Why ExpressVPN quietly dropped the feature on modern macOS, the real risk of recovery-mode workarounds, and how to route traffic cleanly.
Looking for an alternative that handles split traffic on current macOS without touching system security?
If you typed this exact phrase into a search bar, you probably just went through a very specific kind of frustration.
You upgraded your macOS version, launched ExpressVPN, and headed into the preferences menu to route only your browser or specific development tools through the VPN—while keeping Slack, Zoom, and local network printers on your direct connection. But the option was either greyed out, completely gone, or accompanied by a help article suggesting you restart your Mac into Recovery Mode, pop open Terminal, and run `csrutil disable`.
For anyone who relies on a Mac for daily work, client projects, or personal banking, that suggestion feels absurd. Disabling System Integrity Protection (SIP) turns off core macOS root defenses just so a commercial app can inject legacy kernel hooks. Nobody should have to weaken their entire operating system’s security model just to bypass a VPN tunnel for local traffic.
The problem isn't your Mac, and you don't need to leave your system wide open. Here is what actually changed inside macOS, why so many legacy VPNs gave up, and how you can get selective routing back without compromising system security.
## Why Split Tunneling Broke Across Legacy Mac VPNs
To understand why this feature disappeared, you have to look at what Apple did starting with macOS Big Sur and refined in subsequent releases.
Historically, older VPN clients implemented split tunneling by loading custom Kernel Extensions (Kexts). These extensions sat deep within macOS, intercepting outbound packets at the kernel level and deciding which process went where. It was powerful, but it was also inherently unstable. If a VPN kernel extension crashed, your entire Mac suffered a kernel panic and restarted.
To stop third-party software from crashing machines and introducing vulnerabilities, Apple deprecated Network Kernel Extensions entirely and locked down the kernel behind SIP. Instead, Apple introduced the modern NetworkExtension and Packet Tunnel Provider frameworks.
Under this modern architecture, an app runs safely in user space. But routing traffic on a per-application basis through modern system frameworks requires an entirely different technical implementation. Many established VPN providers—including ExpressVPN—relied heavily on their legacy architecture. Rebuilding native, granular application routing to comply with Apple's hardened runtime meant significant engineering overhauls.
Rather than doing the heavy lifting immediately, some providers simply removed split tunneling on modern macOS releases, while others posted workarounds advising technical users to downgrade security checks in Recovery Mode.
## The Problem With "Just Turning Off SIP"
When a forum post or support agent tells you to run `csrutil disable`, it sounds like a quick terminal shortcut. In reality, it strips away the primary barrier protecting your Mac from rogue processes.
System Integrity Protection prevents unauthorized modifications to critical system directories, restricts process code injection, stops unsigned kernel extensions from executing, and protects internal system memory. Disabling SIP does not just let a VPN alter network routes; it leaves your entire machine vulnerable to any privilege escalation attempt from other untrusted software.
If your machine is managed by an employer or contains sensitive client data, turning off SIP is often an immediate compliance violation. Even on a personal machine, treating core operating system security as expendable just to route browser traffic cleanly makes zero sense.
The standard you should demand from any network tool on a Mac is simple: it must work entirely within Apple's supported system frameworks without asking for root-level exceptions.
## What to Look For in a Mac-Compatible Alternative
When you look for an alternative that genuinely handles split traffic on recent macOS versions, traditional "Top 10 VPN" review lists are largely useless. Most affiliates copy feature sheets without testing whether split tunneling actually functions on current macOS builds.
Before paying for another subscription, look for these specific criteria:
1. **Zero SIP Modification:** The software must never require disabling SIP, editing nvram boot arguments, or running recovery terminal scripts.
1. **Domain or App-Level Granularity:** It should offer rules-based routing—whether by letting you specify target applications or defining routing rules based on destination domains and IP ranges.
1. **Clean Teardown:** When the tunnel is disengaged or your laptop goes to sleep, the routing tables should revert instantly without leaving orphaned virtual interfaces or locking your local Wi-Fi.
## How ONLYDOGSVPN Approached This
If you are tired of legacy VPN clients that treat modern macOS security like an inconvenience, take a look at ONLYDOGSVPN.
ONLYDOGSVPN was designed with current operating system architectures in mind rather than clinging to decade-old kernel designs. Instead of demanding low-level kernel bypasses, it operates strictly within secure, modern networking standards. You can configure split routing cleanly—keeping high-bandwidth local traffic, streaming services, or company intranet connections on your default interface while routing designated tools and browsing through encrypted nodes.
Your Mac’s security perimeter remains completely intact. You don't have to touch Terminal, you don't have to reboot into Recovery Mode, and you don't have to choose between functional routing and baseline system integrity.
## Who Shouldn't Switch Yet
To keep expectations realistic, this might not be the right move for everyone.
If you don't actually need selective traffic routing—meaning you are completely happy running full-tunnel mode where 100% of your Mac's internet traffic goes through the VPN at all times—then ExpressVPN's standard connection may still suit you fine. In that scenario, paying for a replacement service simply to regain a setting you don't use daily isn't necessary.
Similarly, if you are running a very old, unmanaged macOS setup where SIP was disabled years ago for specialized firmware modification, legacy workarounds might already be part of your routine.
However, if you depend on a modern, secure Mac for daily productivity, and you need your traffic split without compromising the operating system's built-in defenses, relying on outdated network methods is an unnecessary risk. Your tools should adapt to the operating system they run on—not ask you to break the OS just to stay connected.