// CopVPN FOR macOS · VERSION 3.3.1
macOS VPN
A universal build for Apple silicon and Intel, notarized by Apple. Menu-bar control, system-level kill switch, and a signed installer package.
Version 3.3.1 · .pkg · Apple silicon + Intel
- Version
- 3.3.1
Signed and notarized by Apple. Gatekeeper opens it without a warning.
Included with every plan. One account works on up to 20 devices, with 5 connected at once, so the same subscription runs on every other platform too.
[ 01 / This build ]
What the macOS build supports
macOS restricts what a VPN app may do more than Windows does. Two features work differently here, and we say how rather than listing them as supported.
| Feature | On macOS | What that means here |
|---|---|---|
| Kill switch | On macOS Supported | What that means here Enforced by the system network extension. Holds if the app quits unexpectedly. |
| Split tunneling | On macOS Limited | What that means here By destination domain or IP range, not per application. See the note below the table. |
| Auto-connect | On macOS Supported | What that means here Triggers on joining any network not on your trusted list. |
| Always-on | On macOS Supported | What that means here The network extension keeps the tunnel up across sleep and wake. |
| Start at login | On macOS Supported | What that means here Added as a login item during install. Removable in System Settings. |
| Multi-hop | On macOS Supported | What that means here Two servers in different countries. |
| Protocols | On macOS Supported | What that means here WireGuard and OpenVPN (UDP and TCP). |
| Custom DNS | On macOS Supported | What that means here Your own resolvers, with leak protection always on. |
| LAN access | On macOS Supported | What that means here Optional. Keeps AirPrint and local shares working while connected. |
| Menu bar control | On macOS Supported | What that means here Connect, switch server and check status without the main window. |
Split tunneling on macOS routes by destination address and domain, not by application. Apple does not expose a supported per-app routing API to VPN developers, and any app claiming per-app split tunneling on macOS is doing something unsupported.
[ 02 / Requirements ]
What you need to run it
One installer covers both processor families. The app checks which one you are on and runs natively.
- Operating system
- macOS 12 Monterey or later
- macOS 26 supported. Big Sur and earlier are no longer supported.
- Architecture
- Apple silicon and Intel
- Universal binary. No Rosetta needed on M-series Macs.
- Disk space
- 180 MB free
- Installs to /Applications.
- Memory
- 4 GB RAM
- Under 250 MB resident while connected.
- Permissions
- Admin password, once
- Required to approve the system network extension.
- Network
- Any internet connection
- Wi-Fi, Ethernet or iPhone hotspot.
[ 03 / Install ]
Installing on macOS
-
On first launch macOS blocks the network extension. Open System Settings › Privacy & Security, scroll to the blocked-software line and choose Allow, then enter your admin password.
[ 04 / If something goes wrong ]
Setup help for macOS
The problems people actually hit on this platform.
-
The system extension will not load
The approval step in System Settings is easy to miss, and the prompt disappears after a minute.
-
iCloud Private Relay conflicts
Private Relay and a VPN both try to own Safari traffic. What to turn off, and why.
-
Running from the menu bar only
Hiding the Dock icon and driving the whole app from the menu bar.
-
Uninstalling cleanly
Removing the app, the network extension and the login item together.
[ 05 / FAQ ]
macOS questions
Why does macOS ask for my password during install?
CopVPN installs a system network extension, which is what lets the kill switch work below the application layer. macOS requires an administrator to approve that once. After the approval, no further password prompts appear.
Is this the same app as the one on the App Store?
No. This page offers the direct macOS installer from copvpn.com. The iOS app on the App Store is a different product for iPhone and iPad — installing it will not give you a Mac app. If you landed here looking for iPhone, use the iOS page.
Does it run natively on Apple silicon?
Yes. The download is a universal binary, so M-series Macs run the native ARM build and Intel Macs run the x86 build. Rosetta is not involved either way.
Why is split tunneling different on Mac?
Apple does not give VPN developers a supported way to route traffic per application on macOS. CopVPN therefore splits by destination — you exclude a domain or an IP range rather than an app. It covers most of the same cases, and it is honest about what the system permits.
Does it conflict with iCloud Private Relay?
They overlap. Private Relay routes Safari traffic through Apple’s own relays, which sits awkwardly with a VPN tunnel. macOS usually disables Private Relay automatically while a VPN is active; if Safari behaves oddly, turn Private Relay off manually in System Settings › Apple Account › iCloud.
What happens when the Mac sleeps?
The network extension re-establishes the tunnel on wake before other apps get network access, so you do not get a window of unprotected traffic. Nothing needs to be reconnected by hand.
[ 06 / Every other device ]
Same account, every device
Install it on up to 20 devices at no extra charge, with 5 connected at once.
-
Windows VPN
Windows 10 or later, 64-bit
Set it up -
Android VPN
Android 7.0 or later
Set it up -
iOS VPN
iOS 15 or later
Set it up
Android TV, Linux, routers and the browser extension are covered on the main download page.
All downloads30-day money-back guarantee
Try CopVPN risk free. Unsatisfied? Contact us within 30 days of purchase for a full refund — every plan, every term. Manual wire and crypto payments are the one exception.