What it controls

Your DNS. Your rules.

DNS helps your Mac find websites and online services. MacDNS checks these requests against your blocking rules. You can also create local DNS records and choose where private domains are resolved.

Let DNS providers compete

Ask Cloudflare, Google, and Quad9 together or with short, adaptive delays. MacDNS uses the first positive answer, so one slow provider does not have to hold up the lookup.

Choose what to block

Adjust blocking for ads and trackers, known threats, adult content, gambling, social media, and miscellaneous domains. Each category has its own setting.

Route private domains

Send internal domains to your own DNS server while public names use your selected providers. Configure private routes for your home lab or work network.

Keep DNS answers cached

Reuse eligible DNS answers even after a restart. Prefetch refreshes recently used names near expiry. Serve Expired can fall back to an eligible cached answer when a fresh answer is delayed or unavailable.

DNS rebinding protection

Remove private-network addresses from public DNS answers while allowing configured forward zones and local overrides to return them.

Check your protection

See when DNS protection is active, when the app is waiting for its agent, or when a restart is needed. The status comes from the running components.

Multiple DNS providers

One slow provider? Keep going.

A slow DNS lookup can delay opening a site or connecting an app. With multiple providers enabled, MacDNS can ask them at the same time or start them milliseconds apart, then use the first positive answer.

Compare the query modes

Answer Refinement

Refine the next answer.

DNS providers can return different server addresses for the same name. MacDNS compares their answers in the background. When they disagree, optional latency checks can select an answer for future cached lookups, without making the first reply wait for those checks.

How answer refinement works

Major release

What’s new in MacDNS 2

Choose your providers, keep eligible DNS answers across restarts, and check that protection is active. Version 2 brings these controls together with a resolver built into the MacDNS agent.

Read the full release notes

Built-in resolver

The MacDNS agent now loads its DNS resolver directly instead of starting a separate Unbound process.

Provider and dispatch controls

Enable Cloudflare, Google, or Quad9 and choose parallel, staggered, or sequential dispatch.

Persistent cache

Eligible answers survive restarts. Prefetch refreshes recently used names near expiry. Serve Expired can reuse an eligible cached answer when a fresh answer is delayed or unavailable.

Verified protection status

MacDNS shows Protection Active only after its DNS component confirms that it is intercepting requests.

Request handling

How MacDNS handles DNS

Your rules determine whether MacDNS blocks a domain, answers locally, or asks a DNS server. Public lookups use your selected encrypted providers.

  1. 01Receive

    The macOS DNS proxy extension passes the request to the MacDNS resolver.

  2. 02Apply local policy

    Overrides and blocklist decisions are checked, including allowlist exceptions. Custom and supported private routes are selected before public DNS.

  3. 03Resolve public names

    MacDNS uses an eligible cached answer or the DNS-over-HTTPS providers and dispatch mode you selected.

  4. 04Filter and return

    Rebinding protection checks public answers, requested DNSSEC records are retained, and eligible responses are cached.

Free trial

Try MacDNS for 21 days.

Every feature included. No account or card required. For macOS 14 or later.