Block Malware Domains on Mac
One Curated List, One Layer
Key Takeaways
Block Malware and Scams in Settings turns on a curated list of known malicious and scam domains. A name on the list stops resolving, so the connection is never made
It covers the whole Mac: every app and every browser, whatever route that app's traffic takes, with nothing to configure per app
It is one layer, not a security product. It is not antivirus, it does not remove anything already on the machine, and it does not replace the protections macOS ships with
What the Malware and Scams List Does
Settings carries two curated blocklists. Block Malware and Scams is the second of them, separate from the ad and tracker list beside it, with its own switch.
With it on, a lookup for a known malicious or scam domain fails. The address is never learned and the connection is never made, so whatever was at the other end is not reached. This happens at the DNS layer rather than inside a browser, so it applies to every app and every browser on the Mac, whatever route that app's traffic takes.
The lists come from the HaGeZi project and are refreshed daily. There is nothing to subscribe to, nothing to schedule, and nothing to update by hand.
Where That Helps
- •
A link that does not go where it claimed: if the destination is on the list, it does not load
- •
A scam page a browser would otherwise have opened: the page never arrives, and there is no interstitial inviting a second look at it
- •
Software reaching a known-bad host in the background: apps and helpers are covered by the same switch, with nothing to set per app
- •
Links opened outside a browser: a destination reached from a mail client, a chat app, or a document is covered the same way, because the block is not attached to any one program
In each case the useful property is the same one. The block happens before a connection is made, rather than after something has arrived on the machine and is asking to run.
One Layer, Not a Security Product
This is the part to be clear about, because domain blocking is easy to oversell and the accurate version is more useful than the exciting one.
Blocking known malicious and scam domains is one defensive layer. It stops connections to names that are known to be bad. It does not examine files, it does not watch what software does once it is running, and it has no view of anything that arrives by a route other than a name lookup.
- •
It is not antivirus. Nothing here scans files or identifies malicious software sitting on the machine
- •
It is not malware removal. If something is already installed and running, a domain rule does not clean it up
- •
It does not replace macOS's own protections. macOS ships Gatekeeper and XProtect, and nothing here changes, replaces, or switches off either of them
- •
It knows about domains, not about behavior. A destination that is not on a list is a destination that resolves
What it is worth is coverage at one specific point: the moment before a connection is made, applied to the whole machine at once, with no per-app configuration to keep up with. That is a real layer and a modest one, and modest layers stacked together is how this generally works.
If you think something is already on the machine, this is not the tool for that. Domain blocking works before a connection, and cleanup is a different job for different software. That is the honest answer rather than a hedge.
Turn It On
Install SplitTunnel and start the tunnel
Open Settings in the sidebar
Turn on Block Malware and Scams
Turn on Block Ads and Trackers as well if you want the other curated list. Ads and trackers ship as one list, so that single switch covers both
Leave both on. Settings survive a reboot and blocking resumes automatically
The in-product description of the pair is exactly what they do: blocks known ad, tracker, malware, and scam domains for the whole Mac.
What a Known-Domain List Cannot Catch
- •
Domains that are brand new: a name registered this morning and used this afternoon may not be on any list yet. That is inherent to list-based blocking, whoever maintains the list
- •
Software on encrypted DNS: a browser or app that sends lookups over DNS over HTTPS to a provider it picked bypasses DNS-layer blocking. Turn on Block Encrypted DNS in the Strict Mode section of Settings and it falls back to the system resolver, where the lists apply. That works from a curated list of resolvers, so software that pins its own by IP address stays out of reach
- •
Connections made straight to an IP address: no name is looked up, so there is no name for a rule to act on
The last two are shared by every DNS-layer blocker, Pi-hole and AdGuard Home included. They come with the layer rather than with a particular product.
Two notes about what you will actually see. Not every domain the curated lists catch appears as its own row in the Activity panel in this version, so a quiet panel is not evidence of a quiet list. And the lists do not take per-domain exceptions: blocking applies to every app, and individual domains cannot be excluded from them in this version. If one of them ever blocks something you need, the option in this version is to turn that list off and rely on your own rules instead.
Your Own Rules Sit Alongside
Curated lists and your own domain rules are separate things that coexist. When you want one specific hostname gone, open Domain Rules, click Add Domain, and type it, or block it straight from the Activity panel while you are looking at the row. A rule on a hostname also covers anything underneath it, and Unblock in Domain Rules reverses either route.
The difference between the two is visibility. Rules you add are ones you chose, saw, and can remove one at a time. The lists are a background layer you switch on and stop thinking about.
After You Turn It On
Restart the browser after switching a list on. Connections that are already open and names the browser has already cached can keep a domain reachable for a little longer. A restart applies the change cleanly.
After that there is no routine to keep. Settings and rules survive a restart of the Mac and blocking resumes on its own, so the list stays on until you decide otherwise. It will not announce when it stopped something, which is a fair description of what a background layer should feel like, and a reason to judge it by what it is rather than by how much it tells you it is doing.
Frequently Asked Questions
Turn On the Malware and Scams List
A curated list of known malicious and scam domains, covering every app on the Mac. One layer among several, switched on in one click.
7-day free trial · Cancel anytime