100% On-Device · Native SwiftUI
What is your Mac
talking to?
The first time an app opens a connection, Blockr holds it and asks you. Allow it, block it, or block just that one destination. Every connection your Mac makes, logged with its verdict — and the rules stay yours, enforced on your Mac.
v1.11.0 · macOS 14+, including 27 Golden Gate · Apple Silicon & Intel · Signed & notarized by Apple · No account
A Windows build is on the way
How it works
Install. Approve. Answer. Done.
Install the filter
Click Install & Enable. Blockr sets up a macOS network filter — the same mechanism the big-name firewalls use. macOS asks you to approve it once.
Watch the traffic
Every outbound connection appears live, grouped by the app that made it, with the host it reached and whether it was allowed. Raw IPs are resolved to hostnames.
Answer once per app
A new app's first connection is held while Blockr asks. One alert per app — never one per connection — and your answer becomes a rule.
Tighten it up
Right-click any connection to block that host — for that app, or everywhere. Host rules beat app rules, so you can allow an app and still cut off one tracker.
Safe by design
A firewall shouldn't get in your way.
Blocking traffic can break things, so Blockr is built to fail open, ask once, and never leave an app hanging.
One alert per app, not per connection
A busy app can open hundreds of connections a minute. Blockr coalesces them: you get a single alert naming the app, and your answer settles every connection waiting behind it.
No popup storms
You choose whether it asks at all
Alerts are for the first few days, while the apps you actually use get their rules. After that, New apps — in the menu bar, at the foot of the window, or in Settings ▸ General — sets what happens the first time an app with no rule connects. Ask me is the default: the connection is held and one alert asks you. Allow silently lets anything new through with no alert and no rule written. Block silently drops it the same way, which makes Blockr deny-by-default once your own apps are approved. Every rule you've already written still applies in all three — and whenever Blockr isn't asking, the status strip says so, so you can't be left that way without knowing.
Ask · allow · block
Nothing hangs waiting on you
A held connection is released using your default action if you don't answer in time — so an app never stalls because you stepped away. The alert stays up, and your answer still becomes the rule.
Fails open
"Just for now" is an actual answer
The honest answer to an alert is often neither always nor once, but while I'm doing this thing. Answer for 15 minutes, an hour, or eight — and the rule stops applying by itself. Expiry is checked on every connection inside the filter, so a temporary rule can't outlive its window even if Blockr never runs again.
Temporary rules
Blockr tells you which rules do nothing
A firewall's rule list only ever grows. Blockr names the ones that stopped mattering — expired, already covered by a broader rule with the same answer, or flatly contradicting another rule with the same scope — and names the other rule involved. Nothing is deleted for you, and where the answer isn't certain it stays quiet.
Rule hygiene
Your rules are a file you own
No account, no sync — so a file is the backup and the way to a new Mac. Export as Blockr's own format, or as a hosts file or plain domain list. Those two are what every published blocklist is written in, so a list somebody else maintains can become rules you own and can edit, instead of a subscription you can only switch on and off.
Import · export
Pause when you need to
Troubleshooting something? Pause protection for 15 minutes, an hour, or until you resume — everything is allowed and nothing is asked. Pausing never survives a relaunch, so a pause can't leave you unprotected by accident.
Temporary by design
It tells you when it has stopped blocking
Blockr's filter can be switched off without going anywhere near Blockr — the toggle under System Settings ▸ Network ▸ Filters, and macOS itself after some updates or if the system extension is removed. A blocker that has quietly stopped blocking and still looks switched on is worse than no blocker at all, so Blockr watches that setting and re-reads it every time you come back to the app. If filtering is off it says so plainly — nothing is being blocked — and offers one button to turn it back on. No approval prompt, no admin password, and your rules and lists are exactly where you left them.
New in 1.8
Every rule is visible
The Rules screen lists everything you've decided — including apps that aren't running, which would otherwise be invisible. Change a verdict, delete a rule, or write one ahead of time for an app you haven't launched yet.
