Changelog

Follow up on the latest improvements and updates.

RSS

new

fixed

improved

Mac Roaming Client

RC Release Channels

09/23 September 23 - macOS Roaming Client v2.4.6 Production

Version 2.4.6 of the macOS Roaming Client is now available on the
Production
channel. This release brings together every update from the 2.4 Beta series (v2.4.0 through v2.4.6). To install, download the latest production installer from the dashboard under
Deployments → Roaming Clients
. Auto-upgrades will roll out gradually.
⚠️ Action Required: Redeploy the Updated Certificate Profile
v2.4.6 checks for the new
DNSFilter Root CA G1
certificate. Devices that still have the previous certificate profile will show a
Fix Installation Issues
prompt in the menu bar after upgrading.
Filtering and protection keep working normally while the prompt is showing.
To clear the prompt, download the updated
Combined_Certificates.mobileconfig
(or the branded or white-label profile you deploy) from the Prerequisites section of the macOS Roaming Client install guide and push it through your MDM. The updated profile replaces the installed one in place. We recommend pushing it before auto-upgrade reaches your devices.
⚠️
Minimum macOS Version:
The macOS Roaming Client now requires macOS 13 Ventura or later.
✨ What's New
  • IPv6 Support
    : Filtering and protection now cover IPv6 networks, so users on dual-stack and IPv6-only networks stay protected. Administrators can set upstream resolution to IPv4-only, IPv6-only, or automatic.
  • Filtering Stays On Through a VPN (Opt-In)
    : Devices using encrypted DNS now keep DNSFilter filtering on while a corporate VPN is connected, even when the tunnel blocks the DNS-over-TLS port. Filtering switches to DNS-over-HTTPS, so remote and hybrid users on VPN stay protected and keep encrypted DNS. To turn it on for an install, set
    ENABLE_DOH_FALLBACK=true
    . The deployment guide covers setup and network requirements.
  • Component Version Mismatch Detection
    : The Roaming Client now detects when the menu bar app, system extension, and daemon are running different versions, which can happen after upgrades or MDM-managed installs. When it finds a mismatch, it alerts the user, who can fix it from the menu.
  • Modernized Configuration Architecture
    : The agent now uses a more resilient
    configuration.json
    format in place of the legacy
    daemon.conf
    . Configuration changes apply more reliably without restarting the agent, and existing installations migrate automatically on upgrade. Upstream protocol order settings, including DNS-over-TLS, now apply as configured.
  • Local Domains Stay Current
    : Changes to local domains and resolvers made in the dashboard now apply right away, with no daemon restart needed, and internal domains stay on their assigned local resolvers after restarts and upgrades.
🛠️ Improvements
  • Every Certificate Root in One Profile
    : The macOS certificate profiles now install all DNSFilter roots in a single push, including DNSFilter Root CA G1.
  • Travel Wi-Fi Keys Match the Docs
    : Install-time configuration keys now use the same Travel Wi-Fi names as the dashboard and documentation, and Travel Wi-Fi settings in
    dns_agent.conf
    apply at CLI install. Existing scripts that use the previous names keep working.
  • More Resilient Connectivity
    : The agent's connection handling and upstream failover have been rebuilt, so devices stay filtered as networks change, with less need for a manual restart.
🪲 Bug Fixes
  • Captive portals:
    Captive portal detection is more accurate, the Access Captive Network option clears once you're connected, and Travel Wi-Fi appears as expected when configured through JSON
  • Site assignment:
    Changing a device's Site Key now properly updates its site and policy in the dashboard
  • Menu bar:
    The menu bar icon stays responsive and shows the right state when there's no network connection, and Travel Wi-Fi mode stays in the menu after a reboot
  • Diagnostics:
    Diagnostics are collected more securely and include more complete information

