Rules expire without telling you
You block a domain for an app. A year later the app is gone, the domain has moved, or a broader rule you wrote in between already covers it. Nothing about the list changes: the rule still sits there, still looks like a decision, and quietly does nothing.
Rule Cleanup is the page that goes looking for those. It reports what it finds, with the reason next to it.
What it looks for
- App uninstalled, rule still standing. A block against something that is no longer on the Mac.
- A rule another rule already shadows. `cdn.example.com` next to `example.com`: the parent rule decides first, so the longer one can never fire.
- A domain Tracker Shield already covers. The rule is not wrong, just redundant: the shield stopped it before the rule was ever consulted.
- An app rule a general rule has superseded. The broader rule handles the case; the narrow one adds nothing.
Findings arrive in two groups. Ineffective is the list that can go: each row carries a Delete rule button, and a Delete all for the group. Inform only is the list that cannot: a rule that simply has not been triggered in 30 days is reported there, with no delete button attached.
Each finding is stated as a claim you can check, in words rather than a severity colour. Nothing is deleted automatically. You delete what you delete: the button is there, and pressing it is your call.
When a cleanup pass pays off
After months of use, when the list has grown past the point where you can hold it in your head. After uninstalling a batch of apps. And after switching a domain from a per-app rule to a global one, which is the moment the older, narrower rules become dead weight without ever announcing it.
An honest list is shorter than a long one
A rule list you no longer trust is one you stop reading, and a list you stop reading is where a wrong rule survives for years. Removing what cannot fire is not cosmetic: it is what keeps the remaining rules readable.
Which is also why cleanup deliberately stops short of one thing. A rule that simply has not fired in 30 days is not listed here as removable. It appears in Rule Insights as a hint, without a delete button, because rarely used is not the same as dead.
Key benefits
- Finds rules for apps that are no longer installed
- Names subdomain rules a parent rule already shadows
- Flags domains Tracker Shield covers anyway
- Flags app rules a broader rule has superseded
- Every finding carries a reason, and nothing is deleted without you
Frequently Asked Questions about Rule Cleanup
Does NetMute delete rules on its own?
No. Cleanup finds and explains; the button is yours to press. Nothing on this page happens in the background.
Why are unused rules not offered for deletion?
Because 30 days without a hit is not evidence for a service you use rarely. That case shows up in Rule Insights as a hint. This page only lists rules that provably cannot fire: a shadowed rule, an app that is gone.
If Tracker Shield already covers a domain, why did my rule ever exist?
Usually because you wrote it first, or the shield's list grew to include it later. The rule is not wrong. It is just never reached, since the shield decides first.

