Using a VPN on Mac comes down to four steps: install the client, approve system permissions, import a subscription link, and confirm the route is live. The part that actually trips people up isn't the clicking — it's how macOS vets system extensions and VPN configurations. Until those permissions are approved, the client can look perfectly normal while none of your traffic goes through the proxy.
What follows is the full walkthrough in order, from a clean install onward, with a check you can run yourself at every step. No command-line experience is needed; the only terminal command in this guide appears in the DNS check section, and you can simply copy and paste it.
Download the macOS client and prepare to install
Open the VPNAY website and sign in with your username and password. Creating an account requires no email address and no other personal details, and accounts are anonymous with a no-logs policy. Once you're in, pick the macOS build on the download page to get the installer. The same account works on Windows, iOS, Android, and Linux, with no limit on the number of devices, so you never pay per device.
Plans come in two forms: monthly subscriptions and data packs. Monthly data resets each month on the day you started, and upgrading mid-cycle is prorated by the remaining days. Data packs last until they run out and never expire. Your first payment is covered by a 30-day no-questions-asked full refund, and payment supports Alipay, WeChat, and USDT.
| Type | Price | Data | Notes |
|---|---|---|---|
| Monthly subscription | ¥9.9 / month | 60GB | Data resets monthly on your start date |
| Monthly subscription | ¥18 / month | 250GB | Mid-cycle upgrades are prorated by remaining days |
| Monthly subscription | ¥28 / month | 500GB | Best for several devices online at once |
| Data pack | ¥158 | 300GB | Lasts until used up, never expires |
| Data pack | ¥358 | 1000GB | Lasts until used up, never expires |
| Data pack | ¥658 | 3000GB | Lasts until used up, never expires |
For everyday browsing and video, the 60 GB monthly tier is a fine starting point; if you keep several devices online at once, or run long downloads on your Mac, start at the 250 GB tier instead. Coverage spans 120+ countries and 250+ routes, and you can check the regions and route types in the server list.
Installation and system extension approval
Drag the client into the Applications folder and launch it for the first time. macOS raises two kinds of prompts: one says the system extension was blocked, the other asks whether to allow a VPN configuration. Approve both. Skip either one and you get a client that reports "Connected" while no traffic actually flows.
Approve the system extension
The exact path varies slightly by macOS version: on newer releases it's System Settings → General → Login Items & Extensions → Network Extensions, while older versions use System Preferences → Security & Privacy. Find the VPNAY entry, turn the switch on, and enter your Mac login password when prompted. On some versions you'll need to restart the client once before the extension actually takes effect.
A system extension is how macOS expects VPN-style apps to run: the client has to take over network traffic through it, rather than just opening a local port the way an ordinary app would. That also explains why the first install is fussier than later updates — you approve the permission once, and the system remembers it.
Adding a VPN configuration and the keychain prompt
On the first connection, macOS shows "App wants to add VPN configurations" — enter your Mac login password and allow it. This step only writes the configuration into the system network settings; it doesn't change how other apps use the network. If the client offers to save your account, a keychain access request follows — choose Always Allow and you won't be asked again.
After the first launch you may also see a "Background items added" notification. Allow it so the client can start at login and refresh your subscription in the background.
Don't run two proxy clients at once
Two proxy clients will fight over the system proxy port and the network extension. The classic symptom is a full list of healthy nodes and pages that still won't load — easy to misread as a route failure while troubleshooting.
Import the subscription link
A subscription link is an address generated by the dashboard. It carries your account credentials and the list of routes currently available. The client reads it once and knows which servers to connect to and where to pull updates from.
Import steps
- Copy the full link from the subscription section of the dashboard, and make sure you don't drop the parameters at the end.
- Back in the client, open the Subscriptions / Profiles entry and choose import from clipboard, or just paste the link.
- After saving, click Update Subscription once and wait for the route list to refresh.
- Turn on Auto-Update Subscription and the client will pull the latest routes on its own — nothing more to manage day to day.
Choosing split-tunnel rules and DNS
Most macOS clients offer two modes. Rule mode sends mainland China sites direct and international traffic through the proxy — the right default for everyday use. Global mode hands all traffic to the proxy, which is useful for troubleshooting or for services that only work in certain regions. Point DNS at the proxy as well: that way resolution requests never reach your local ISP, and you avoid the half-working state where the exit IP has changed but lookups are still local.
The protocols your nodes use come down with the subscription link, and the client matches them automatically — no manual configuration. The differences between them show up mainly in UDP forwarding and how they behave on a weak connection. For browsing, video, and downloads, just pick a route with low latency.
