Block Distracting Websites on Mac

A Short List, Applied to Every App on the Machine

SplitTunnel Team·6 min read·Updated August 2026

Key Takeaways

  • Write the list first. Four or five names you genuinely lose time to beat thirty copied from someone else's list

  • A domain rule works at the DNS layer, so a blocked site stops resolving in every browser and every app on the Mac, desktop clients included

  • It is coverage, not a lockout. Every rule is one Unblock away, so if you need something a future you cannot undo, a commitment tool with scheduled lockouts is the honest recommendation

Write the List Before You Install Anything

The tooling is the easy half. Most people searching for this already know the three or four sites that eat their afternoons, and anyone who does not can find out by paying attention for a single working day. Name them before you touch any settings, because a blocker pointed at a guess is a blocker you switch off by Thursday.

  • The one you open without deciding to, usually the name your fingers type during a two-second wait

  • The one you open for a specific thing and leave forty minutes later

  • The one that is genuinely useful some of the time, which is the hardest call on the list

  • The desktop app version of any of the above, because that is exactly where a browser-only block falls apart

Keep it short. Five names you meant beat thirty you inherited from a forum post, and every name you add is one you have to live with at four in the afternoon when you suddenly need something from it.

Why the Block Has to Be Wider Than a Browser

The usual first attempt is an extension, and it works exactly as far as it goes. It covers the browser it is installed in. Open a second browser, a fresh profile, or a private window somewhere else, and the block is simply not there. Meanwhile a good share of modern distraction never involves a browser at all: the chat client, the video app, the social client sitting in the menu bar keeping its badge count current.

SplitTunnel handles your Mac's DNS lookups, so a rule applies at the DNS layer, below the individual apps and browsers. Add a hostname under Domain Rules and the name stops resolving for the whole machine: every app, every browser, every background helper, no matter whether that app's traffic goes out through a VPN or straight over your normal connection.

Machine-wide is the design: what a Pi-hole does for a whole network, a domain rule does for this Mac. A rule is never scoped to one app. If the goal is to cut off a single app rather than a single site, the per-app block is the tool for that.

Turn Each Name Into a Rule

There are two ways in, and they suit different moments. Use Domain Rules when you already know the name you want gone, which is the normal case for a distraction list. Use the Activity panel when you have just watched something reach a domain you did not expect.

From Domain Rules

1

Install SplitTunnel and start the tunnel, then open Domain Rules in the sidebar

2

Click Add Domain and type the first name on your list, for example example.com

3

Click Block. The rule takes effect immediately and appears in the list

4

Repeat for the rest of the list. Each name is its own rule, and each one shows up alongside the others

From the Activity panel

1

Open Activity in the sidebar. It lists connections with the app that made them and the domain each one looked up

2

Select the connection you want to stop. The detail pane offers Block followed by that domain

3

Click it. The rule lands in Domain Rules like any other, and that same button now reads Unblock

One Entry Covers More Than You Typed

You do not have to chase variants of a name. A rule on a hostname also covers anything underneath it, so the mobile host, the media host, and whatever host the site starts using next month are all included in the entry you already wrote.

What it does not do is reach sideways. A separate domain is a separate rule, and large services often own several unrelated names, including a short-link domain that shared links travel on. Add the obvious name first, then open Activity and see what is left.

Blocking a parent domain to stop one host underneath it takes the rest of that domain with it, sign-in and content included. When the rest of the site still has to work, block the specific name you saw.

What It Looks Like When It Works

The name stops resolving. The browser shows its ordinary cannot-find-the-server page rather than a blocked-by-something warning, and a native app behaves the way it does with no network at all. There is no countdown, no motivational screen, and no button offering fifteen more minutes. The plainness is the appeal for most people: nothing announces that a rule was involved, and there is nothing on screen to negotiate with.

Rules persist. They survive a restart of the Mac and blocking resumes automatically, so there is nothing to switch back on in the morning and no ritual to repeat after an update. Everything you did not block keeps resolving normally, so the rest of your work is untouched.

Coverage, Not a Lockout

Worth being blunt about, because the marketing around focus software often is not. A domain rule is not willpower in software. Every rule has an Unblock next to it, and nothing at all stops you clicking it.

What the rule changes is reach and upkeep: one entry covers every browser and every app on the machine, and it keeps covering them without being renewed. What it does not change is how hard the decision is to reverse. The friction it adds is the few seconds between a reflex and a deliberate choice, which for a surprising number of people is the entire fix, and for some people is nowhere near enough.

If your requirement is that a future you cannot undo the decision, a commitment tool with scheduled lockouts is the honest recommendation. Those tools are built around timers and locked sessions. A domain rule is built around what the machine can reach, and the two solve different halves of the problem.

When a Rule Looks Ignored

  • Software on encrypted DNS: a browser or app that sends lookups over DNS over HTTPS to its own provider bypasses DNS-layer blocking. Turn on Block Encrypted DNS in the Strict Mode section of Settings and it falls back to the system resolver, where your rules apply. It is a curated list of resolvers, so software that pins its own resolver by IP address stays out of reach

  • Cached names and open connections: right after you add a rule or switch on Strict Mode, a browser can keep a site reachable for a little longer. Quit it and start it again so the block applies cleanly

  • The wrong name: a site is not always reachable under the name you assumed. Open Activity, load the thing that still works, and read the domain your Mac actually asked for

The first of those is shared by every DNS-layer blocker, Pi-hole and AdGuard Home included. It is a property of the layer rather than a fault in one tool, and knowing it up front is what keeps a rule from looking mysteriously broken.

Living With the List

A distraction list is not a one-time exercise, though it settles down fast. Add a name when you notice a new hole, take one back when a rule costs you something you actually needed, and leave the rest alone. The list that works is usually the one you stopped editing three weeks ago.

One thing to know before you commit: a rule applies to the whole Mac, which includes everyone using it. On a shared machine, a shared rule is what you get. And taking one away is the same single click in the other direction: open Domain Rules, find the entry, click Unblock.

Frequently Asked Questions

Block the List, Not One Browser at a Time

Add each name once and it stops resolving for every app on the Mac, subdomains included. No terminal, no config files, one click to undo.

7-day free trial · Cancel anytime