How to Block Ads on Mac
One Curated List, Every App on the Machine
Key Takeaways
One switch does it: Block Ads and Trackers in Settings. Ads and trackers ship as one curated list, so that single toggle covers both
Blocking happens at the DNS layer, so ad and tracker domains stop resolving for every app and every browser on the Mac, not only the browser you set something up in
It works on names, so advertising served from the same hostname as the content you wanted is unaffected. A browser content blocker handles that half, and the two work well together
What Blocking Ads at the DNS Layer Means
Most ad blocking people have used works inside a page. An extension loads with the browser, looks at what the page is assembling, and removes the parts it recognizes as advertising. That is one approach and a good one. This guide describes the other one, which is worth understanding before you set it up, because it changes what to expect.
SplitTunnel handles your Mac's DNS lookups, so blocking happens on names rather than on page elements. When something on the Mac tries to reach an ad or tracker domain that is on the curated list, the lookup fails, the address is never learned, and the connection is never made. Nothing has to read a page, and nothing has to be installed in a browser.
The practical consequence is reach. Blocking at the DNS layer sits below the browsers and below the apps, so it applies to every app and every browser on the machine, no matter how each app's traffic is routed. The chat client, the launcher, the menu bar utility, and Safari are covered by the same switch at the same time.
Where you block decides what it covers. An extension covers the browser it is installed in. The DNS layer covers the Mac.
Turn On Block Ads and Trackers
Install SplitTunnel and start the tunnel
Open Settings in the sidebar
Turn on Block Ads and Trackers. Ads and trackers ship as one curated list, so this single switch covers both
Turn on Block Malware and Scams as well if you want the second curated list. It is a separate switch and a different job
That is the setup. The lists come from the HaGeZi project and are refreshed daily, so there is nothing to update by hand
Two switches in total, and no list to build, choose, or subscribe to. It is worth saying plainly that there is no separate tracker toggle to go looking for: ads and trackers are one list behind one control, which is not how every tool in this space presents it.
What Changes in Practice
The most noticeable change is usually not the browser. It is everything else.
- •
Fewer ad and tracker domains resolve anywhere on the Mac, in apps as well as in browsers
- •
Pages that pull advertising from separate ad domains have less to fetch, so those parts never arrive
- •
Apps that report usage to known tracking endpoints stop reaching them, with nothing to configure per app
- •
Domains you have not blocked keep resolving normally, so the rest of your browsing is untouched
There is no block page and no interstitial. A blocked ad domain is simply not there, which in a browser usually looks like empty space or a slot that never fills, and in an app usually looks like nothing at all.
The Ads This Does Not Remove
Here is the limit, stated up front rather than discovered later. DNS-layer blocking works on names. Anything served from a hostname you have not blocked carries on as before, and that includes advertising a site serves from the same hostname as the content you came for.
- •
Good at: ad and tracker domains, background telemetry, and anything an app contacts by name without asking you
- •
Good at: coverage outside the browser, where extensions cannot reach
- •
Not the tool for: things served from the same hostname as the content you wanted
- •
Not the tool for: software that connects without looking a name up at all
In plain terms: a platform that serves its own advertising from its own domain is serving it from a name you want to keep resolving, so there is nothing there for a domain rule to act on without taking the site with it. That is not a defect in the setup. It is what this layer can and cannot see.
Which is why people who care about advertising usually run a browser content blocker as well. The two are complementary rather than competing: the content blocker handles what is inside a page, in the browser it is installed in, and the DNS layer handles the domains, everywhere on the machine including software that never opens a browser. Running both is the normal answer, not an admission that either one fell short.
Browsers That Use Their Own Encrypted DNS
One more ceiling belongs here, because it is the usual reason blocking looks like it did not work. A browser or app that sends its lookups over encrypted DNS, known as DNS over HTTPS, to a provider it picked itself is not asking the system resolver anything, so it never sees the block.
The answer is in Settings, in the Strict Mode section: turn on Block Encrypted DNS. Strict Mode blocks known encrypted-DNS (DoH) resolvers, so software that reached for one falls back to the system resolver, where the lists and your own rules apply. It works from a curated list of resolvers rather than a promise about every one that exists: software that pins its own resolver by IP address stays out of reach.
Every DNS-layer blocker shares that edge, Pi-hole and AdGuard Home included. It belongs to the layer rather than to one product, and knowing it in advance is what keeps a switch from looking mysteriously broken.
Restart the browser after you turn blocking or Strict Mode on. Connections that are already open and names the browser has already cached can keep serving a domain for a little longer. A restart applies the change cleanly.
Adding Your Own Rules for the Stragglers
The curated list handles the known ad and tracking industry. It will not know about a domain that started serving ads last week, or an endpoint specific to one piece of software you happen to run. That is what your own rules are for, and there are two ways to add one: block a domain straight from the Activity panel while you are looking at it, or open Domain Rules, click Add Domain, and type the hostname. Either way the rule lands in Domain Rules, where Unblock removes it again.
The Activity panel is the more useful of the two routes, because it shows which app looked up which domain, which is the piece a published list can never tell you. The guide on blocking a tracking domain, linked below, walks through that sequence and the judgment calls that come with it.
Two honest notes about how the curated side behaves alongside your own rules. Not every domain the lists catch appears as its own row in Activity in this version, so the switch is doing more than the panel itemizes for you. And the lists do not take per-domain exceptions: blocking applies to every app, and individual domains cannot be excluded from them in this version. Your own rules are the part you see and control one at a time.
It Stays On
Turn the switch on once. List settings and domain rules survive a restart of the Mac and blocking resumes automatically, so there is nothing to switch back on in the morning and no step to repeat after an update. If a curated list ever costs you something you needed, the option in this version is to turn that list off and work with your own rules instead, since individual domains cannot be excluded from it.
Most setups end up running both halves without thinking about it much: the curated list handling volume quietly across the machine, a browser content blocker handling the in-page half where you browse, and a short list of your own rules for the specific things you decided your Mac should not be talking to.
Frequently Asked Questions
Ad Domains Blocked for the Whole Mac
One switch turns on the curated ad and tracker list. No extension to install per browser, and nothing to maintain by hand.
7-day free trial · Cancel anytime