What a Mac firewall actually blocks

Last updated 2026-08-28. Written for people who are not network engineers.

The firewall built into macOS blocks connections coming in to your Mac. It cannot stop an app on your Mac from sending data out. Almost everyone who goes looking for a Mac firewall wants the second thing, and almost nobody is told that the built-in one does not do it.

Built into macOS incoming only Sending, outgoing needs a separate app Where to switch it on System Settings, Network, Firewall

What is a firewall, in plain words?

A firewall decides which network conversations your Mac is allowed to have. Every time an app fetches a page, checks for updates, or reports something back to its maker, that is a conversation. A firewall sits in the middle and can stop any of them.

What makes firewalls confusing is that the word covers two quite different jobs, and most articles do not separate them. One job is keeping other machines out. The other is keeping your own apps in. They need different tools, and macOS ships only the first.

What does the firewall built into macOS do?

It stops other machines on the network from starting connections to yours. You switch it on in System Settings, under Network, then Firewall. It is worth having on, particularly on shared or public networks, and it takes one click.

Apple's own description of it is about incoming connections, and that is the whole scope. There is no hidden setting inside it for the other direction. If you turn it on expecting to see a list of your apps and choose which ones may reach the internet, you will not find one, because that list does not exist in the built-in firewall.

So what stops an app sending data out?

A separate firewall app. macOS provides an official way for one to sit in the path of every connection and decide, and several apps use it. That is the category Little Snitch, LuLu, Radio Silence and MiniFirewall all belong to.

This is not a gap Apple forgot about. Deciding what an app may contact is a judgement only you can make, so Apple leaves it to apps that specialise in asking, or in showing. The mechanism they all use is the same system service; what differs is entirely how they treat you.

Incoming and outgoing: who started it?

Direction is about who knocked first, not which way data travels. An incoming connection is something on the internet reaching towards your Mac. An outgoing connection is your Mac reaching out. Once either is open, data flows both ways.

That distinction matters when you block something, because you are usually asked to choose. Some concrete cases:

What is happeningWho starts itWhat to block
A browser loading a page, and the trackers on it Your Mac Outgoing connections
An app checking in with its maker in the background Your Mac Outgoing connections
Someone on the same cafe network probing your Mac The other machine Incoming connections
A file sharing or web server running on your Mac The other machine Incoming connections
You are not sure, and you want it gone Either Both directions

What can a firewall app block, exactly?

The useful ones can block at more than one level, and the level you choose changes how much collateral damage you cause:

A whole app
The blunt instrument. Effective, and it stops the app working for its legitimate purposes too.
One website, for every app
The precise instrument. The app keeps working; the one destination you objected to stops being reachable from anywhere on the Mac.
One website, for one app only
Narrower still, and inherently less reliable, because the firewall has to work out which website each connection belongs to and some apps make that hard.
An address or a range
For when you know the number rather than the name. Also how you keep something off your local network.

What makes a simple firewall for Mac, rather than an expert one?

Whether it puts decisions on you at the moment it is least convenient. Expert firewalls interrupt you to approve or deny each new connection as it happens. Simple ones show you what happened and let you act on it whenever you like. The difference is not power, it is who is on the spot.

The prompting design sounds thorough, and it is where most people give up. You get asked whether some program you have never heard of may contact a server you have never heard of, while you are trying to do something else. Nobody can answer that well twenty times a day, so the honest outcomes are clicking Allow reflexively, which protects nothing, or uninstalling.

A simple firewall accepts that trade openly: it will not catch something you never thought to look at, and in exchange it never trains you to dismiss it.

Which Mac firewall should you choose?

Decide first whether you want to be asked. If you want control over every connection and will answer for it, Little Snitch or LuLu. If you want quiet, the question is whether you need to block individual websites or only whole apps.

If you wantLook atWhat you accept
Control over every connection as it happens Little Snitch, LuLu Being interrupted, often, especially in the first days
Quiet, and to silence whole apps Radio Silence No way to block one website and keep the app working
Quiet, and to block individual websites too MiniFirewall No alerts, so nothing tells you to look
Only to keep other machines out The firewall already in macOS No control over what your apps send

Whatever you choose, a firewall sees everything your Mac connects to, so what the app does with that record matters as much as its features. The full comparison goes through each one, and the Little Snitch alternative guide is the shorter read if prompts are what sent you looking.

Common questions

Does macOS have a firewall?

Yes. macOS has included a firewall for years, and you switch it on in System Settings under Network, then Firewall. It blocks connections that other machines try to make to your Mac. It does not control what your own apps send out, which is a different job.

Does the Mac firewall block outgoing connections?

No. The firewall built into macOS only blocks incoming connections. No setting inside it stops an app on your Mac from reaching a server on the internet. For that you need a separate app, which is why Mac firewall apps exist at all.

Do I need a firewall on my Mac?

For incoming connections, macOS already has one and switching it on is sensible. For outgoing connections, you need one if you want to know what your apps are contacting and stop some of it. Most people who go looking for a Mac firewall want the second thing without realising the built-in one cannot do it.

What is the difference between incoming and outgoing connections?

It is about who starts the conversation. An incoming connection is something on the internet reaching towards your Mac. An outgoing connection is your Mac reaching out to something. Both carry data in both directions once open, so the distinction is about who knocked first.

What is a simple firewall for Mac?

One that does not ask you to make decisions you are not equipped to make. The complicated ones interrupt you to approve or deny each new connection. A simple one shows you what is happening and lets you block what you object to, on your own schedule, without ever putting you on the spot.

Can a Mac firewall block just one website for one app?

Some can. Blocking a whole app is the blunt option and stops it working entirely. Blocking one website leaves the app functioning while stopping the one thing you objected to. Little Snitch and MiniFirewall can do this; Radio Silence and the built-in macOS firewall cannot.

Will a firewall slow my Mac down?

A well built one will not. macOS provides a way for firewall apps to hand simple website and address blocks to the system itself, which then enforces them without ever running the firewall app. Slowdowns come from apps that inspect everything in their own code instead.

Are Mac firewalls safe to install?

Any firewall sees everything your Mac connects to, so the question worth asking is what the app does with that. Look for one that keeps the record on your Mac, states plainly that it collects nothing, and includes no code from other companies. On the Mac App Store, check the privacy label on the listing.

Sources

Want the quiet kind?

MiniFirewall is a Mac app (macOS 13.0 or later, Apple Silicon and Intel) that shows every website and app your Mac is talking to, and blocks any of it with one click. It never interrupts you with pop-up questions: nothing is blocked until you say so. Your traffic stays on your Mac. Nothing is collected, nothing is sold, and there are no ads.

Get MiniFirewall on the Mac App Store