new

improved

fixed

Mac Roaming Client

RC Release Channels

Beta

09/16 September 16 – macOS Roaming Client v2.4.6 Beta

Version 2.4.6 of the macOS Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
✨
What's New
Filtering Stays On Through a VPN (Opt-In)
– Devices using encrypted DNS now keep DNSFilter filtering enforced while a corporate VPN is connected, even when the tunnel blocks the DNS-over-TLS port. Filtering continues over DNS-over-HTTPS, so remote and hybrid users stay protected on VPN without giving up encrypted DNS. Turn it on per install with
ENABLE_DOH_FALLBACK=true
; see the deployment guide for setup and network requirements.
🛠️ Improvements
Every Certificate Root in One Profile
– The published macOS certificate profiles now install all DNSFilter roots in a single push, including the new DNSFilter Root CA G1. Re-download the profile you already deploy and push it, and it replaces the installed one in place.
Travel Wi-Fi Keys Match the Docs
– Install-time configuration keys now use the same Travel Wi-Fi naming as the dashboard and documentation. Existing scripts keep working with the previous names.
🪲 Bug Fixes
  • Fixed an issue where deploying with a configuration override and no site key cleared the existing device configuration.
  • Fixed an issue where the Diagnostic Tool failed on the first run after a clean install.
  • Improved how diagnostics are collected and what the diagnostic bundle includes.

new

Mac Roaming Client

RC Release Channels

Beta

08/06 August 6 – macOS Roaming Client v2.4.5 Beta

Version 2.4.5 of the macOS Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
⚠️
Minimum macOS Version Update
– Starting with v2.4.4, the macOS Roaming Client requires macOS 13 Ventura or later. macOS 12 Monterey is no longer supported.
🪲 Stability & Connectivity Fixes
  • Fixed a DNS failover issue introduced in the 2.4 series that could cause intermittent resolution failures. When a lookup fell back to a backup server or protocol, the retry could be rejected or dropped — most pronounced with secure DNS (DNS-over-TLS) as the primary protocol, where affected devices could see a large share of queries fail and, with fail-close enabled, lose connectivity until the agent recovered.

new

Mac Roaming Client

RC Release Channels

Beta

07/22 July 22 – macOS Roaming Client v2.4.4 Beta

Version 2.4.4 of the macOS Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
⚠️
Minimum macOS Version Update
– Starting with v2.4.4, the macOS Roaming Client requires macOS 13 Ventura or later. macOS 12 Monterey is no longer supported.
🛠️ Improvements
Live Local Domain and Resolver Sync
– Local domain and resolver configuration changes made in the dashboard now apply without requiring a daemon restart, keeping filtering current as your environment changes.
🪲 Stability & Connectivity Fixes
  • Fixed an issue where large DNS records (such as TXT, SPF, DKIM, and DNSSEC records) could not be resolved while the agent was active, as truncated UDP responses were not being retried over TCP
  • Fixed an issue where local domains defined in the configuration file lost their assigned resolvers, causing matching queries to fall through to public resolvers instead
  • Fixed an issue where the menu bar icon could become unresponsive, particularly when no network connection was available

new

Mac Roaming Client

RC Release Channels

07/16 July 16 – macOS Roaming Client v2.4.3 Beta

Version 2.4.3 of the macOS Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
🪲
Stability & Connectivity Fixes
  • Fixed an issue where device hostnames were not automatically reported to the dashboard on fresh installs of v2.4.2, causing devices to appear with no hostname in the device list
  • Fixed an issue where reinstalling or upgrading the agent could create duplicate device entries in the dashboard
  • Resolved an issue where reassigning a device to a different site by changing the Site Key did not correctly update the device's site assignment and policy in the dashboard — the device now registers to the new site as expected on both live key changes and clean reinstalls
  • Fixed an issue where Travel Wi-Fi configuration settings (
    ALLOW_MANUAL_CAPTIVE_PORTAL
    ,
    ALLOW_PROXY_DISABLE
    , and
    CAPTIVE_PORTAL_DELAY
    ) were silently ignored when set in the
    dns_agent.conf
    file during CLI installation. These settings are now correctly applied on install

fixed

Web App

API

Mac Roaming Client

07/02 July 2 – Web Application and API Update

🪲 Hot Fix
macOS Roaming Client Duplicate Registrations
– Resolved a device identification issue on macOS Roaming Client 2.4.2 that could cause the same device to register more than once. Existing duplicates were consolidated.

