SoonPublic beta for macOS 14 and later

Every app gets
its own route

Routekeeper decides where each app on your Mac sends its traffic: through a proxy, straight out, or nowhere at all. And it keeps watch so nothing slips past.

Beta · macOS 14 Sonoma or later · bring your own proxy · no accounts

Apps

try switching a route
Apple system extension No kernel extensions No servers of ours Native Swift app
How it works

From app to website, and not a step off the route

No need to push everything through a VPN. Pick where each app goes, and let the rest work as usual.

No accounts and no Routekeeper servers. Traffic goes only along the routes you set, and nowhere else.

Add a proxy

SOCKS5, HTTP or HTTPS, with or without a password. Add several: work, home, another country.

Set the routes

Telegram via Amsterdam, Safari direct, that pushy updater to a dead end. One click per app.

The keeper keeps watch

The monitor shows every connection, and the leak detector flags anything that strayed from its route.

Features

As precise as a switchman at the junction

A firewall and a router in one window. No config files in the terminal, no noise.

Rules by destination

A wildcard domain, an IP, a subnet or a port. One route per app, plus exceptions where you need them.

T*.telegram.orgproxy
S*.corp.exampleoffice
›_10.0.0.0/8direct
Aany addressdead end

Asks before letting anything out

An unknown connection waits for your answer, and the answer becomes a rule: just once, while the app runs, or forever.

Live connection monitor

App, destination, matching rule, route and traffic. Turn any odd-looking line into a rule with one click.

Leak detector

Catches anything that went around the proxy, including DNS queries to your ISP.

Zoom bypassed the proxy52.84.12.7:443
DNS sent to your ISPChrome · example.org

By signature, not by name

A renamed copy will not inherit someone else’s route.

Telegram.app✓ signed
Telegram copy✕ mismatch
+ helperssame route

Any proxy, even for stubborn apps

Works with apps that have no proxy settings of their own: command-line tools, Electron apps, messengers. UDP and QUIC are closed for them, so traffic can’t sneak around.

SOCKS5HTTP CONNECTHTTPSusername & passwordcurl · git · node
Modes

And when there’s no rule?

Then the mode decides. Start gentle and tighten things up whenever you like.

Privacy

Traffic goes only where you told it to

No servers of ours

Routekeeper sends nothing to its developer. No analytics, no accounts.

Passwords under lock

Proxies and passwords live in a config only root can read. Even the app’s own window can’t see them.

Names resolved by the proxy

When the hostname is known, the proxy server resolves it, not your ISP’s DNS.

Built the Apple way

A system network extension with no kernel extensions. macOS itself asks for your permission.

What you need

Set your first route in five minutes

On first launch Routekeeper walks you through it: installs the extension, asks macOS for permission and helps you add a proxy.

Beta coming soon
  • A Mac with macOS 14 Sonoma or laterRoutekeeper uses Apple’s system network extensions, no kernel extensions.
  • Three permissions on first launchTurn on the extension in System Settings → General → Login Items & Extensions, then click Allow in two macOS prompts: network content filtering and the proxy configuration. Routekeeper walks you through it.
  • Your own proxy serverSOCKS5, HTTP CONNECT or HTTPS, with or without a password. Only for proxy routes: the firewall needs no server.
  • That’s itNo account, no subscription to someone else’s servers, no second client running alongside.
FAQ

Frequently asked questions

How is this different from a VPN?

A VPN wraps all of your Mac’s traffic in one tunnel. Routekeeper decides per app and per destination: Telegram through a proxy, your bank and Zoom direct, the pushy updater nowhere. Everything else works as if Routekeeper weren’t there.

How is it different from Little Snitch or LuLu?

They are firewalls: they answer “allow or not”. Routekeeper also answers “where to”: one rule can send an app through a specific proxy. Firewall, router and monitor in one window.

Do I need my own server?

For proxy routes, yes: Routekeeper doesn’t sell proxies and runs no servers. Any SOCKS5, HTTP or HTTPS proxy will do: your own VPS, a work proxy, one you pay for. If you only need the firewall, you need no server at all.

Can Routekeeper see my traffic?

Traffic passes through the network extension on your Mac and goes where you sent it. Routekeeper doesn’t decrypt connections and sends nothing to its developer: no analytics, no list of sites.

What if the proxy server is down?

By default that app’s connections don’t go around the proxy; they fail with an error you can see in the monitor. That way nothing leaks silently. If you prefer, you can let them go direct in Settings.

Do calls and UDP work?

Routekeeper carries TCP through the proxy. UDP and QUIC are closed for proxied apps so traffic can’t slip past; browsers simply fall back to TCP. Calls need UDP, so keep calling apps on a direct route.

Why does macOS ask me to allow something?

Routekeeper runs as an Apple system network extension. macOS only turns those on with the owner’s explicit consent, so on first launch it asks three times: turn on the extension in System Settings → General → Login Items & Extensions, allow network content filtering, and allow the proxy configuration. You only do this once.

What if I close the Routekeeper window?

Your rules keep working: the extension enforces them, and the window is only for editing rules and watching the monitor.

Routekeeper icon: a brass lantern with a railway switch on its glass
Why the name

The keeper of the routes

Old railway junctions had one person nothing worked without. They stood at the fork, knew every route and threw the switches: this train to the right, that one to the left, the suspicious one onto a siding.

And at night they walked the tracks with a lantern, looking for anything that had slipped through.

Routekeeper does the same for your Mac.

The lantern is being lit

Routekeeper is getting ready for its first public beta. You’ll need a Mac with macOS 14 Sonoma or later.

Beta coming soon