processes are listed under the app they belong to, so a browser is one row, not twelve. Expand it to see each host, port and connection count.
  • Up and down, per app. Live traffic bars per app show which one is uploading while you are not using it.
  • Exact bytes per destination. When a connection closes, the filter records exactly how many bytes it sent and received. Each destination and domain row shows them under Sent and Received, and so does the inspector.
  • Pick a time window. The traffic chart shows upload above the centre line and download below. Hover a column to read the time and rates, or drag across the chart and the list and map show only that window. It works from the keyboard and with VoiceOver too.
  • Search everything. Type an app, a host or a port number and the list narrows as you type. Scoped words such as app:, host:, port:, proto:, country:, direction:outgoing and rule:none narrow it further; a menu in the search field inserts them.
  • Why it happened. The inspector names the rule that decided a connection, or says that no rule did and which mode stepped in.
  • Ask in plain language. On a Mac with Apple Intelligence (macOS 26 or later), the on-device assistant answers questions about this Mac’s network with the records it used, shown as charts, a traffic timeline, a map or cards you can click to inspect. Numbers are checked against the connection records, and nothing leaves the Mac. It explains; it never changes rules.
  • Smart filters. Search tokens narrow the list to AI apps, ad and tracking hosts, new apps, unsigned apps, Apple services, local network, abroad and heavy users. Apps, Apple services, command-line tools and websites show their real icons.
  • Daily limits and AI agents. Set a daily data limit for an app in the inspector and Outbound tells you when it goes over. Analytics shows which AI apps connect, which AI services they reach and the countries those servers are in, with a written overview of the range by Apple Intelligence on a Mac that has it.
  • Act where you look. Allow or block the app, or just one destination, from the same row.

Compared with what is built in

Activity Monitor counts the data but not where it goes

macOS already gives you totals and a Terminal view. Here is what each one answers.

QuestionActivity Monitornettop in TerminalOutbound
How much data each process sent and receivedYesYesYes, per app and per destination
Which servers a process talks toNoRemote addressesHost names, ports, counts and last seen
Helpers grouped under their appNoNoYes
Where the server isNoNoCity and country, offline
Why a connection was allowedNoNoThe deciding rule or mode
Block an app or a hostNoNoYes, from the same row
PriceIncluded with macOSIncluded with macOS$39 USD one time ($29 for the first 50), $59 for 5 Macs

Apple describes the Network tab in View network activity in Activity Monitor. nettop is documented in its manual page (man nettop).

Check right now, for free

Two Terminal commands that already help.

If you only need a quick look, macOS can show live connections without any app. Both commands are read-only.

nettop -m tcp -n
lsof -i -n -P | grep ESTABLISHED

The first shows each process with its live TCP connections and remote addresses, updating as you watch. The second lists established sockets once. Neither can block a connection; for that you need an outbound firewall. Step-by-step: see which apps use the internet on your Mac.

Outbound Overview: protecting this Mac, filter health, apps online, allowed and blocked counts, most active apps and recently blocked hosts
Outbound Map: arcs from this Mac to the cities its connections reach, blocked ones in red, with a list of top places

Map

Where your data goes, drawn from your Mac.

Arcs run from your Mac to each city your apps reach, with blocked destinations in red. The map sits beside the list, or above it in a narrow window, and follows the time window you select on the chart. The location database lives on your Mac, so no address is ever looked up online.

Switch the map to 3D for a real globe, and pick Standard, Muted or Satellite. Turn on the floating globe in Settings › Labs: resize it, hold it to move it, and pick one of five themes. Connection pop-ups spring in, and packets glide along great-circle arcs.

Outbound’s floating globe at two sizes: a dotted globe turned to Europe, Africa and Asia, with app icons at the places they connect to and green and red great-circle arcs between them

Location data: DB-IP City Lite, CC BY 4.0. A city is an estimate of where a server’s address is registered, not proof of where your data is stored.

From watching to deciding

When you see something you did not expect.

  1. Find it. Search for the app or the host, or narrow to a moment on the traffic chart.
  2. Check why. The inspector shows the rule or mode that let it through.
  3. Decide. Block the whole app, or only that destination, for as long as you choose.

Guides: block an app from the internet · stop apps phoning home · does the macOS firewall block outgoing connections?

Questions

Questions before you start

Read the full FAQ ›

Can I see which apps use the internet on a Mac without installing anything?

Yes. Activity Monitor’s Network tab shows how much data each process sends and receives. In Terminal, nettop lists each process’s open connections with their remote addresses, and lsof -i lists open network sockets. None of them group helpers under their app, name the rule that applied, or block anything.

Does the Outbound monitor send my connection list anywhere?

No. Connection history, traffic totals and locations stay on your Mac. Locations come from an offline database stored on the Mac, so looking up where a server is never sends that address anywhere.

Can the map be a globe?

Yes. The Network Monitor map has 2D and 3D, where 3D is a real globe, with Standard, Muted and Satellite styles. The floating globe, turned on in Settings › Labs, can be resized and held to move, with five themes: Graphite, Blue Marble, Midnight, Daylight and Amber. The menu bar panel can show a flat map or a globe.

Can an AI app see which servers my apps connect to?

Only if you add Outbound to it. Outbound includes a Model Context Protocol server (outboundctl mcp), and Settings › Intelligence has an Add Outbound to button for Claude, Cursor, Codex, Gemini CLI and VS Code. Those apps see the same figures as Analytics, never the contents of a connection. They can ask to change a rule, and Outbound makes the change only if you allow it. You can switch this off.

Is the monitor separate from the firewall?

They are one app. The monitor shows what connected and why it was allowed or blocked; the same window lets you allow or block an app or a single destination.

Which macOS versions does it support?

Outbound requires macOS 14 or later; see the compatibility page for what has been tested.

Outbound app icon

Be one of the first 50

Outbound is $29 for the first 50 licences, then $39. Pay once, use it on 2 Macs.

  • 2 Macs per licence
  • One-time, no subscription
  • macOS 14 or later