100% On-Device · Native SwiftUI

What is your Mac
talking to?

The first time an app opens a connection, Blockr holds it and asks you. Allow it, block it, or block just that one destination. Every connection your Mac makes, logged with its verdict — and the rules stay yours, enforced on your Mac.

v1.2.0 · macOS 14+ · Apple Silicon & Intel · Signed & notarized by Apple · No account

How it works

Install. Approve. Answer. Done.

Install the filter
Click Install & Enable. Blockr sets up a macOS network filter — the same mechanism the big-name firewalls use. macOS asks you to approve it once.
Watch the traffic
Every outbound connection appears live, grouped by the app that made it, with the host it reached and whether it was allowed. Raw IPs are resolved to hostnames.
Answer once per app
A new app's first connection is held while Blockr asks. One alert per app — never one per connection — and your answer becomes a rule.
Tighten it up
Right-click any connection to block that host — for that app, or everywhere. Host rules beat app rules, so you can allow an app and still cut off one tracker.

Safe by design

A firewall shouldn't get in your way.

Blocking traffic can break things, so Blockr is built to fail open, ask once, and never leave an app hanging.

One alert per app, not per connection
A busy app can open hundreds of connections a minute. Blockr coalesces them: you get a single alert naming the app, and your answer settles every connection waiting behind it.
No popup storms
Nothing hangs waiting on you
A held connection is released using your default action if you don't answer in time — so an app never stalls because you stepped away. The alert stays up, and your answer still becomes the rule.
Fails open
Pause when you need to
Troubleshooting something? Pause protection for 15 minutes, an hour, or until you resume — everything is allowed and nothing is asked. Pausing never survives a relaunch, so you can't leave yourself unprotected by accident.
Temporary by design
Every rule is visible
The Rules screen lists everything you've decided — including apps that aren't running, which would otherwise be invisible. Change a verdict, delete a rule, or write one ahead of time for an app you haven't launched yet.
Auditable
It never reads your traffic
Blockr decides at the moment a connection opens — which app, which host, which port. It never inspects, decrypts, or proxies what flows through, and after the verdict the data path is untouched. Your connection log stays on your Mac.
Private

Features

Everything your Mac connects to.

A live log of every outbound connection, grouped by the app that made it — searchable, sortable, and one right-click from a rule.

Every rule in one place — including apps that aren't running. Change a verdict, delete a rule, or write one for an app before it has ever connected.

Connection alerts
The first time an app reaches the internet, Blockr pauses that connection and asks. The alert names the app, where it's going, and the exact executable — so you know whether it's the app or one of its helpers.
The headline
Per-app and per-host rules
Allow or block everything an app does, or scope a rule to one destination. Hosts can be exact (example.com), an address, or a wildcard (*.example.com), with an optional port.
Two levels
Host rules beat app rules
Allow an app in general and still cut off a single tracker. The most specific rule wins — naming an app beats naming a host, an exact host beats a wildcard, and a port breaks the tie.
Precedence
Live connection log
Every connection with its app, remote host, port, verdict and time. Search by app, host or port; filter to just what was blocked; sort on any column.
Searchable
Hostnames, not just IPs
Reverse DNS turns 17.253.144.10 into apple.com, looked up only for rows on screen and cached — so the log reads like something you can act on.
Readable
History that survives relaunch
Connections and per-app totals are kept on disk, so the monitor is never blank and a rule is always attached to an app you recognise. Export the log to CSV or JSON.
Persistent
Right-click to write a rule
Found something you don't like in the log? Right-click it: block that host for that app, block it for every app, or allow the app outright. No retyping hostnames.
One click
The rules manager
Every rule in one screen, including apps that aren't running and would otherwise be invisible. Add App… writes a rule for something before it has ever connected.
Auditable
Pause protection
Allow everything and stop asking for 15 minutes, an hour, or until you resume — from the menu bar or ⇧⌘P. Never survives a relaunch.
Temporary
Start at login
While Blockr isn't running there's nobody to ask, so unknown apps get your default action. Starting at login is the difference between a firewall and a window.
Always on
Know what got blocked
A blocked connection just fails silently inside the app that made it. Optional notifications tell you when that happens — rate-limited to one per app per minute.
Optional
100% on your Mac
No account, no telemetry, nothing uploaded. Blockr never inspects or proxies your traffic — it decides at connect time and gets out of the way.
Privacy
Light and dark, properly
Native SwiftUI throughout, with a menu-bar item that keeps working when the window is closed.
Native
Built for everyone
Full keyboard support, VoiceOver labels on every control and verdict, and contrast that holds up in both appearances.
WCAG 2.1 AA

Pricing

Free for you. Fair for work.

Personal use is free forever — the full app, unlimited scans, no key, no account, no nag screens. If Blockr earns its keep at your job, a one-time commercial license keeps it supported.

