Windows doesn’t make it easy to see what your installed apps are quietly sending out over the internet. Portmaster, a free and open-source tool, changes that by showing every outbound connection an app makes and giving you the power to block it.
What is Portmaster?
A free, open-source firewall built for visibility
Portmaster is developed by Safing and released as open-source software available on GitHub, running on both Windows and Linux. It functions as an application-layer firewall, meaning instead of just blocking ports or IP addresses, it identifies which specific process or app is trying to make a connection and lets you decide whether that connection should go through.
Once installed, it sits in the background monitoring outbound network traffic and presents it in a live-updating interface that lists every app, the destination it’s reaching out to, and whether that destination resolves to a known tracker, ad server, or malware domain. Because Portmaster resolves DNS requests through its own encrypted resolver rather than relying on Windows’ default DNS handling, it can catch connections other blockers miss and add a layer of privacy to everyday browsing. Users can set default block or allow behavior for new connections, then build permanent per-app rules over time as it learns what’s normal for that machine.
In practice, it works a lot like Little Snitch, the well-known macOS app firewall, except that it is built for Windows and Linux, platforms that have historically lacked a comparable option. Unlike a router-level solution such as Pi-hole, Portmaster runs directly on the machine, so it doesn’t require a separate device or server on the network, and it keeps protecting a laptop even when it’s away from home. The core application, including its blocklists and per-app controls, is free. Safing also offers an optional paid feature called SPN, a network that routes and encrypts traffic across multiple relays, functioning as an alternative to a traditional VPN for those who want it, though it isn’t required to use the firewall itself.
How useful is it?
Portmaster earns its keep the moment you install it and watch the connection list start to fill in. Most people are surprised by how many processes reach out to the internet in the background: game launchers, PDF readers, even some antivirus software regularly ping analytics or update servers without much explanation.
Because Portmaster labels each connection with the process name and destination, you get a clear picture of what’s happening rather than a vague warning. Its built-in filter lists block a large share of known trackers and ad networks system-wide, so the effect resembles running a network-level ad blocker like Pi-hole, but without needing a separate box on the network. That system-wide reach is one of its biggest advantages, since it applies the same protection to every app on the machine, not just a browser extension.
The secure DNS feature adds another layer, encrypting lookups so that even the addresses being requested aren’t easily visible to an ISP or a local network. For anyone who has wanted a Windows equivalent of the granular control Little Snitch gives Mac users, this comes close. Being able to click into an individual connection, see where a piece of software is sending data, and permanently allow or block it is a genuinely useful capability that Windows doesn’t offer natively.
On the other hand, the interface prompts frequent decisions early on, at least until rules accumulate, and less technical users may find themselves unsure which of the many unfamiliar processes making connections are actually safe to block. It’s most useful for people who already have some curiosity about their system’s network activity rather than as a fire-and-forget install for someone who wants zero involvement.
Should you use it?
Worth trying, with a learning curve attached
Whether to install Portmaster depends mostly on how much you care about knowing what your software does when you’re not looking. For privacy-conscious users, self-hosters who already run tools like Pi-hole, or anyone frustrated by increasingly aggressive telemetry from mainstream apps, Portmaster is one of the few tools built specifically for this on Windows, and it does the job well. It’s free, actively maintained, and doesn’t require specialized hardware or network changes to get running, which matters since comparable oversight has traditionally required a dedicated firewall appliance or a fair amount of technical setup.
That said, it isn’t the right fit for everyone. Blocking the wrong connection can break an app in ways that aren’t always obvious, so there’s some trial and error involved, especially in the first few days after installing it. People who want something that quietly works in the background without asking for input may find the early setup period more involved than they’d like.
Because it’s an actively developed, community-driven project, there’s also the usual caveat that comes with open-source software under continued development: occasional bugs or interface changes are possible, and it’s worth keeping expectations realistic rather than assuming flawless performance out of the box. For most people who are simply curious about what’s happening on their network, or who want more control than Windows Firewall offers without diving into enterprise-grade tools, Portmaster is a solid, low-risk option to try. It costs nothing to test, the paid SPN feature is entirely optional, and uninstalling it if it’s not a good fit is straightforward.
Portmaster gives Windows users real network visibility
Portmaster won’t be for everyone, but it fills a real gap on Windows: knowing exactly what your apps are doing online, and having the final say over it. For anyone curious enough to look, it’s worth the short learning curve.