Skip to main content

The network tools Apple stopped shipping, on every Apple device you own

Ping, traceroute, DNS, whois, MX and DNSBL, free on Mac, iPhone and iPad, with real ICMP, in the same app you SSH from.

By Lucas Russo, developer of SSHive · Updated

You open Spotlight, type "Network Utility", and nothing comes back. That is not a broken install: the app is gone. Network Utility shipped with every Mac up to macOS Catalina 10.15, was deprecated in Big Sur 11 in June 2020 (the bundle was still sitting in /System/Library/CoreServices/Applications/ but the tabs no longer did anything) and was removed from the system entirely in Ventura 13. On a current Mac (checked here on macOS 27.0, build 26A5388g) it is in neither /System/Library/CoreServices/Applications/ nor /System/Applications/Utilities/. Apple's own support pages still describe it in the present tense, because they were never updated past the macOS 10.15 URL path. So the everyday jobs it used to cover (is that host up, where does the path break, what does this name resolve to, who owns this domain) now mean opening Terminal. Or nothing at all, if what you are holding is an iPhone. SSHive puts those jobs back, on macOS, iPhone and iPad, inside the SSH client you already use to get into the box: ping, traceroute, DNS lookup, whois, MX lookup and DNSBL blacklist checking, plus a view of your local network interfaces. All of them are free. No ads, no subscription, no account, and no Pro gate on any of them, on any platform. Ping and traceroute are real ICMP everywhere: the Mac App Store build, iPhone and iPad alike. That is unusual enough to be worth a sentence: it is widely assumed that Apple's sandbox rules it out, and it does not. A datagram ICMP socket needs no root and is permitted; only a raw socket is refused. The full mechanism is on the traceroute page. One thing this is not: it is not a port scanner and it is not netstat. Network Utility's Port Scan and Netstat tabs have no equivalent here, and you should keep nmap and lsof -i for those. What it has that no Network Utility clone ships: the mail-side tools. And when the diagnosis points at one specific host, the SSH session is one tab away instead of one app away.

What SSHive does

Ping: is it up, and how bad is it

Ten probes on the Mac, twenty on iPhone and iPad, with per-probe RTT, TTL, a loss percentage and an average. Real ICMP echo requests on every Apple build (Mac App Store, iPhone and iPad) sent from an unprivileged datagram socket rather than by shelling out. A TCP-connect probe to a port you choose is offered as well, labelled as such, for hosts that filter ICMP.

Traceroute: where the path actually breaks

Thirty hops, three ICMP probes each, streamed as every router answers, with a Stop button. It runs identically in the Mac App Store build, on iPhone and on iPad, because SSHive builds the probes itself from a datagram ICMP socket instead of driving the setuid system binary. A hop that stays silent prints as asterisks; a system that refuses ICMP outright is reported as a refusal, never as a fabricated path.

DNS lookup: six record types at once

A, AAAA, MX, CNAME, NS and TXT queried in parallel against your system resolver, each one independently error-trapped so a domain with no MX still shows its A record. iPhone and iPad add SOA, and the TTL of every answer.

Whois straight over TCP port 43

A real WHOIS client, not a wrapper around somebody's web API. SSHive opens port 43 itself and follows registry referrals: on the Mac up to three hops (two referrals), starting from a built-in map of eighteen TLD servers; on iPhone and iPad, starting from IANA. The Mac parses registrar, dates, name servers, status, DNSSEC and abuse contact, and flags an expiry under 60 days.

MX and DNSBL, the pair Apple never shipped

MX Lookup sorts exchanges by priority. On the Mac it also resolves each one to IPv4, reverse-resolves that address and runs it through the blacklist engine, so mail routing and reputation land in one table. The standalone DNSBL check gives three verdicts on iPhone and iPad (listed, clean or no answer), so a silent zone is never counted as clean there; the Mac gives two, and reads a zone that fails to answer as clean. IPv4 only.

Free everywhere, and honest about the gaps

Every tool here is free on Mac, iPhone and iPad. None sits behind the licence check: no upgrade prompt, no ads, no account. What is missing is deliberate: no port scanner, no netstat, no finger. SSHive Pro is a separate one-time purchase (about $12.99, a Universal Purchase across Mac, iPhone and iPad, no subscription) that lifts the free-tier limits and adds RDP and VNC, never touching the diagnostics.

How to do it, step by step

  1. 1

    Open the tools tab on your Mac

    Click the network icon in the sidebar (its tooltip reads Network Tools), or the Network Tools pill on the Welcome screen. Either opens a dedicated tools tab alongside your sessions, so running a diagnostic never costs you a live SSH connection.

  2. 2

    Pick a card: everything is on one screen

    The panel is split into three sections: This machine (your network interfaces), Lookup and reputation (DNS Lookup, DNSBL Check, MX Lookup and Whois) and Reachability (Ping, Port check and Traceroute). Nothing is buried in a menu: every tool has its own input field and its own button, and you can move or hide the cards within a section.

