LittleSnitch on a Mac: watching outbound traffic from the menu bar

Searching for Little Snitch on a Mac leads to a site offering two products with the same name and completely different pricing models, a demo whose terms are stated in a footnote, and a comparison page written in feature bullets rather than in decisions. The App Store lists one of them as free, which raises more questions than it settles.

The underlying idea is simple enough. macOS has no built in way to see or stop what leaves the machine, and this is the software that fills that gap. Everything else is a choice between two ways of doing it.

The half of the traffic macOS does not filter

The built in firewall is an inbound filter. Apple's description of it says so directly.

A firewall can protect your Mac from unwanted contact initiated by other computers when you're connected to the internet or a network. Source: support.apple.com, read September 28, 2026

Contact initiated by other computers is the whole of its remit. An app on the Mac that opens a connection outward is not covered by that pane, by its allowed list, or by stealth mode. There is no System Settings equivalent for outbound connections, and no status item anywhere in macOS that reports them.

That is the gap. Objective Development, an Austrian company, has been selling software to fill it for a long time, and it now ships two separate products to do it.

Two products, two pricing models

The difference that matters most is not a feature. It is how each one is bought.

Little Snitch Little Snitch Mini
Current version 6.5 1.9
How it is sold Perpetual licence, paid upgrades for new major versions Subscription in-app purchase
Price 59 EUR single licence 1.49 USD monthly or 13.49 USD yearly
Where it comes from Direct download from the developer Mac App Store, listed as free
macOS required macOS 27, also compatible with Tahoe, Sequoia and Sonoma macOS 12.0 or later
Free use Demo mode, three hours at a time, restartable Monitoring features free permanently

Those prices were read from the developer's order page and the App Store listing on September 28, 2026, in the currencies each one quotes. The direct edition also offers a family licence at 115 EUR, a five seat multi licence at 239 EUR and a ten seat multi licence at 419 EUR.

One detail on the order page is worth noticing before paying for anything: a licence purchased now is stated to be valid for both Little Snitch 6 and Little Snitch 5. For anyone on an older macOS release, that removes the usual worry about buying into the wrong version.

The subscription edition is the newer arrival and the one most people meet first, because it is the one that appears in the App Store. Its listing gives its size as 9.7 MB and its minimum system as macOS 12, which is several releases older than the direct edition requires.

What the paid line actually separates

The developer's own comparison page splits the two products by audience rather than by feature count, describing the smaller one as focused on essentials and simplicity and the larger one as being for enthusiasts and experts. Underneath that framing, the split is consistent and easy to summarise.

The smaller edition is built to be silent. Its stated design is a single window interface, unobtrusive background operation, and community maintained blocklists so that protection needs almost no attention. It shows what connected and lets connections be stopped, and it keeps a traffic history with statistics for the previous twelve months.

The larger edition is built to interrupt. Its defining behaviour is an immediate alert whenever an application or process tries to open a connection, with a decision to allow or deny it at that moment. On top of that it adds rules written at the level of individual protocols and ports, blocking by IP address, temporary rules that expire, rule priority, rule groups, and profiles that can be tied to network environments and switched automatically when the Mac changes network.

Two of its features are worth calling out because they do not appear in feature comparisons often. It includes a command line tool, described by the developer as being for remote administration and for maintaining rules, settings and backups. And it can capture traffic data in PCAP format, which is the format packet analysers read, alongside Berkeley Packet Filter monitoring and code signature checks intended to stop malware from presenting itself under another identity.

Version 6 also added DNS encryption, so that server name queries are encrypted rather than sent in the clear. That is a privacy feature rather than a filtering one, and it overlaps with settings some people already have configured at the router or through a profile, which is worth checking before treating it as a reason to upgrade.

The part that lives in the menu bar

Both editions put their day to day interface at the top of the screen rather than in a window, and this is the practical difference between owning the software and using it.

The larger edition's headline addition in version 6 is described by the developer as a Control Center in the menu bar, giving access to essential network information, recent activity charts and recently blocked connections at a glance. The smaller edition has a status menu showing an animated live overview of recent network activity. In both cases the intended pattern is the same: glance at the icon, notice something unexpected, then open the full window only when there is a reason to.

That pattern has an obvious failure mode. A menu bar already holding a backup utility, a clipboard manager, a VPN client, a battery tool and a screenshot tool has no room left, and on a laptop with a notch the overflow is silent: icons simply stop being drawn. A network monitor whose icon is not visible is a network monitor that is not being read.

macOS offers two controls for this and they are worth knowing before installing anything new. Holding Command and dragging a status menu icon moves it along the bar, and holding Command and dragging it out of the bar removes it. Those work on the system's own items, which is often enough on a desktop and rarely enough on a laptop. Keeping a specific icon permanently visible while everything else collapses is what a dedicated menu bar tool is for.

Trying either one without paying

Both have a genuine free path, and the terms are different enough to matter.

The direct edition runs without a licence key in demo mode, and the developer's terms for it are unusually generous. The demo provides the same protection and functionality as the full version, runs for three hours, and can be restarted as often as desired. One component is limited on a different clock: the Network Monitor expires after 30 days. So the alerting and blocking can be evaluated indefinitely in three hour sittings, while the long term traffic analysis has a real deadline.

