Find the app before you write a rule
A block is only precise when you already know which app and endpoint are moving data.
Mac Network MonitorLearn when to block a Mac app, how to avoid breaking expected workflows, and how local firewall rules help keep the decision precise.
To block app internet access on Mac, identify the app and its endpoint first, then create a local firewall rule for the application, domain, IP address, port, or protocol. iNTM keeps monitoring visible so you can confirm the rule works without blocking more than intended.
Open iNTM Firewall and select the Realtime tab. Find the app and its connection, then check the remote target, port, and protocol before acting.
Prefer a domain, IP, port, or protocol rule when blocking the whole app would break expected features.
Use the connection's block action or open Rules to create a rule. Confirm the app and target in the rule sheet, save it, and keep the firewall enabled.

Check whether login, sync, update checks, or collaboration features still work as expected.
Use ongoing traffic history to refine overly broad or overly narrow firewall rules.
Download iNTM View App Firewall
Blocking can help when an app repeatedly reaches an endpoint you do not trust, uploads data outside your workflow, or consumes bandwidth in the background. The best rule is specific enough to solve the problem without damaging normal app behavior.
Firewall rules are sensitive because they reveal what apps you use and where they connect. iNTM evaluates rules locally and keeps connection metadata in the local app sandbox wherever possible. After a rule is on, watch the same app in the traffic view: a working block shows the connection attempt failing or disappearing, not a silent success that still moves data.
Blocking internet access means stopping a chosen app, or one of its destinations, from making new connections. It is not the same as turning off Wi-Fi, and it is not the same as watching a speed number. The built-in macOS firewall mainly controls incoming connections to your Mac. Outbound access, the direction an app uses when it reaches the internet, needs an app firewall that can target the application, a domain, an IP address, a port, or a protocol.
Start from the connection you already identified. If one domain or port is the problem, a narrow rule keeps login, sync, and updates working. Block the whole app when every connection from that app is unwanted, such as a helper you never use. Apply the rule, use the app the way you normally would, and look for a broken feature before you add a second rule. A block you cannot explain later is harder to undo than a block aimed at one endpoint.
A rule is only useful if the traffic you cared about stops and the rest of the app still behaves. Open the connection list for that app after the rule is enabled. You want to see the unwanted endpoint quiet, and any required service still connecting. If a login or sync breaks, narrow the rule instead of leaving the app fully blocked. Speed in the menu bar can confirm that a large transfer stopped, but the connection list is what proves which destination was affected.
Yes. iNTM can apply a local firewall rule to one application, so the rest of your Mac keeps its normal network access.
The built-in firewall is mainly for incoming connections. To block internet access for a specific Mac app, use an app firewall that can target that app's outbound connections.
After the rule is enabled, watch that app's connections. The unwanted domain or IP should stop transferring data, while any service you still need should keep connecting.
A block is only precise when you already know which app and endpoint are moving data.
Mac Network MonitorUse menu bar upload and download rates to see that a transfer is happening, then come back here to stop it.
Mac Network Speed Monitor