Auditable
It never decrypts your traffic
Blockr decides at the moment a connection opens — which app, which host, which port. It never decrypts or proxies what flows through, and after the verdict the data path is untouched. The one thing it reads is DNS replies, on port 53, so that connections arriving as bare addresses can still be matched to names. Your connection log stays on your Mac.
Private
Features
Everything your Mac connects to.
A live log of every outbound connection, grouped by the app that made it — searchable, sortable, and one right-click from a rule.
Every rule in one place — including apps that aren't running. Change a verdict, delete a rule, or write one for an app before it has ever connected.
Connection alerts
The first time an app reaches the internet, Blockr pauses that connection and asks. The alert names the app, where it's going, and the exact executable — so you know whether it's the app or one of its helpers.
The headline
Per-app and per-host rules
Allow or block everything an app does, or scope a rule to one destination. Hosts can be exact (example.com), an address, or a wildcard (*.example.com), with an optional port.
Two levels
Host rules beat app rules
Allow an app in general and still cut off a single tracker. The most specific rule wins — naming an app beats naming a host, an exact host beats a wildcard, and a port breaks the tie.
Precedence
Live connection log
Every connection with its app, remote host, port, verdict and time. Search by app, host or port; filter to just what was blocked; sort on any column.
Searchable
Filter out the noise
macOS's own services connect constantly, and they can bury everything else. Right-click any row to hide that app, that host, or that whole domain from the log. It changes what you see and nothing else — no rule is written and nothing is blocked differently. A count of what's hidden stays on screen with one click to bring it back, and a blocked connection is shown even when a filter would hide it.
New in 1.6
Hostnames, not just IPs
Reverse DNS turns 17.253.144.10 into apple.com, looked up only for rows on screen and cached — so the log reads like something you can act on.
Readable
History that survives relaunch
Connections and per-app totals are kept on disk, so the monitor is never blank and a rule is always attached to an app you recognise. Export the log to CSV or JSON.
Persistent
Right-click to write a rule
Found something you don't like in the log? Right-click it: block that host for that app, block it for every app, or allow the app outright. No retyping hostnames.
One click
The rules manager
Every rule in one screen, including apps that aren't running and would otherwise be invisible. Add App… writes a rule for something before it has ever connected.
Auditable
Pause protection
Allow everything and stop asking for 15 minutes, an hour, or until you resume — from the menu bar or ⇧⌘P. Never survives a relaunch.
Temporary
Start at login
While Blockr isn't running there's nobody to ask, so unknown apps get your default action. Starting at login is the difference between a firewall and a window.
Always on
Know what got blocked
A blocked connection just fails silently inside the app that made it. Optional notifications tell you when that happens — rate-limited to one per app per minute.
Optional
100% on your Mac
No account, no telemetry, nothing uploaded. Blockr never decrypts or proxies your traffic. It decides at connect time, reads DNS replies and nothing else, and gets out of the way.
Privacy
Light and dark, properly
Native SwiftUI throughout, with a menu-bar item that keeps working when the window is closed.
Native
Built for everyone
Full keyboard support, VoiceOver labels on every control and verdict, and contrast that holds up in both appearances.
WCAG 2.1 AA
Thirteen languages
English, German, Spanish, French, Italian, Japanese, Korean, Dutch, Polish, Portuguese (Brazil), Russian, Turkish and Simplified Chinese — the whole app, not just the menus: every status line, every verdict, the connection alert, the map's country labels and every VoiceOver description. Blockr follows your Mac, or you can pick a language for Blockr alone in Settings without changing anything else — and the counts, the dates and the pause-until times follow that choice too, rather than whatever your Mac is set to.
Your language
Map
See where it all ends up.
Every connection your Mac made, placed on the country that answered it — worked out on your Mac, from a table Blockr already has.
Nothing is looked up online
The easy way to build this screen is to ask a web service who owns each address — which would hand a stranger a running list of everywhere your Mac goes, one lookup at a time. Blockr bundles the table and reads it offline, so drawing the map costs zero requests.
No lookups sent
Red is where you're saying no
Every dot is sized by how much traffic went there and colored by the verdict that won. A red one is a destination your rules and blocklists are turning away more often than not — usually the part of the map worth looking at first.
