VPNonly how it works guides faq install github

Mullvad split tunneling on Mac

Mullvad's own macOS app has split tunneling, but it's exclude-only: your whole Mac joins the VPN and you pick apps to leave out. If that's the model you want, it's included with your subscription — use it.

If you want the opposite — your Mac stays on its normal connection and one app joins the tunnel — Mullvad hands out standard WireGuard configs you can point a per-app tool at.

Get a WireGuard config from Mullvad

  1. Sign in at mullvad.net → WireGuard configuration.
  2. Generate a key, choose the countries you want, and download the zip.
  3. One key covers every server, so the zip holds a few hundred .conf files that all share it.

Put one app on it with VPNonly

  1. Install VPNonly and open the menu → Import WireGuard config….
  2. Choose the whole zip — VPNonly turns it into a single Mullvad entry with a country picker, the way NordVPN's country list works. Pick the exit country from the menu at the bottom.
  3. Search for an app, flip its switch. It relaunches once, then it's on the VPN and nothing else is.

Tested 1 September 2026: imported the full zip, chose Singapore, and VPNonly's own check showed a Mullvad exit address with the Mac's normal address unchanged. Mullvad enforces strict cryptokey routing, which needs VPNonly 1.9.16 or later — earlier versions connect but carry no traffic.

Get VPNonly for Mac — $19

The app’s exact privileged engine source is public and MIT licensed.

Other providers

NordVPN · Proton VPN · Surfshark · IVPN · ExpressVPN · AirVPN or your own server. Or see which Mac VPNs have split tunneling, provider by provider.