LuLu firewall for a Mac: a free way to see which apps call home
A Mac ships with a firewall, and that firewall does not do the thing most people picture when they hear the word. It decides what may reach the Mac. It has no opinion about what leaves it. LuLu, from Objective-See, exists to cover the other direction: it sits in the way of outgoing connections and asks before letting a new one through. That single difference is why a search for this tool usually starts with someone noticing an app talking to a server it has no business talking to.
The questions that follow are practical. Is it free in the way that matters. How noisy is it. What can it not see. And what does it cost in day to day friction compared with the paid tool in the same category.
The direction of traffic is the whole point
Apple's firewall lives at Apple menu > System Settings > Network > Firewall. Its options describe its scope exactly: block all incoming connections, automatically allow built-in software to receive incoming connections, automatically allow downloaded signed software to receive incoming connections, and enable stealth mode. Apple describes the first as "Prevent incoming connections to nonessential services and apps," and stealth mode as preventing the Mac from "responding to probing requests that can be used to reveal its existence." Every one of those sentences is about traffic arriving.
The LuLu documentation puts the gap in one line: "Apple's built-in firewall only blocks incoming connections. LuLu is designed to detect and block unauthorized outgoing connections, for example when malware attempts to connect to it's command & control server."
That covers a class of problem the built-in firewall structurally cannot. An app already running on the Mac, launched by the person using it, is not an incoming connection. A telemetry endpoint, an updater checking in at login, a document tool reaching a service that was never mentioned at install time: all of that is outbound, all of it is allowed by default, and none of it appears in the Firewall panel. LuLu turns each first attempt into a question.
What the tool is, in numbers that can be checked
LuLu is free and open source. The project is published under GPL-3.0, and the current release on the project's repository is version 4.5.1, dated 5 August 2026. The product page lists the requirement as macOS 10.15 or later, which is a wide net by current standards.
Free here means free, not a limited tier. There is no paid edition of LuLu with the useful features behind it, and the project takes sponsorship through its repository rather than licence sales. For anyone evaluating tools on a work machine where software purchases need a signature, that changes the order of the shortlist.
Installation puts a long-running network extension in place and sets the app to start at login. The product page notes that it "will appear in the status bar (unless configured otherwise)," which is the first hint that this tool joins the queue of icons at the top of the screen rather than staying out of sight.
The first week is the expensive part
Any tool that asks about every new outgoing connection is loudest when it knows nothing. The alerts arrive in a cluster during the first days and thin out as rules accumulate, and how bad that cluster feels depends on settings chosen at the start.
Several preferences exist precisely to lower the volume. Allow Apple Programs automatically permits processes signed solely by Apple, which removes a large share of the system's own chatter from the alert stream. Allow Installed Applications does the same for apps that were already on the Mac when the tool arrived, on the theory that they were trusted before. There are also options covering DNS traffic and simulator applications, which matters on a developer machine where a simulator generates traffic constantly.
Two operating modes sit at the extremes. Passive mode stops asking and lets connections through, which is useful while presenting or recording. Block mode does the reverse. Neither is a setting to leave on and forget, but both are better than uninstalling the tool in frustration during a meeting.
Judging an alert you did not expect
The hard part of an outbound firewall is not the clicking. It is deciding, in five seconds, whether a process has a legitimate reason to reach a server. Three things in the alert carry most of the answer: which binary is asking, where it lives on disk, and where it is going.
A process running from inside an app bundle in the Applications folder, belonging to an app that was opened deliberately a moment ago, is the easy case. A helper with a name close to a familiar one, running from a temporary or hidden directory, is the case worth pausing on. An updater checking in shortly after login is ordinary, and denying it means finding out later why the app never updates.
When the answer is not obvious, deny once rather than permanently. A denied connection that mattered shows up as a broken feature within minutes, and the rule can be changed. A permanent allow granted by reflex is the one nobody revisits, which is exactly how an alert-driven tool quietly becomes a tool that permits everything.
The trade in Allow Installed Applications deserves a moment. It buys quiet by trusting the state of the machine at install time. On a Mac that has been in service for three years, that is a broad grant. On a fresh machine it is nearly free. The conservative route is to leave it off and accept a louder first week, which is also the only way to learn what was already talking.
Where it cannot see
A tool that asks about connections is only as good as its view of them, and this one documents its blind spots rather than hiding them.
The first is structural. Per the project's own FAQ, "Some network traffic may not be routed through Network Extensions (such as LuLu). As such, such traffic is never seen by LuLu, and be cannot be blocked." Anything that bypasses the network extension mechanism bypasses the alerts.
The second affects how rules can be written. Blocking by host name is limited by what macOS exposes, and the FAQ points at Apple's own note that name based blocking applies to "Network.framework or NSURLSession connections". Applications that use their own networking stack, browsers included, can therefore be governed by address rather than by name. A rule meant to stop one hostname may not behave as written for those apps.