At a glance
The table is the map
A picture is unreadable to anyone using VoiceOver, so every fact the map draws is also a row underneath it — sortable by country, allowed, blocked or total. Nothing on this screen is said with color alone.
WCAG 2.1 AA
Your own location is optional
Switch it on and the map draws the lines from where you are; leave it off and everything else is identical. Blockr asks only when you press the button, uses it for nothing else, keeps it only while the app is open, and never sends it anywhere.
Off by default
It keeps up with the traffic
Dots grow and counts climb as connections arrive, so the map is a live picture of the session rather than a report you have to ask for.
Live
What people are saying.
Pricing
Free for you. Fair for work.
Personal use is free forever — the full app, unlimited scans, no key, no account, no nag screens. If Blockr earns its keep at your job, a one-time business license keeps it supported.
Personal
Free forever
For individuals and personal projects
- The full firewall — every feature
- Unlimited rules, per app and per host
- Connection alerts, live log, CSV/JSON export
- 100% on-device — nothing uploaded
- No account, no nag screens
- Free updates forever
Business
$5 / device
One-time payment — no subscription
- Everything in Personal
- Use commercially at work
- One-time payment — no subscription
- Free updates forever
- Supports solo indie development
The personal tier is the full app — buy a business license only if you use Blockr commercially. One seat per device, paid once, yours for life. Secure checkout via Stripe; your license key is emailed instantly.
Download & install
Two clicks and one approval.
Download the app and drag it into Applications — that's it. No Terminal, no Homebrew, no sign-up.
Version 1.11.0 · Released September 8, 2026 · Free updates forever
macOS 14 Sonoma or later, including macOS 27 Golden Gate · Apple Silicon or Intel
Everything Blockr needs is built right into the app — native SwiftUI, nothing else to set up. One universal build runs natively on Apple Silicon and Intel.
Opens with a double-click
Blockr is signed with an Apple Developer ID and notarized by Apple, so it opens cleanly the first time — no Open Anyway trip through System Settings, no Terminal. Open the DMG, drag Blockr into Applications, and launch it.
One approval, once
A network filter is privileged, so macOS asks you to approve it — click Install & Enable, approve Blockr under Login Items & Extensions ▸ Network Extensions with your administrator password, then allow the “filter network content” prompt. That's the whole setup, and you only do it once.
Your traffic stays yours
Blockr decides at the moment a connection opens, and never decrypts or proxies what flows through. DNS replies, on port 53, are the one thing it reads, so names can be matched to addresses. Your rules and connection log stay on your Mac. Nothing is uploaded, ever.
Check the file you downloaded
Blockr is signed with an Apple Developer ID and notarized by Apple, and macOS checks that every time you open it — that is the check that catches a file altered on its way to you. To confirm it yourself, compare the SHA-256 of your copy with the one published for the Blockr.dmg this page serves.
SHA-256 checksum
Published checksum
Run this on your download and compare
shasum -a 256 ~/Downloads/Blockr.dmg
Or have your Mac compare them for you: save Blockr.dmg.sha256 beside the download and run shasum -a 256 -c Blockr.dmg.sha256.
FAQ
Common questions.
Is Blockr really free?
Personal use is free forever — the full app, unlimited rules, no account, no trial timer, no nag screens. If you use Blockr at work, a one-time $5 business license per device keeps it supported.
How does Blockr actually block a connection?
It installs a network content-filter system extension — the same macOS mechanism the big-name firewalls use. Every new outbound connection is routed through the filter, which allows or drops it based on your rules. macOS asks you to approve the extension once, in System Settings under Login Items & Extensions.
Does Blockr handle IPv6 and QUIC / HTTP/3?
Yes, both. Blockr filters at the flow level rather than the protocol level: every new outbound connection is judged on the app that opened it and where it is going, so QUIC over UDP is matched by the same rules as HTTPS over TCP, and IPv6 destinations are handled exactly like IPv4. Rules are written against hosts, so there is no separate protocol switch to remember. And with Encrypted DNS switched on, a blocked domain is refused at the lookup itself, before there is an address to connect to.
What doesn't Blockr filter?
