Rules by destination
A wildcard domain, an IP, a subnet or a port. One route per app, plus exceptions where you need them.
Routekeeper decides where each app on your Mac sends its traffic: through a proxy, straight out, or nowhere at all. And it keeps watch so nothing slips past.
No need to push everything through a VPN. Pick where each app goes, and let the rest work as usual.
No accounts and no Routekeeper servers. Traffic goes only along the routes you set, and nowhere else.
SOCKS5, HTTP or HTTPS, with or without a password. Add several: work, home, another country.
Telegram via Amsterdam, Safari direct, that pushy updater to a dead end. One click per app.
The monitor shows every connection, and the leak detector flags anything that strayed from its route.
A firewall and a router in one window. No config files in the terminal, no noise.
A wildcard domain, an IP, a subnet or a port. One route per app, plus exceptions where you need them.
An unknown connection waits for your answer, and the answer becomes a rule: just once, while the app runs, or forever.
App, destination, matching rule, route and traffic. Turn any odd-looking line into a rule with one click.
Catches anything that went around the proxy, including DNS queries to your ISP.
A renamed copy will not inherit someone else’s route.
Works with apps that have no proxy settings of their own: command-line tools, Electron apps, messengers. UDP and QUIC are closed for them, so traffic can’t sneak around.
Then the mode decides. Start gentle and tighten things up whenever you like.
Routekeeper sends nothing to its developer. No analytics, no accounts.
Proxies and passwords live in a config only root can read. Even the app’s own window can’t see them.
When the hostname is known, the proxy server resolves it, not your ISP’s DNS.
A system network extension with no kernel extensions. macOS itself asks for your permission.
On first launch Routekeeper walks you through it: installs the extension, asks macOS for permission and helps you add a proxy.
A VPN wraps all of your Mac’s traffic in one tunnel. Routekeeper decides per app and per destination: Telegram through a proxy, your bank and Zoom direct, the pushy updater nowhere. Everything else works as if Routekeeper weren’t there.
They are firewalls: they answer “allow or not”. Routekeeper also answers “where to”: one rule can send an app through a specific proxy. Firewall, router and monitor in one window.
For proxy routes, yes: Routekeeper doesn’t sell proxies and runs no servers. Any SOCKS5, HTTP or HTTPS proxy will do: your own VPS, a work proxy, one you pay for. If you only need the firewall, you need no server at all.
Traffic passes through the network extension on your Mac and goes where you sent it. Routekeeper doesn’t decrypt connections and sends nothing to its developer: no analytics, no list of sites.
By default that app’s connections don’t go around the proxy; they fail with an error you can see in the monitor. That way nothing leaks silently. If you prefer, you can let them go direct in Settings.
Routekeeper carries TCP through the proxy. UDP and QUIC are closed for proxied apps so traffic can’t slip past; browsers simply fall back to TCP. Calls need UDP, so keep calling apps on a direct route.
Routekeeper runs as an Apple system network extension. macOS only turns those on with the owner’s explicit consent, so on first launch it asks three times: turn on the extension in System Settings → General → Login Items & Extensions, allow network content filtering, and allow the proxy configuration. You only do this once.
Your rules keep working: the extension enforces them, and the window is only for editing rules and watching the monitor.
Old railway junctions had one person nothing worked without. They stood at the fork, knew every route and threw the switches: this train to the right, that one to the left, the suspicious one onto a siding.
And at night they walked the tracks with a lantern, looking for anything that had slipped through.
Routekeeper does the same for your Mac.
Routekeeper is getting ready for its first public beta. You’ll need a Mac with macOS 14 Sonoma or later.