The subscription edition takes the opposite approach. Its free tier is the monitoring, permanently: the real time connection list, the traffic diagrams and the animated map view of worldwide connections all work without paying. The in-app purchase adds blocking of connections, longer traffic history ranges, and advanced display and filtering options.

That produces a useful sequence for anyone unsure which they want. Install the free edition and read it for a week. If the answer to every connection is fine, monitoring was the whole requirement and the free tier is the end of the process. If several connections need stopping and the stopping needs to be conditional, that is the case for the subscription or for the perpetual licence.

The licence terms trip people up

The direct edition's licences are defined by a rule most software does not use, and the order page spells it out: the number of seats is determined by the number of computers or users, whichever is lower.

A single licence permits either one person on multiple computers, or multiple people on one computer, but never multiple people on multiple computers, whether or not the use is simultaneous. The family licence covers up to five computers at a time belonging to the same household and used by people who live there, and it is stated as non commercial only, so it does not extend to business users. The multi licences are the ones that allow multiple people on multiple machines.

The person most likely to get this wrong is someone who works alone across a laptop and a desktop and also lets a family member use one of them. That is multiple users on multiple computers, and a single licence does not cover it.

The reason the alerts are answerable at all

A prompt saying that a process wants to reach a server in Ireland is useless if there is no way to find out why. Objective Development's answer to that is a document format it publishes alongside the software, and it is the most interesting part of the whole arrangement.

In a nutshell, an Internet Access Policy (IAP) is a document that allows software vendors to declare and describe the Internet usage of their programs. Source: obdev.at, read September 28, 2026

The developer compares it to a privacy policy, with the difference that it is machine readable: it declares which connections a program makes and for what purpose, so firewall software can read it and present the explanation at the moment a decision is being asked for. The stated benefit to the person answering the prompt is being able to judge whether a connection is necessary and what blocking it would break.

Adoption is voluntary, so coverage is partial, and the developer lists the applications that ship one, a set that includes 1Password, iA Writer, Scrivener and BBEdit. There is also a separate free viewer for checking which installed apps carry a policy. Where a policy exists, the prompt becomes a real question. Where none exists, it goes back to being a guess, which is the honest limit of the alerting model.

Where it does not help

Three limits are worth being clear about, because none of them are hidden and all of them get discovered late.

It does not retroactively police what has already been allowed. A rule created in a hurry to make a video call work is a permanent allowance until someone reviews it, which is presumably why the larger edition added usage statistics for rules so that unused ones can be found.

It is not a malware scanner. Code signature checking confirms that an application is still the one a rule was written for, which is a different job from deciding whether that application is trustworthy in the first place.

And the alerting model has a cost that no feature list shows. A Mac with a lot of software installed generates a lot of first connections, and the first days after installing the alerting edition involve a steady stream of decisions. The smaller edition exists partly because that cost is unacceptable to most people. Choosing between them is mostly choosing how much attention this subject deserves.

What to change first

Start with the free monitoring for a week before paying for anything, because it answers the only question that matters, which is whether the traffic leaving this particular Mac contains anything worth stopping. Then decide on the pricing model rather than the feature list, since a perpetual licence at 59 EUR and a yearly subscription at 13.49 USD reach break even after a few years and the interaction models are further apart than the features are. And whichever one ends up installed, make sure its icon is one of the ones still visible at the top of the screen, which is what Koffret is for.

Frequently asked questions

Does the built in Mac firewall do the same thing as Little Snitch?

No. Apple describes the macOS firewall as protecting the Mac from contact initiated by other computers, which is inbound traffic only. Connections that software on the Mac opens outward are not covered by that pane at all, and that outbound direction is what this software watches.

How much does Little Snitch cost?

On the developer's order page, read on September 28, 2026, a single licence is 59 EUR, a family licence for up to five computers in one household is 115 EUR, a five seat multi licence is 239 EUR and a ten seat multi licence is 419 EUR. Little Snitch Mini is listed as free in the Mac App Store with in-app purchases of 1.49 USD monthly or 13.49 USD yearly.

What is the difference between Little Snitch and Little Snitch Mini?

The larger edition alerts on every new connection and allows rules written per protocol, port and IP address, with profiles that switch by network and a command line tool. The smaller one runs silently in a single window with blocklists, and is sold as a subscription rather than a perpetual licence.

Can Little Snitch be used for free?

Both can, with different limits. The direct edition runs in demo mode with the same functionality as the full version for three hours at a time, restartable as often as desired, though its Network Monitor expires after 30 days. Little Snitch Mini keeps its monitoring features, including the connection list, traffic diagrams and map view, free permanently, and charges for blocking.

Which macOS versions are supported?

The current direct release, version 6.5, is listed as running on macOS 27 and as also compatible with macOS Tahoe, Sequoia and Sonoma, with older releases kept on a legacy page for macOS 13 Ventura and earlier. Little Snitch Mini's App Store listing requires macOS 12.0 or later.

Back to all posts