Network monitor for Mac
See which apps connect, where, and how much
Outbound lists every app that reaches the network, each host it talks to, the port, how often, how much data went up and down, when it was last seen, and where the server is. Select a connection and it tells you why it was allowed or blocked.

What you get
Each app gets one row, with every destination under it
- Grouped by app. Helper processes are listed under the app they belong to, so a browser is one row, not twelve. Expand it to see each host, port and connection count.
- Up and down, per app. Live traffic bars per app show which one is uploading while you are not using it.
- Exact bytes per destination. When a connection closes, the filter records exactly how many bytes it sent and received. Each destination and domain row shows them under Sent and Received, and so does the inspector.
- Pick a time window. The traffic chart shows upload above the centre line and download below. Hover a column to read the time and rates, or drag across the chart and the list and map show only that window. It works from the keyboard and with VoiceOver too.
- Search everything. Type an app, a host or a port number and the list narrows as you type. Scoped words such as
app:,host:,port:,proto:,country:,direction:outgoingandrule:nonenarrow it further; a menu in the search field inserts them. - Why it happened. The inspector names the rule that decided a connection, or says that no rule did and which mode stepped in.
- Ask in plain language. On a Mac with Apple Intelligence (macOS 26 or later), the on-device assistant answers questions about this Mac’s network with the records it used, shown as charts, a traffic timeline, a map or cards you can click to inspect. Numbers are checked against the connection records, and nothing leaves the Mac. It explains; it never changes rules.
- Smart filters. Search tokens narrow the list to AI apps, ad and tracking hosts, new apps, unsigned apps, Apple services, local network, abroad and heavy users. Apps, Apple services, command-line tools and websites show their real icons.
- Daily limits and AI agents. Set a daily data limit for an app in the inspector and Outbound tells you when it goes over. Analytics shows which AI apps connect, which AI services they reach and the countries those servers are in, with a written overview of the range by Apple Intelligence on a Mac that has it.
- Act where you look. Allow or block the app, or just one destination, from the same row.
Compared with what is built in
Activity Monitor counts the data but not where it goes
macOS already gives you totals and a Terminal view. Here is what each one answers.
| Question | Activity Monitor | nettop in Terminal | Outbound |
|---|---|---|---|
| How much data each process sent and received | Yes | Yes | Yes, per app and per destination |
| Which servers a process talks to | No | Remote addresses | Host names, ports, counts and last seen |
| Helpers grouped under their app | No | No | Yes |
| Where the server is | No | No | City and country, offline |
| Why a connection was allowed | No | No | The deciding rule or mode |
| Block an app or a host | No | No | Yes, from the same row |
| Price | Included with macOS | Included with macOS | $39 USD one time ($29 for the first 50), $59 for 5 Macs |
Apple describes the Network tab in View network activity in Activity Monitor. nettop is documented in its manual page (man nettop).
Check right now, for free
Two Terminal commands that already help.
If you only need a quick look, macOS can show live connections without any app. Both commands are read-only.
nettop -m tcp -n
lsof -i -n -P | grep ESTABLISHEDThe first shows each process with its live TCP connections and remote addresses, updating as you watch. The second lists established sockets once. Neither can block a connection; for that you need an outbound firewall. Step-by-step: see which apps use the internet on your Mac.


Map
Where your data goes, drawn from your Mac.
Arcs run from your Mac to each city your apps reach, with blocked destinations in red. The map sits beside the list, or above it in a narrow window, and follows the time window you select on the chart. The location database lives on your Mac, so no address is ever looked up online.
Switch the map to 3D for a real globe, and pick Standard, Muted or Satellite. Turn on the floating globe in Settings › Labs: resize it, hold it to move it, and pick one of five themes. Connection pop-ups spring in, and packets glide along great-circle arcs.

Location data: DB-IP City Lite, CC BY 4.0. A city is an estimate of where a server’s address is registered, not proof of where your data is stored.
From watching to deciding
When you see something you did not expect.
- Find it. Search for the app or the host, or narrow to a moment on the traffic chart.
- Check why. The inspector shows the rule or mode that let it through.
- Decide. Block the whole app, or only that destination, for as long as you choose.
Guides: block an app from the internet · stop apps phoning home · does the macOS firewall block outgoing connections?
Can I see which apps use the internet on a Mac without installing anything?
Yes. Activity Monitor’s Network tab shows how much data each process sends and receives. In Terminal, nettop lists each process’s open connections with their remote addresses, and lsof -i lists open network sockets. None of them group helpers under their app, name the rule that applied, or block anything.
Does the Outbound monitor send my connection list anywhere?
No. Connection history, traffic totals and locations stay on your Mac. Locations come from an offline database stored on the Mac, so looking up where a server is never sends that address anywhere.
Can the map be a globe?
Yes. The Network Monitor map has 2D and 3D, where 3D is a real globe, with Standard, Muted and Satellite styles. The floating globe, turned on in Settings › Labs, can be resized and held to move, with five themes: Graphite, Blue Marble, Midnight, Daylight and Amber. The menu bar panel can show a flat map or a globe.
Can an AI app see which servers my apps connect to?
Only if you add Outbound to it. Outbound includes a Model Context Protocol server (outboundctl mcp), and Settings › Intelligence has an Add Outbound to button for Claude, Cursor, Codex, Gemini CLI and VS Code. Those apps see the same figures as Analytics, never the contents of a connection. They can ask to change a rule, and Outbound makes the change only if you allow it. You can switch this off.
Is the monitor separate from the firewall?
They are one app. The monitor shows what connected and why it was allowed or blocked; the same window lets you allow or block an app or a single destination.
Which macOS versions does it support?
Outbound requires macOS 14 or later; see the compatibility page for what has been tested.
Be one of the first 50
Outbound is $29 for the first 50 licences, then $39. Pay once, use it on 2 Macs.
- 2 Macs per licence
- One-time, no subscription
- macOS 14 or later