  3. 3

    On iPhone, use the Tools tab

    Tap Tools in the bottom tab bar (the network icon). The list is split in three sections: Diagnostic (Ping, DNS Lookup, Traceroute and Whois), Email & IP (MX Lookup and Blacklist Check) and Information, which holds the network interfaces. On iPad the same list lives in the split-view sidebar, under Network tools.

  4. 4

    Type a target and run it

    Every tool takes a hostname or an IP: example.com for ping, traceroute, DNS, whois and MX; a dotted-quad IPv4 for the blacklist check, which also accepts a domain and resolves it first. Streaming runs (ping, traceroute) print as they go and can be stopped mid-flight with Stop or Cancel.

  5. 5

    Go from diagnosis to fix without leaving the app

    When the output points at one host, open a session tab against it and log in. Ping shows the loss, DNS confirms the record is fine, you SSH in and restart the service. Same window on the Mac, same app at 3am on a phone. That last step is the one no diagnostic-only app can do.

How to read what these tools are telling you

Work in this order: name, then reachability, then path, then reputation. Most incidents die at step one. Packet loss. Loss on a ping only means something if it is consistent and if the destination cares about ICMP. A router dropping 3% of echo requests while forwarding your TCP traffic at line rate is doing its job: ICMP is handled by the control plane and is the first thing rate-limited under load. What matters is loss that tracks your actual symptom, and jitter: probes at 40, 41, 39, 210, 42 ms are worse news than ten steady probes at 180 ms. Remember which engine you are on, too. ICMP is the default and measures the path itself. If you switched to the TCP engine because the host filters ICMP, total loss then means the probe was silently dropped: a firewall discarding traffic to the port you picked reads as 100% loss on a machine that is perfectly healthy. A host with nothing listening but no firewall replies with a RST, which SSHive correctly counts as reachable and marks 'port closed'. Three asterisks in a traceroute. A starred hop in the middle of an otherwise complete trace is almost never the fault. It means that router chose not to send an ICMP time-exceeded reply, or rate-limited it. A real break looks different: every hop from N onward is stars and the destination never answers. Same logic for latency: one hop at 180 ms followed by a hop at 30 ms is not a slow hop, it is a router deprioritising your probe. Only latency that rises and stays risen through the final hop is a path problem. WHOIS status codes. clientTransferProhibited is healthy: your registrar has locked the domain against unauthorised transfer. serverHold is the emergency: the registry has pulled the domain from the zone, so it will not resolve at all. redemptionPeriod and pendingDelete mean it already expired. MX priority is a preference, not a quality score: lowest number tried first, equal numbers round-robin. DNSBL hits are not equal. Read the return code (the Mac also shows the TXT reason; iPhone and iPad show the code alone). A Spamhaus PBL entry only says "this IP is a dynamic range that should not send mail directly", which is expected on a home line. UCEPROTECT level 2, queried on iPhone and iPad only, lists a whole allocation because a neighbour spammed, and most receivers ignore it; a lone level-2 hit beside otherwise clean rows is usually noise. Barracuda, or Spamhaus SBL/XBL, is what actually bounces your mail. And treat any result with care on a public resolver: several zones refuse those queries with a 127.255.255.x code. The Mac shows that code as Listed even though nothing is listed, and reads a DNS error as not listed; iPhone and iPad set both apart as no answer. Check the return code, and re-test from a network using its own recursive resolver.

