NetMute

Safari Shield

A content blocker for Safari that runs on NetMute's tracker list. It closes the one gap a network filter cannot close on its own: what leaves Safari through iCloud Private Relay.

Safari Shield

The connection the network filter never sees

NetMute normally decides at the network layer. An app opens a connection, the filter reads the destination, your rules apply. That is why one switch can cover every app on the Mac at once.

iCloud Private Relay changes that picture for Safari. With it on, Safari's traffic leaves your Mac through Apple's relay, and what the filter sees is the relay, not the site the request was actually for. Your rule is still there. The destination it was written against is no longer visible at that layer.

Safari Shield takes the other route. It is a Safari content blocker: the tracker list is applied inside the browser, before the request goes out, where the destination is still plain.

One switch in NetMute, one in Safari

Turn Safari Shield on in NetMute, then enable the extension once under Safari › Settings › Extensions. From then on Safari matches against the same curated tracker list NetMute uses at the network level, compiled into the content-blocker rules Safari understands.

A content blocker never sees your browsing. NetMute hands Safari a rule set, and Safari does the matching itself. Which pages you open is not reported back, and no page content passes through NetMute.

The site-critical groups apply here too. Endpoints a page needs in order to work, such as bank logins, 3-D Secure confirmations and consent dialogs, are let through by default, so a stricter list does not turn into a broken checkout.

When this is the layer that matters

  • iCloud Private Relay is on. The case Safari Shield exists for: Safari's traffic is relayed, and the network filter can no longer attribute it to a host.
  • You browse mostly in Safari. The trackers you meet most are the ones on the pages you open, and this is the layer closest to them.
  • You want both layers. The network filter keeps covering every other app on the Mac, and Safari Shield adds the browser on top.

Two layers, stated honestly

Safari Shield does not replace the network-level Tracker Shield, and the network-level shield does not replace Safari Shield. They sit at different layers and they fail in different places: a content blocker only ever sees Safari, and a network filter only ever sees what the network still exposes.

The honest limit sits right next to it: Safari Shield applies to Safari only. It does not extend to other browsers, and switching it on changes nothing for apps outside the browser. Those stay with the network filter, where they always were.

Key benefits

  • A second route to the tracker list, inside Safari itself
  • Keeps working when iCloud Private Relay hides the destination from the network filter
  • The same curated list, compiled into Safari content-blocker rules
  • Site-critical endpoints stay allowed, so logins and checkouts keep working
  • Nothing about your browsing reaches NetMute: Safari does the matching

Frequently Asked Questions about Safari Shield

Do I still need the network-level Tracker Shield?

Yes. Safari Shield covers Safari. The network-level shield covers every other app on your Mac, from your mail client to background services. They are two layers, not two versions of the same thing.

Does Safari Shield see the pages I visit?

No. A Safari content blocker is handed a rule set and Safari does the matching itself. NetMute is not told which pages you open, and no page content passes through it.

Why is this needed when NetMute already filters the network?

iCloud Private Relay routes Safari's traffic through Apple's relay, so at the network layer the destination host is no longer visible. A content blocker works inside Safari, where it still is.

Ready for full control?

Get NetMute in the Mac App Store. One-time purchase, lifetime updates.

Download NetMute from the Mac App Store