Outbound for Mac

Security

Outbound uses an Apple Network Extension content filter to decide which connections may proceed. Decisions and rules stay on the Mac; v1 installs no kernel extension or DNS proxy.

Updated

Mac appOutbound
content filter
Destination

How a connection is handled

macOS passes a new flow to Outbound’s NEFilterDataProvider system extension. The filter evaluates the process, destination and rule conditions. It allows, denies or pauses the connection to ask you. Apple documents the content-filter provider API.

The app presents alerts and edits the rule store. The outboundctl command edits that store too. The extension’s XPC service checks the calling app’s code identity, including the signing team, before accepting it.

Unanswered questions are allowed by default in Ask mode

In Ask mode, an unanswered connection is allowed after 8 seconds for UDP or 60 seconds for TCP by default, then added to Review. You can change the wait (15–120 seconds for TCP) or have unanswered connections blocked. The alert stays open so you can still make a rule. When the app disconnects, the mode default also applies.

Strict mode blocks connections that do not have a matching allow rule. Use Strict mode when unattended, unknown traffic should be denied. Test the rules your essential apps need before depending on that mode.

What the app connects to

  • HTTPS blocklist URLs that you choose to add.
  • The HTTPS managed rule feed that your administrator configures.
  • outboundfirewall.com, once a day, to check for updates. Updates are signed, and you can turn automatic checks off.
  • outboundfirewall.com, over HTTPS, when you send a problem report from Help › Report a Problem. See the privacy policy for what it contains.
  • download.db-ip.com, when you download the offline location database.
  • Each website shown in the app, to fetch its icon. You can turn website icons off.
  • The AI service you choose in Settings › Intelligence (OpenAI, Anthropic, Google Gemini, OpenRouter, or an OpenAI-compatible server such as Ollama or LM Studio), only after you add a key and turn on “Send figures to” it. “Show What’s Sent…” displays the exact request first.
  • PostHog and Sentry, only if you turn on “Share anonymous crash reports and usage” in Settings. It is off by default.

A future change to network behavior will be documented here before release. The website’s server-side checkout integration is separate from the app and is disabled today.

What stays on the Mac

Rules, settings and audit logs are stored locally. The rule store uses versioned data, atomic writes and a backup of its previous version. Audit files contain connection metadata and decisions, with 30 days retained locally.

An administrator can configure audit export to a chosen folder for a SIEM collector. That is an explicit managed export, not product analytics. Logs can reveal app names and destinations; share only the relevant, redacted lines when asking for support.

Hardening

  • The app and the background agent verify the code signature of the filter they connect to.
  • Rule and settings files are opened without following symbolic links.
  • CSV and history exports neutralise spreadsheet formulas.
  • A blocklist feed cannot shrink itself away gradually: a refresh below 10% of the list’s largest size is refused.
  • Learn mode never re-trusts a program whose pinned code changed. The replaced program is asked about like a new one, and is blocked if nobody answers.

Release verification

A signed, notarized public DMG has not been published. We do not claim a completed notarization or live compatibility test. See the download status and compatibility status before installing.

Closed source, with a credited dependency

Outbound is closed source. Domain matching uses the Mozilla Public Suffix List, licensed under MPL-2.0. See credits.

Report a security issue

Email support@outboundfirewall.com with the affected version, a description and steps to reproduce. Do not send passwords, private keys or unredacted traffic logs. We will arrange a suitable way to share sensitive details if needed.