Neither point makes the tool useless. Both mean it should be read as visibility with teeth, not as a guarantee. An outbound firewall that catches the ordinary case is worth having even when a determined piece of software could route around it.
Side by side with the alternatives
Three tools get compared in this space: the firewall already on the Mac, LuLu, and Little Snitch from Objective Development.
| macOS firewall | LuLu 4.5.1 | Little Snitch 6.5 | |
|---|---|---|---|
| Traffic it governs | Incoming only | Outgoing | Outgoing, with a network monitor |
| Price | Included with macOS | Free, GPL-3.0 | Paid licence, 30 day trial |
| Where settings live | System Settings > Network > Firewall | Its own app and status bar item | Its own app and status bar item |
| Alerts on a new connection | No | Yes, per process | Yes, per process |
| Stealth mode for probes | Yes | Not its scope | Not its scope |
| Stated platform note | Part of the system | macOS 10.15 or later | 6.5 adds compatibility with macOS 27 Golden Gate |
| Documented gaps | Nothing outbound | Traffic outside network extensions, name based rules limited to some frameworks | See maker's documentation |
On price, the maker's order page lists a Little Snitch 6 single licence gift card at 59.00 euro and a bundle with Micro Snitch at 63.49 euro, and offers a 30 day trial of the app itself. Its own description covers the same core behaviour, "Whenever an app wants to connect to the Internet, Little Snitch shows a connection alert, so you can allow or deny the connection," plus a network monitor, DNS encryption and blocklists.
The honest summary is that the two outbound tools answer the same question and differ in polish, reporting and support model. The free one is not a crippled version of the paid one. Choosing between them is a question of whether the monitoring interface and the commercial support are worth the licence, and both are real reasons to pay.
Rules, once the noise dies down
Rules in LuLu are created in response to an alert or added manually through an Add Rule button in the Rules window, and they can be edited, deleted, exported and imported. The export matters more than it sounds. A rule set that took a fortnight of answered prompts to build is worth carrying to the next machine, and worth keeping a copy of before an operating system upgrade.
Reviewing the rule list every few months is the part everybody skips. Rules outlive the reason they were created, especially the ones added at speed while trying to get work done. An app uninstalled a year ago can still have a standing permission. The list is short enough to read in one sitting, which is not true of most security configuration.
It also lands in the menu bar
By default the tool puts an icon in the status bar, and it is rarely alone there. The kind of Mac that gets an outbound firewall is the kind that already has a VPN indicator, a backup tool, a clipboard manager, a battery limiter and two sync clients. On a laptop with a notch, the ones at the far left of that group simply disappear behind it.
LuLu offers a blunt answer: a No Icon Mode where, per the documentation, it "will run without an icon in the status bar," recoverable by launching /Applications/LuLu.app again to change the preference back. That works, and it costs the thing the icon was for. A security tool that is invisible is also a security tool whose state cannot be checked at a glance, and turning it off during a presentation means finding the app again afterwards.
The alternative is to keep the icon and make the bar hold more. A menu bar organizer hides the quiet indicators behind a divider and brings them back on a gesture, and the ones worth judging can still be clicked while the bar stays collapsed. That distinction is the whole difference between hiding icons and organizing them, and it is where these tools separate.
What to change first
Install the outbound firewall with Allow Apple Programs on and Allow Installed Applications off, then keep its status bar icon rather than reaching for No Icon Mode. If the bar is the reason the icon felt like a problem, fix the bar: Koffret collapses it while leaving every icon clickable, with a fourteen day trial and no card.
Frequently asked questions
Is LuLu really free, or is there a paid version with the good parts?
It is free and open source under GPL-3.0, with no paid edition holding back features. The project accepts sponsorship through its repository instead of selling licences. The current release is 4.5.1, dated 5 August 2026, and the product page lists macOS 10.15 or later as the requirement.
Do I still need the built-in firewall if I install this?
Yes, because they work in opposite directions. Apple's firewall in System Settings > Network > Firewall governs incoming connections and offers stealth mode, while an outbound tool asks about connections leaving the Mac. Turning one off does not compensate for the other.
How many alerts should I expect?
Expect a cluster in the first few days and much less after that, since each answer becomes a standing rule. Turning on the option that automatically allows processes signed solely by Apple removes a large share of the system's own traffic from the stream. Passive mode exists for the times when no interruption is acceptable, such as a presentation.
Can it block everything my apps send?
No, and the project says so. Traffic that is not routed through network extensions is never seen by the tool and cannot be blocked, and rules written against host names apply only to connections made through the frameworks Apple exposes for that, so some apps can only be governed by address. Treat it as visibility with enforcement for the ordinary case.
Can I run it without a menu bar icon?
Yes. There is a No Icon Mode that runs the app with no status bar item, and launching the app from the Applications folder lets you switch the icon back on. The cost is that the state of a security tool can no longer be checked at a glance, which is why hiding the icon behind a divider is usually the better trade than removing it.