Block Trackers on Mac
The Known Tracking Industry, at Volume
Key Takeaways
Tracking is a volume problem. A Mac contacts analytics and telemetry endpoints constantly, from software that never opens a browser
Block Ads and Trackers in Settings covers the known tracking industry in one switch. Ads and trackers ship as one curated list, refreshed daily
The Activity panel shows which app looked up which domain, so the rules you add yourself are about your machine rather than someone else's list
The Problem Is Volume
Blocking one tracking domain is satisfying. It is also not the shape of the problem. A Mac that has been awake for an hour has reached analytics, crash reporting, and usage measurement endpoints many times over, from software that had no reason to mention it: the browser, certainly, but also the editor, the launcher, the note taking app, two menu bar utilities, and the updater for something you installed last year and forgot.
Handled one name at a time, that is an ongoing hobby. Handled as a category, it is a switch, and the two approaches are worth combining rather than choosing between.
One Switch for the Known Tracking Industry
Settings carries two curated blocklists. The first is Block Ads and Trackers. Ads and trackers ship as one list, so that single switch covers both, and there is no separate tracker toggle to go looking for. The second is Block Malware and Scams, which has its own switch and does a different job.
The lists come from the HaGeZi project and are refreshed daily, so the known tracking industry stays covered without you subscribing to anything or maintaining a file. When a name on the list is looked up by anything on the Mac, the lookup fails, the address is never learned, and the connection is never made.
Because this happens at the DNS layer rather than inside a browser, it applies to every app and every browser on the machine, whatever route that app's traffic takes. For tracking specifically that is the difference that matters, since most of the volume never involves a browser at all and no browser extension was ever going to see it.
Turn It On
Install SplitTunnel and start the tunnel
Open Settings in the sidebar
Turn on Block Ads and Trackers. One list, one switch, both categories
Leave it on. List settings survive a reboot and blocking resumes automatically, so there is nothing to switch back on later
Then Look at Your Own Machine
A published list is built for everybody. Your Mac runs one specific set of software, and the interesting names are the ones that set reaches for. The Activity panel shows which app looked up which domain and where its connections are going, so a domain stops being something you read about and becomes something you watched happen.
Attribution is the part no list can give you. Knowing that a name belongs to the editor you use all day changes what you do about it, compared with knowing only that some software on the Mac wanted it. It is also what keeps the rules you add short: you are not blocking a category on principle, you are answering a question about one program.
Turning one of those rows into a rule takes a click from the row you are reading, and the guide on blocking a tracking domain, linked below, covers that sequence and the judgment that goes with it. The short version is that you can also type a hostname yourself under Domain Rules with Add Domain, and that Unblock in that list reverses either route.
One thing to weigh before blocking a name you saw. Rules are machine-wide, and shared analytics and crash-reporting services sit behind domains that many unrelated apps use. Blocking one of those switches it off for everything on the Mac, not only the app you were watching.
What a Known-List Approach Cannot Do
Curated lists work by knowing about domains. That is their strength, and it is also the boundary, so it is worth being specific about where the boundary runs.
- •
New and obscure endpoints: a tracking domain that appeared this week, or one specific to a small piece of software, may not be on any list yet. Your own rules are the answer to those
- •
Things served from the same hostname as the content you wanted: this works on names, so measurement arriving from a hostname you need carries on as before
- •
Software on encrypted DNS: a browser or app sending lookups over DNS over HTTPS to a provider it picked bypasses DNS-layer blocking. Turn on Block Encrypted DNS in the Strict Mode section of Settings and it falls back to the system resolver, where rules apply. It works from a curated list of resolvers, so software that pins its own by IP address stays out of reach
- •
Connections made straight to an IP address: no name is looked up, so there is no name for a rule to act on
The last two belong to the DNS layer itself rather than to any one product. Pi-hole, AdGuard Home, and a filtering resolver on a router share them for the same reason, so they are worth knowing as properties of the approach rather than complaints about a tool.
Two more notes, so the Activity panel does not mislead you about what the switch is doing. Not every domain the curated lists catch appears as its own row in this version, which means the list is doing more than you can itemize from that view. And the lists do not take per-domain exceptions: blocking applies to every app, and individual domains cannot be excluded from them in this version. Your own rules are the part you see and control one at a time.
What Actually Changes
Less than a headline would suggest, and more than you would notice on the first afternoon. Known tracking domains stop resolving across the machine, so the background chatter thins out. Software that measured you through a name on the list stops reaching it, with no per-app settings to hunt for. Domains you have not blocked keep resolving normally, so ordinary use is unchanged.
There is no block page and no notification when something is stopped. A tracking endpoint that is not there is quiet by definition, which is the point of doing it this way.
Restart the browser after turning a list on. Connections that are already open and names already cached can keep a domain reachable for a little longer. A restart applies the change cleanly.
Keep It Proportionate
A short rule list next to one curated switch is a better outcome than a long rule list on its own. The switch handles the part that scales, your rules handle the part that is specific to you, and neither needs revisiting on a schedule. If a rule costs you something you needed, open Domain Rules and click Unblock. If a curated list does, the option in this version is to turn that list off and lean on your own rules, since individual domains cannot be excluded from it.
Frequently Asked Questions
Known Tracking Domains, Blocked Machine-Wide
One curated list handles the tracking industry at volume. The Activity panel handles what your own Mac actually contacts.
7-day free trial · Cancel anytime