VPN Bypass
A macOS menu bar app that decides which traffic goes through your VPN. Pick the services and domains that should skip it, or the few that must use it, and it keeps the routes right as the VPN reconnects and addresses change.
Corporate VPN clients send everything through the tunnel, so streaming stalls, AirPlay and Chromecast break, and personal traffic crosses the company network. Most clients lock their own split tunnelling, and a route added by hand is gone at the next reconnect or when a CDN moves. VPN Bypass adds the routes for you from a menu bar dropdown and puts them back every time the VPN or the network changes.
The dropdown in Bypass mode, and the Settings window on the Services tab
Features
- Three modes: Bypass sends the destinations you list around the VPN, VPN Only sends only them through it, and Custom routes each rule where you say, first match wins.
- 37 built-in service packs (Telegram, WhatsApp, YouTube, Netflix, Spotify, Zoom, GitHub and more) plus any domain, wildcard or subnet you add.
- In Custom mode a rule can exit direct, through a specific VPN when several are up, through an HTTP or SOCKS5 proxy, or through a Tailscale peer.
- Routes come back on their own when the VPN reconnects or the network changes, and domains are re-resolved as their addresses rotate.
- Detects GlobalProtect, Cisco AnyConnect, OpenVPN, WireGuard, FortiClient, Zscaler, Cloudflare WARP, Pulse Secure, Check Point and Tailscale exit nodes.
- Leaves Tailscale's own range, loopback and the other tunnels alone, so a mesh VPN and local proxies keep working next to it.
vpnbscripts everything the app does over a socket only your account can open, and reads passwords from standard input, never from the command line.- No kernel or system extension to approve: one small root helper does the routing, and only this app can talk to it.
- Optional
/etc/hostsDNS bypass, route verification, notifications, launch at login, and config import and export.
Quick start
brew tap geiserx/vpn-bypass
brew trust --cask geiserx/vpn-bypass/vpn-bypass
brew install --cask vpn-bypass
Then open VPN Bypass from Applications, approve the one admin prompt that installs the root helper, connect your VPN, and turn on a service in Settings > Services or type a domain into the dropdown. It worked when the pill in the dropdown reads ON and the menu bar mark shows its arrow. Needs macOS 13 or later; the DMG, building from source and the fix for "the app is damaged" are in Getting started.
Documentation
Everything is at geiserx.github.io/VPN-Bypass.
- Getting started: Homebrew, DMG, source, and the first run
- Routing modes: Bypass, VPN Only and Custom; routes and rules
- Usage: the dropdown, the Settings tabs and the
vpnbCLI - MCP server: let an AI agent read and change VPN Bypass
- How it works: supported VPN clients and how they are detected
- Other VPNs and proxies: what it touches when several tunnels or proxies run
- Troubleshooting: Gatekeeper, routes, DNS and proxy errors
- Development: build, test, contribute
Related projects
vpn-bypass-mcp: an MCP server that lets an AI agent such as Claude Code read and change VPN Bypass through the same socket as vpnb.
License
GPL-3.0-or-later. Made possible by generous supporters: Lee.