Personal
Free forever
For individuals and personal projects
  • The full firewall — every feature
  • Unlimited rules, per app and per host
  • Connection alerts, live log, CSV/JSON export
  • 100% on-device — nothing uploaded
  • No account, no nag screens
  • Free updates forever
Download — Free
Commercial
$5 / device
One-time payment — no subscription
  • Everything in Personal
  • Use commercially at work
  • One-time payment — no subscription
  • Free updates forever
  • Supports solo indie development

The personal tier is the full app — buy a commercial license only if you use Blockr commercially. One seat per device, paid once, yours for life. Secure checkout via Stripe; your license key is emailed instantly.


Download & install

Two clicks and one approval.

Download the app and drag it into Applications — that's it. No Terminal, no Homebrew, no sign-up.

Download Blockr for Mac — Free

Version 1.0.0 · Released July 23, 2026 · Free updates forever

macOS 14 Sonoma or later · Apple Silicon or Intel
Everything Blockr needs is built right into the app — native SwiftUI, no third-party dependencies, nothing else to set up. One universal build runs natively on Apple Silicon and Intel.
Opens with a double-click
Blockr is signed with an Apple Developer ID and notarized by Apple, so it opens cleanly the first time — no Open Anyway trip through System Settings, no Terminal. Open the DMG, drag Blockr into Applications, and launch it.
One approval, once
A network filter is privileged, so macOS asks you to approve it — click Install & Enable, approve Blockr under Login Items & Extensions ▸ Network Extensions with your administrator password, then allow the “filter network content” prompt. That's the whole setup, and you only do it once.
Your traffic stays yours
Blockr decides at the moment a connection opens — it never inspects, decrypts, or proxies what flows through. Your rules and connection log stay on your Mac. Nothing is uploaded, ever.

FAQ

Common questions.

Is Blockr really free?
Personal use is free forever — the full app, unlimited rules, no account, no trial timer, no nag screens. If you use Blockr at work, a one-time $5 commercial license per device keeps it supported.
How does Blockr actually block a connection?
It installs a network content-filter system extension — the same macOS mechanism the big-name firewalls use. Every new outbound connection is routed through the filter, which allows or drops it based on your rules. macOS asks you to approve the extension once, in System Settings under Login Items & Extensions.
What happens when an app I've never seen connects?
Blockr pauses that connection and shows a floating alert naming the app and where it's going. Allow or block it, remember the answer as a rule or not, and scope it to the whole app or just that one host. If you don't answer in time the connection is released using your default action so nothing hangs — the alert stays up, and your answer still becomes the rule.
Can I allow an app but block one destination?
Yes — that's what host rules are for. A host rule outranks the app's overall rule, so you can allow an app in general and still block a single tracker, an analytics endpoint, or a whole domain with a wildcard like *.example.com. Add one straight from the connection log by right-clicking a row.
What happens when Blockr isn't running?
The extension keeps enforcing the rules you've already set, but there's nobody to ask about an app it hasn't seen — so unknown apps get your default action, which you choose in Settings. That's why Start at login is worth turning on: a firewall that only protects you while its window is open isn't one.
Does Blockr slow down my network?
No. The filter decides when a connection is first opened — after that the data path is untouched, so throughput and latency are unaffected. Blockr never inspects, decrypts, or proxies the contents of your traffic.
Does Blockr upload anything?
No. Every connection record, rule, and hostname stays on your Mac — no account, no telemetry. The one thing that leaves your Mac is an optional reverse-DNS lookup, which asks your normal DNS resolver for the hostname of an IP you're already connecting to; you can turn it off in Settings.
Can I run Blockr alongside Little Snitch?
No — macOS allows only one network content filter to be active at a time. If another firewall is installed and enabled, Blockr's filter can't run until it's disabled.
Will macOS warn me about an unidentified developer?
No. Blockr is signed with an Apple Developer ID and notarized by Apple, so it opens with a normal double-click. You will be asked to approve the system extension once — that prompt is macOS confirming you meant to install a network filter, and it needs an administrator password.
How do I update Blockr?
Re-download the latest Blockr.dmg from this page and drag the new Blockr into your Applications folder, replacing the old one. Your rules and history are kept. Nothing is checked for automatically.
How do I remove it?
Open Settings ▸ Extension and choose Remove System Extension — macOS will ask for an administrator password. That stops all filtering and monitoring. Then drag Blockr to the Trash.
Also by the same solo developer Scrubbr Blockr shows you what's filling your disk. Scrubbr shows you what your files are secretly carrying — location, device, author — and strips it before you share. Free for personal use.

Like what I make?

All my apps are free for personal use. If they save you time or make your day a little easier, a tip keeps me going — it goes straight to development, no middleman.

Hear about new apps first

One short email when twoplus11 ships a new Mac app. No spam — and unsubscribing is one click that works instantly.

One confirmation email first — you're only in if you click it.