Product features

Your Mac. Your DNS rules.

Let DNS providers compete, refine cached answers, and block unwanted domains. Give local projects their own names and route private domains, all from one native Mac app.

macOS 14+Intel + Apple silicon21 days, no card

Complete MacDNS General window showing active protection and DNS configuration

Encrypted upstreams

Choose your DNS providers

A slow provider does not have to hold up your DNS lookup. Enable Cloudflare, Google, and Quad9 individually or together, then choose how they are queried. Public requests to these providers use DNS over HTTPS.

Providers
Cloudflare · Google · Quad9
Dispatch

Parallel. Start queries to all enabled providers together. The first positive answer returns without waiting for the others.

Staggered. Start with the provider ranked fastest by recent average DNS latency. Other providers start after short, adaptive delays, without waiting for its full timeout.

Sequential. Try one provider at a time, moving on if it does not produce a positive answer within the attempt budget. This mode does not compare answers in the background.

Refinement
With parallel or staggered dispatch, compare provider answers in the background and refine future cached lookups. See how it works
DNSSEC
Ask providers to reject failed DNSSEC validation by default while preserving DNSSEC records requested by clients
Bypass control
Optionally block DoT and DoQ plus DoH to known provider addresses. Custom DoH endpoints on other addresses are not covered
Logging
Query and reply logging use macOS unified logging and are off by default

Adaptive dispatch

A head start, in milliseconds.

Staggered mode learns from recent DNS response times. It gives the fastest-ranked provider a head start while allowing others to join the lookup soon after. You choose the mode. MacDNS calculates the delays.

Timing example and limits

If the fastest provider averages 40 ms, the three ranked providers are scheduled at 0, 20, and 40 ms. These are dispatch delays, not promised response times.

The delay is half the fastest provider’s recent average latency multiplied by rank, bounded to 10–150 ms for additional providers. When any enabled provider has no latency history, all start together.

Pending queries can continue briefly after the first answer to collect results. Staggered mode does not guarantee that only one provider receives the query.

Answer Refinement

Compare the destinations, too.

The quickest DNS reply does not always point to the quickest destination. In parallel and staggered modes, MacDNS returns the first positive answer, then compares the IP addresses returned by different providers in the background. A refined answer can replace the cached result for later lookups.

Consensus and latency checks

If two or more providers return the same non-empty IP set, that consensus can update the cache. When there is no consensus and Answer Refinement is enabled, MacDNS uses ICMP latency probes to compare eligible public destination addresses.

It selects a provider’s answer using the lowest measured destination latency. Private and reserved addresses are excluded from probes. If probes fail or exceed their time budget, it falls back to the first candidate.

The first reply does not wait for refinement. Cache replacement preserves the entry’s original expiry. ICMP latency is a selection signal, not a guarantee of faster page loads or a security verdict.

Split DNS

Route private domains

Send internal domains to your own DNS server while public names use your selected providers. Configure a forward zone for your home lab or work network. MacDNS also uses supported private routes from the current network and keeps private reverse lookups and .onion names off public DoH, including during background refreshes.

  • Forward selected domains to a DNS server you specify
  • Use network-provided DNS routes for supported private search domains
  • Keep private reverse lookups and .onion names off public DNS
  • Enable, disable, edit, or remove forward zones in the app
Complete MacDNS Forward Zones window

Local records

Local DNS records

Give local projects their own domain names without editing /etc/hosts. Configure exact names or wildcards directly in MacDNS, with A, AAAA, CNAME, MX, TXT, PTR, and NS records. Matching requests are answered locally.

  • Use exact names or wildcard domains without editing /etc/hosts
  • Configure A, AAAA, CNAME, MX, TXT, PTR, and NS records
  • Keep intentional private answers exempt from rebinding protection
  • Enable, disable, edit, or remove records in the app
Complete MacDNS DNS Overrides window

Exceptions

Allow trusted domains

If a blocklist stops a domain you need, add an allowlist exception. You can turn exceptions on or off without deleting them. Other DNS policy, private routing, and local overrides continue to apply.

  • Let trusted domains resolve even when they appear in a blocklist
  • Enable and disable exceptions without deleting them
  • Keep allowlist decisions and configuration on your Mac
Complete MacDNS Allowlist window

Local filtering

Choose what to block

Choose separate blocking levels for ads, trackers, known threats, and other unwanted domains. Blocking depends on the lists you select. MacDNS stores the lists on your Mac and keeps the previous working data if an update is empty or broken.

Complete MacDNS Blocklist window

Available levels by category

Ads & Tracking

Default: Normal

Ads, trackers, and telemetry

DisabledLightNormalProPro+Ultimate

Malware & Security

Default: Pro

Malware, scams, and known security threats

DisabledLightNormalProUltimate

Adult Content

NSFW domains

DisabledEnabled

Gambling

Gambling and betting domains

DisabledLightNormalPro

Social Media

Facebook, Instagram, TikTok, X, and Snapchat

DisabledEnabled

Miscellaneous

Pop-ups, URL shorteners, and DoH bypass

DisabledLightNormalPro

Domain counts come from the upstream lists and can change between updates.

Local visibility

See blocked domains

Find which domain was blocked, check its category, and add an exception when needed. The Stats tab shows local blocklist activity, not a history of every DNS request.

  • Review up to 100 blocked domains, their categories, and block counts
  • Filter results by blocklist category
  • Add the matched blocklist rule directly to the allowlist
  • Refresh or clear the local blocklist statistics
Complete MacDNS Stats window

Runtime behavior

DNS recovery across networks

Move between Wi-Fi networks, connect a VPN, or wake your Mac. MacDNS monitors these changes and captive portals to rebuild stale DNS connections and update its protection status.

Complete MacDNS menu bar panel and configuration popover

Persistent cache

Eligible DNS answers survive restarts. When enabled, prefetch refreshes recently used names as they approach expiry, so later lookups can reuse the cache.

Serve expired

When enabled, Serve Expired can return an eligible stale answer if no fresh answer arrives within one second, while resolution continues in the background. It can also provide a fallback after upstream failure.

Provider health

Connections are bounded, checked, and rebuilt after network changes instead of lingering in a stale state.

Verified protection state

The menu reports active protection only when the DNS component confirms that it is intercepting traffic.

Update recovery

MacDNS detects an outdated DNS component after an update and either replaces it or reports that a restart is required.

Authenticated components

The app, agent, and DNS extensions verify each other and fail closed when that trust check breaks.

Free trial

Try every DNS control

21 days with no payment details required.