System-Wide Ad Blocker for Mac

One Blocker for the Machine, Not One Per Browser

SplitTunnel Team·7 min read·Updated August 2026

Key Takeaways

  • A browser extension covers the browser it is installed in. Nothing about it reaches a second browser, a fresh profile, or an app that is not a browser at all

  • Blocking at the DNS layer covers the whole Mac at once: every app, every browser, and every background helper, no matter how each app's traffic is routed

  • The two do different jobs and stack well. An extension removes what a page assembles, including advertising on the same hostname as the content. The DNS layer removes ad and tracker domains everywhere else

Why One Extension Is Never the Whole Machine

The search that leads here is usually a specific frustration rather than a general one. You installed a blocker, it worked, and then you started noticing the parts of the Mac it does not touch.

  • A second browser: the extension in Chrome does nothing in Safari, Firefox, Arc, or Edge

  • A second profile or a private window: extensions are scoped per profile, and a fresh profile starts with none of them

  • Things that are browsers without saying so: Electron apps, in-app web views, and help windows that open a page inside the app

  • Everything that is not a browser: desktop clients, updaters, launchers, and background helpers reach ad and tracking endpoints with no browser involved

  • Upkeep: every browser is a separate install, a separate settings screen, and a separate thing to redo after you reinstall it

None of that means the extension is bad at its job. It means the job it does is scoped to a browser, and the thing you are searching for is scoped to a machine.

What System-Wide Means Here

SplitTunnel handles your Mac's DNS lookups, so blocking happens one layer below the software doing the browsing. A domain on a curated list or in your own rules stops resolving, so the address is never learned and the connection is never made.

Because the block is not attached to a browser, it covers every app and every browser on the Mac, background helpers included, and it does not matter whether that app's traffic goes out through your VPN or straight over your normal connection. A browser you install next month is covered by a switch you turned on today, without you doing anything about it.

Machine-wide is the design: what a Pi-hole does for a whole network, this does for one Mac. There is no per-browser version of it, and no per-app version of it either.

The Setup Is Two Switches

1

Install SplitTunnel and start the tunnel

2

Open Settings in the sidebar

3

Turn on Block Ads and Trackers. Ads and trackers ship as one curated list, so this single switch covers both

4

Turn on Block Malware and Scams for the second curated list

5

Add anything the lists miss under Domain Rules with Add Domain, or block a domain straight from the Activity panel while you are looking at it

The lists come from the HaGeZi project and are refreshed daily, so there is nothing to subscribe to and nothing to update by hand. The in-product description is exactly what the pair does: blocks known ad, tracker, malware, and scam domains for the whole Mac.

Two Different Kinds of Ad Blocking

This is the part worth understanding properly, because it decides both what to expect and what else to run.

A browser content blocker works inside the page. It sees what the page is assembling and removes the parts it recognizes as advertising, wherever those parts came from, including advertising a site serves from the same hostname as its content. Its reach ends at the browser it is installed in.

DNS-layer blocking works on names. It sees that something on the Mac wants to reach a hostname, and if that hostname is on the list the lookup fails. It has no view of what a page looks like and no opinion about page structure, so it cannot remove an ad that arrives from a hostname you need. Its reach is the whole machine, browsers and apps alike.

  • In-page content blocker: strong on what a page builds, including ads on the same hostname as the content. Covers one browser

  • DNS-layer blocking: strong on ad and tracker domains and on background traffic that never involves a page. Covers every app and browser on the Mac

  • Together: page-level removal where you browse, domain-level blocking everywhere else, with no conflict between them

So the honest recommendation is not to pick one. Run the content blocker in the browser you spend the day in, and run the DNS layer for the machine. The overlap between them is small, and the gap each one leaves is close to exactly what the other one covers.

Where the DNS Layer Stops

Three limits, none of them fine print, all of them easier to know now than to discover later.

  • Advertising on the same hostname as the content: a platform serving its own ads from its own domain is serving them from a name you want to keep resolving, so there is nothing for a domain rule to act on without taking the site with it. That half is the content blocker's job

  • Software on encrypted DNS: a browser or app that sends lookups over DNS over HTTPS to a provider it picked bypasses DNS-layer blocking. Turn on Block Encrypted DNS in the Strict Mode section of Settings and it falls back to the system resolver, where the lists apply. That works from a curated list of resolvers, so software that pins its own by IP address stays out of reach

  • Connections made straight to an IP address: no name is looked up, so there is no name for a rule to act on

The last two are shared by every DNS-layer blocker, Pi-hole and AdGuard Home included. They belong to the layer rather than to a particular product, which is worth knowing before you compare tools on a feature list.

Two more things about the curated side. Not every domain the lists catch appears as its own row in the Activity panel in this version, and the lists do not take per-domain exceptions: blocking applies to every app, and individual domains cannot be excluded from them in this version.

Nothing to Host

The other way people reach for machine-wide coverage is to move the blocking off the Mac entirely: a Pi-hole on the home network, a self-hosted server, or a filtering resolver in the cloud. Those work, and for a household they are often the better answer, since they also cover phones, TVs, and consoles that cannot run software of their own.

The cost is that something has to exist and stay running, and the coverage stops the moment the laptop leaves that network. Blocking that lives on the Mac has the opposite shape: no server to host, no router page to configure, nothing to keep awake, and it still applies on hotel Wi-Fi and in a coffee shop. In exchange it covers that Mac and nothing else on your network.

Lookups are processed locally on your Mac and are not sent anywhere to be classified, so choosing an on-machine blocker does not mean handing your browsing to a service to look through.

What to Run

  • One Mac, everything on it covered, nothing to maintain: DNS-layer blocking on the machine itself

  • Also want in-page advertising removed where you browse: add a browser content blocker in your main browser

  • Every device in the house covered: a network-wide resolver, at home, with somewhere to host it

  • Want to know which app wanted a domain before you block it: the Activity panel shows which app looked up which domain, which is the piece a published list cannot tell you

Settings and rules survive a restart of the Mac and blocking resumes automatically, so the maintenance story ends with the two switches. Most people turn them on, add three or four rules of their own over the following month, and stop thinking about it.

Frequently Asked Questions

One Blocker for the Whole Mac

Curated ad and tracker lists that cover every app and every browser, with no extension to install per browser and no server to run.

7-day free trial · Cancel anytime