Frequently asked questions

Did Apple really remove Network Utility from macOS, and when?+
Yes. It was fully functional through macOS Catalina 10.15. Big Sur 11, in June 2020, deprecated it: the bundle was still in /System/Library/CoreServices/Applications/, but the tabs no longer did anything. By Monterey 12 it was reported gone, with the networkQuality command line tool offered as a partial consolation. On macOS 27.0 (build 26A5388g) it is absent from both /System/Library/CoreServices/Applications/ and /System/Applications/Utilities/. Apple's support pages describing it are still online, but they are frozen at the macOS 10.15 URL path and were never updated.
Which of the six tools actually work on iPhone and iPad?+
All of them: ping and traceroute in real ICMP, DNS lookup, whois, MX lookup and the DNSBL blacklist check, plus the network-interfaces view. The iPhone and iPad builds run the same probe engine as the Mac, so a trace or a ping started on your phone is directly comparable with one started on your desktop, which is often exactly what you need when the question is whether the problem follows the device or the network.
Is SSHive's ping a real ICMP ping?+
Yes, on every Apple build: the Mac App Store version, iPhone and iPad. SSHive opens an unprivileged datagram ICMP socket and sends genuine Echo Requests, reporting the round-trip time and TTL of each reply. The TCP-connect probe is a separate, clearly labelled mode for hosts that filter ICMP; when you use it, remember that the measured RTT includes the TCP handshake, so it reads slightly high, and that a firewalled port shows as unreachable on a machine that answers ICMP perfectly well.
Does traceroute really work in the sandboxed Mac App Store version?+
Yes. A traceroute has to set the IP TTL on each outgoing probe and then read the ICMP time-exceeded replies routers send back, and the widespread belief is that this needs a raw socket the sandbox refuses. It does not: a datagram ICMP socket does both, needs no root, and is permitted. That was verified under sandbox-exec with SSHive's own entitlements before shipping. The one real requirement is that the app hold com.apple.security.network.server as well as network.client: with the client entitlement alone the replies come back EPERM, which looks exactly like a filtering network. SSHive declares both.
Are the network tools free, or do they need Pro?+
All six are free, on Mac, iPhone and iPad. None of them goes through the licence check, so there is no upgrade prompt, no ad overlay before a result, and no account to create. You can install the app, run a whois and never see a paywall. SSHive Pro is a separate one-time purchase (about $12.99, a Universal Purchase across Mac, iPhone and iPad, no subscription) that lifts the free-tier limits and adds RDP, VNC and the rest of the Pro features. It does not gate the diagnostics on any platform.
Does SSHive send my lookups through a third-party API?+
No. WHOIS queries open a TCP connection to port 43 on the registry or registrar server directly: the Mac chains up to three hops (two referrals) to reach the authoritative server, and iPhone and iPad start at IANA and follow the referrals from there. DNS lookups and blacklist checks use your device's own configured resolvers, with no relay in between. That matters for accuracy as much as privacy: many mobile whois apps proxy through a web service, which puts a cache and a third party between you and the registry.
Is this a complete Network Utility replacement?+
Not a literal one, and we would rather say so up front. Ping, Lookup, Traceroute, Whois and the Info tab's interface list all have equivalents here. Port Scan and Netstat do not. Use nmap and netstat -an or lsof -i in Terminal for those. Finger is a dead protocol nobody needs. In exchange you get two things Network Utility never had, and that no clone of it ships: MX lookup and DNSBL blacklist checking, on iPhone and iPad as well as the Mac.

What the sandbox actually forbids, and what it does not

Every platform difference in this section comes down to one question: what is a sandboxed app actually allowed to open. ICMP has no port numbers. To send an echo request and read the reply, a process needs a socket that speaks IP protocol 1 directly, and the usual assumption is that this means a raw socket: root-only, and flatly refused by the App Sandbox. That assumption is what kept ping and traceroute out of many App Store apps, and it is wrong. Darwin also offers a datagram ICMP socket, socket(AF_INET, SOCK_DGRAM, IPPROTO_ICMP), which any unprivileged process may open and which the sandbox permits. It is why /sbin/ping lost its setuid bit years ago, and it is what Apple's own SimplePing sample uses on iOS. So ping and traceroute have one implementation, not several. SSHive assembles the Echo Requests itself, computes the ICMP checksum, sets IP_TTL when a trace needs it, and reads what comes back: on macOS through a small native N-API addon, on iPhone and iPad through the equivalent Swift type. Replies are matched on identifier, sequence number, source address and a random eight-byte payload cookie, because a datagram ICMP socket also receives copies of replies meant for other processes on the machine. One requirement was found by measurement rather than documentation, and it is worth repeating because it fails silently. Under sandbox-exec with com.apple.security.network.client alone, socket() succeeds, sendto() succeeds, and recvfrom() returns EPERM: the probe leaves and nothing ever comes back, which is indistinguishable from a network that filters ICMP. com.apple.security.network.server is required as well. SSHive declares both, which is why the sandboxed App Store build measures real round trips instead of timing out in silence. A TCP-connect probe is still offered, but as a deliberate choice for hosts that filter ICMP rather than as a substitute: a connection to a port you name, timed from connect to socket-ready, labelled with a TCP badge. One subtlety there: a refused connection counts as a success, because an RST proves a live host answered. The port is simply closed, and the log says so. DNS, whois and DNSBL need no privilege at all, so no platform has to work around anything; what differs is scope. On the Mac, DNS queries A, AAAA, CNAME, MX, TXT and NS in parallel; iPhone and iPad add SOA and report each answer with its TTL. Every type is error-trapped on its own, so a domain with no MX still shows its A record. WHOIS is a plain TCP session on port 43: send the query, terminate with CRLF, read until the server closes. On the Mac it follows the referral chain up to three hops, two referrals deep, with a ten-second timeout per hop; iPhone and iPad start at IANA and follow the referrals from there. A DNSBL check is an A-record lookup on the reversed octets of an IPv4 address under each zone, fanned out in parallel, and the verdicts depend on the device. The Mac reports listed or clean, and reads a DNS error as clean. iPhone and iPad report three verdicts, listed, clean or no answer, so a zone that stays silent, or that returns a refusal code rather than a listing, is never counted as clean there.