new

Mac Roaming Client

RC Release Channels

06/23 June 23 - macOS Roaming Client v2.4.2 Production

Version 2.4.2 of the macOS Roaming Client is now available on the
Production
channel. To install, download the latest production installer from the dashboard under
Deployments → Roaming Clients
.
✨ What's New
Component Version Mismatch Detection
– The Roaming Client now detects when the menu bar app, system extension, and daemon are running mismatched versions — a scenario that can cause features to behave unexpectedly after upgrades or MDM-managed installs. When a mismatch is detected, users are alerted and can resolve it directly from the menu.
🪲 Stability & Connectivity Fixes
  • Fixed an issue where the agent could fail to start correctly on macOS boot due to a stale local DNS configuration file from a previous session, causing it to get stuck and never recover without a manual restart
  • Addressed an intermittent offline issue where some endpoints could go offline after waking from sleep or switching networks and require a reboot to recover
  • Corrected a regression where Travel Wi-Fi mode would disappear from the menu after rebooting with Wi-Fi disabled, on machines with certain network extensions present
  • Restored the allow_proxy_disable configuration setting, which was silently dropped when upgrading from 2.3.x to 2.4.x — the setting is now correctly carried forward
  • The menu bar icon now correctly shows the offline state when the device has no network connection, without surfacing a spurious "Fix Installation Issues" warning that doesn't apply in that context

new

Mac Roaming Client

RC Release Channels

Beta

06/15 June 15 – macOS Roaming Client v2.4.2 Beta

Version 2.4.2 of the macOS Roaming Client is now available on the
Beta
channel. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
✨ What's New
Component Version Mismatch Detection
– The Roaming Client now detects when the menu bar app, system extension, and daemon are running mismatched versions — a scenario that can cause features to behave unexpectedly after upgrades or MDM-managed installs. When a mismatch is detected, users are alerted and can resolve it directly from the menu.
🪲 Stability & Connectivity Fixes
  • Fixed an issue where the agent could fail to start correctly on macOS boot due to a stale local DNS configuration file from a previous session, causing it to get stuck and never recover without a manual restart
  • Addressed an intermittent offline issue where some endpoints could go offline after waking from sleep or switching networks and require a reboot to recover
  • Corrected a regression where Travel Wi-Fi mode would disappear from the menu after rebooting with Wi-Fi disabled, on machines with certain network extensions present
  • Restored the
    allow_proxy_disable
    configuration setting, which was silently dropped when upgrading from 2.3.x to 2.4.x — the setting is now correctly carried forward
  • The menu bar icon now correctly shows the offline state when the device has no network connection, without surfacing a spurious "Fix Installation Issues" warning that doesn't apply in that context

new

Mac Roaming Client

RC Release Channels

Beta

05/22 May 22 – macOS Roaming Client v2.4.1 Beta

Version 2.4.1 of the macOS Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel.
🪲 Hotfix
AirPrint Connectivity with macOS Agent Enabled
– Resolved an issue where AirPrint was unresponsive while the macOS Roaming Client was active. AirPrint now works as expected with the agent enabled.

new

Mac Roaming Client

RC Release Channels

05/21 May 21 – macOS Roaming Client v2.4.0 Beta

Version 2.4.0 of the macOS Roaming Client is now available on the
Beta channel
. To install, download the latest beta installer from the dashboard under
Deployments → Roaming Clients → Beta Channel
.
✨
What's New
IPv6 Support
– Filtering and protection now extend to IPv6 networks, keeping users on dual-stack and IPv6-only environments protected without falling back to unfiltered resolvers. Administrators can configure IPv4-only, IPv6-only, or automatic upstream resolution to fit their network.
Modernized Configuration Architecture
– The agent now uses a more resilient configuration format, replacing the legacy
daemon.conf
with
configuration.json
. Configuration changes apply more reliably without agent restarts, recoverable errors no longer cascade into broader issues, and existing installations migrate cleanly on upgrade.
🪲
Stability & Connectivity Fixes
  • Resolved an issue where DNS queries could fail on certain cellular and mesh network setups, causing slow or failed page loads
  • Addressed an edge case where connection reuse on DNS-over-TLS upstreams could cause the client to enter a fail-closed state on some devices
  • Resolved an intermittent issue where internal domains could fail to resolve through local resolvers in certain upgrade scenarios
  • Fixed an issue where the Roaming Client could go offline on certain ISP networks and require a manual restart to recover
This release brings IPv6 coverage and a stronger configuration foundation to the macOS Roaming Client, with meaningful stability improvements across network types and upgrade paths.
Load More
→