A subscription link is as sensitive as your credentials
Don't post it in public groups or share screenshots of it. To use another device, just sign in to the same account on that device — there's no need to forward the link. If it does leak, reset it once in the dashboard and the old link stops working immediately.
Verify the route is really working
A "Connected" status in the client only means the process started — not that traffic is going through the proxy. Confirm it with three independent checks; if any one of them fails, the setup isn't finished.
- ✅ Open this site's My IP page: the exit IP should be located in the same region as the route you picked, not your local ISP.
- ✅ Run
scutil --dns | grep 'nameserver\['in Terminal — the resolvers it lists should no longer be your local ISP's addresses. - ✅ Sites reachable only through international routes load normally, while mainland China sites stay just as fast — that means the split-tunnel rules are working.
- ❌ The exit IP hasn't changed: traffic isn't being captured. Go back and check the system extension and system proxy settings.
- ❌ The resolvers are still your ISP's: DNS is going out directly. Set the client to resolve through the proxy.
- ❌ Nothing loads at all: first confirm the subscription updated successfully, then work through the next section in order.
The route itself is worth choosing carefully, too. Dedicated lines (IEPL) run on their own channel and are less exposed to public-internet swings; relay routes add one extra hop over the public internet and are usually steadier than a direct connection. The server list on this site labels each route by region and type, so you can switch as needed.
What counts as working: the exit IP has changed, DNS lookups no longer go through your local ISP, and the target site loads — all three at once. A status that simply reads "Connected" proves nothing on its own.
macOS permission prompt reference table
These are basically the only prompts you'll meet during a first-time setup, so just match them against the table. What they share: each one has to be allowed manually in System Settings, and once you decline, macOS won't ask again on its own.
| Prompt | When it appears | What to do |
|---|---|---|
| "Developer cannot be verified" | First time you open the installer or app | System Settings → Privacy & Security, click Open Anyway |
| "System extension blocked" | After the client's first launch | General → Login Items & Extensions → Network Extensions, allow it, then restart the client |
| "App wants to add VPN configurations" | First connection | Enter your Mac login password and allow |
| "wants to use your keychain" | Saving or reading account credentials | Choose Always Allow; affects this Mac only |
| "Background items added" | After the first launch | Allow it; used for launch at login and automatic subscription updates |
Permissions only need approving once
macOS remembers extensions and configurations you've approved, so routine client updates usually won't ask again. If a major macOS upgrade brings the prompt back, allow it once along the same path — your subscription and account are unaffected.
The troubleshooting order for "connected but pages won't load"
This problem can almost always be pinned down with a fixed order. The principle is to work from the outside in: first confirm whether traffic is being captured at all, then look at split-tunnel rules and DNS, and only then suspect the node itself.
- Confirm traffic is being captured. Open the My IP page and check where the exit is located. If it hasn't changed, the system proxy or network extension isn't active — go back to the permissions section and approve it again.
- Switch modes to rule out a split-tunnel mistake. Temporarily switch to global mode. If pages load right away, the rule set was sending that domain direct — add it to the proxy rules.
- Check the system clock. A large time offset breaks timestamp-based handshake checks and skews certificate validation, which shows up as a connection that works but loads no HTTPS pages at all. Turn on Set Date and Time Automatically, then try again.
- Flush the DNS cache.Run these two commands in Terminal, then reconnect:
sudo dscacheutil -flushcache sudo killall -HUP mDNSResponder - Make sure no second proxy is running. Quit other proxy clients and browser proxy extensions so they can't grab the port and system proxy settings.
- Check the system extension status. After a macOS upgrade or a security-software cleanup, the extension can revert to an unapproved state — allow it again under Login Items & Extensions.
Narrow the scope before you troubleshoot
If only a few sites fail, suspect the split-tunnel rules and the site's own regional restrictions first. If nothing loads at all, that's when you start at step 1 above.
The order matters more than any trick: confirm traffic is being captured, then check split-tunnel rules and DNS, and only then suspect the node. Most "connected but pages won't load" cases are solved in the first two steps — switching nodes won't help.
FAQ
Do I need to set everything up again on a new Mac?
You'll reinstall the client and import the subscription link, but you won't pay again. One account covers unlimited devices, so a Mac, a Windows PC, and an iPhone can all be online at once.
Will the VPN configuration linger after I uninstall the client?
It can. Delete the leftover configuration under System Settings → Network → VPN, then remove the matching extension under Login Items & Extensions.
How often does the subscription link need updating?
With auto-update on, the client pulls changes on its own. Manual updates are only needed when the dashboard announces route changes — one click is enough.
What happens when my data runs out?
Monthly subscription data resets each month on your start date. You can also buy a data pack in the dashboard, starting at ¥158/300 GB — it lasts until it's used up and never expires.