How to Stop Your Mac from Automatically Responding to Pings (ICMP Echo Requests)

By default, macOS is designed to respond to ICMP Echo Requests (commonly known as “Pings”). If another device on your local Wi-Fi network (or across the internet, if your router forwards the port) opens a terminal and types ping [your-macs-ip-address], your Mac will automatically reply, confirming that it is currently powered on and actively connected to the network.

While pinging is a fundamental tool for network troubleshooting, it is also the very first tool malicious actors use to map a network. By blasting a subnet with ping requests, a bad actor can instantly generate a list of active, vulnerable targets. If you are connected to a public Wi-Fi network at a coffee shop or an airport, broadcasting your presence is a massive security risk.

You can configure the macOS built-in firewall to activate “Stealth Mode,” which forces your Mac to completely ignore all uninvited network traffic, including pings.

How to Enable Stealth Mode on macOS

You can block ICMP echo requests directly from the System Settings without needing to use the terminal.

  1. Click the Apple Logo in the top left corner of your screen.
  2. Select System Settings (or System Preferences on older versions).
  3. Click on Network in the left-hand sidebar.
  4. Click on Firewall in the right pane.
  5. Ensure the Firewall toggle switch is turned On. (If the padlock in the bottom left is closed, click it and enter your password to make changes).
  6. Click the Options… button.
  7. In the pop-up window, look for the checkbox labeled Enable Stealth Mode.
  8. Check this box.
  9. Click OK.

From this moment forward, your Mac is completely invisible to casual network scanning. If another computer attempts to ping your IP address, the requests will simply time out, making it appear as though your IP address is empty and your computer does not exist.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.