Outbound connections only. Blockr does not filter inbound connections, and it has no packet-level rules: it decides at the moment a connection opens, then leaves the data path alone. It also cannot see inside a connection it has allowed, which is deliberate, because that would mean decrypting your traffic. If you want inbound protection too, macOS has its own firewall in System Settings under Network; it works by a different mechanism, so it runs alongside Blockr rather than competing with it.
What happens when an app I've never seen connects?
Blockr pauses that connection and shows a floating alert naming the app and where it's going. Allow or block it, remember the answer as a rule or not, and scope it to the whole app or just that one host. If you don't answer in time the connection is released using your default action so nothing hangs — the alert stays up, and your answer still becomes the rule.
Can I make Blockr stop asking once everything is set up?
Yes — that's what New apps is for, in the menu bar, at the foot of the window, or in Settings ▸ General. It sets what Blockr does the first time an app with no rule connects, and it has three settings. Ask me is the default: the connection is held and you get one alert. Allow silently lets anything new through without an alert and without writing a rule. Block silently drops it the same way — deny-by-default, once the apps you use have been approved. Every rule you've already written still applies in all three. And whenever Blockr isn't asking, the status strip at the top of the window says so, so you can't be left in that state without knowing.
Can I allow an app but block one destination?
Yes — that's what host rules are for. A host rule outranks the app's overall rule, so you can allow an app in general and still block a single tracker, an analytics endpoint, or a whole domain with a wildcard like *.example.com. Add one straight from the connection log by right-clicking a row.
What happens when Blockr isn't running?
The extension keeps enforcing the rules you've already set, but there's nobody to ask about an app it hasn't seen — so unknown apps get your default action, which you choose in Settings. That's why Start at login is worth turning on: a firewall that only protects you while its window is open isn't one.
Does Blockr slow down my network?
No. The filter decides when a connection is first opened — after that the data path is untouched, so throughput and latency are unaffected. Blockr never decrypts or proxies the contents of your traffic. The one thing it reads is DNS replies, on port 53 only, and only while a blocklist or a domain rule is switched on, so that connections arriving as bare IP addresses can still be matched to names. That happens in memory on your Mac, is never written down or sent anywhere, and can be switched off in Settings.
Does Blockr upload anything?
No. Every connection record, rule and hostname stays on your Mac — no account, no telemetry, and nothing about your traffic is ever sent to us. Blockr does make network connections, and this is all of them: a check with twoplus11.com about once a week for a new version (the app version and nothing else, switchable off in Settings); an optional reverse-DNS lookup that asks your normal resolver for the hostname of an IP you are already connecting to; blocklist downloads, but only for lists you subscribe to and fetched straight from the publisher, never proxied through us; if you turn on Encrypted DNS, your DNS queries going to the resolver you chose; and, only if you have entered a business license key, a check that the key is valid — at activation and about once a day after. The free tier never contacts a license server. Blocklists and Encrypted DNS are both off until you switch them on.
Can I run Blockr alongside Little Snitch?
No — macOS allows only one network content filter to be active at a time. If another firewall is installed and enabled, Blockr's filter can't run until it's disabled.
Will macOS warn me about an unidentified developer?
No. Blockr is signed with an Apple Developer ID and notarized by Apple, so it opens with a normal double-click. You will be asked to approve the system extension once — that prompt is macOS confirming you meant to install a network filter, and it needs an administrator password.
How do I update Blockr?
Blockr tells you when a new version is out; it does not install one itself. It checks about once a week, you can check any time from Blockr ▸ Check for Updates…, and you can turn the automatic check off in Settings ▸ General ▸ Updates. When there is an update, Download opens the Blockr.dmg — drag the new copy over the old one in Applications, and your rules and history are kept. Blockr did install updates in place until 1.9.0; that was removed because the updater's own helper bundles are what macOS 26.6 stamps as modified, and a stamped bundle stops the network filter from loading. One caveat either way: replacing the app replaces its network filter too, so macOS may ask you to approve the filter again afterwards.
How do I remove it?
Open Settings ▸ Extension and choose Remove System Extension — macOS will ask for an administrator password. That stops all filtering and monitoring. Then drag Blockr to the Trash.