What is Surge on Mac, and why is it using the network?
Last updated: 2026-08-05
Surge is a third-party proxy and network tool, not an Apple system process. Its traffic can include connections forwarded for other apps or devices, so a large total does not by itself indicate that Surge is uploading or downloading data on its own.
What it is
Surge is a third-party network tool from Surge Networks. It is not a process built into macOS and is not required for macOS itself to run. Its application identifier is com.nssurge.surge-mac, and the main executable may appear at /Applications/Surge.app/Contents/MacOS/Surge.
At its core, Surge can act as an HTTP or SOCKS5 proxy. It evaluates requests against rules chosen by the user, then either allows them to connect directly or forwards them through a configured upstream proxy. It also provides DNS features, request inspection, and optional HTTPS debugging.
Enhanced Mode gives Surge a broader role than an ordinary system proxy. It uses Apple Network Extension to create a virtual network interface and handle traffic from software that does not obey the macOS system proxy settings. This current design should not be confused with an obsolete kernel extension or an old virtual-interface driver.
You may also encounter names such as Surge Mac, Surge NE, Surge Network Extension, Surge VIF, or Enhanced Mode. The shortened identifier com.nssurge.sur has been observed in nettop, whose displayed process names may be truncated. Available evidence does not establish whether that shortened entry comes from the main app, the Network Extension, or a helper executable in every Surge release, so it should not be treated as a complete bundle identifier.
Why it talks to the network
When “Set as System Proxy” is enabled, apps that support the macOS proxy settings connect to Surge’s local proxy port. Surge examines the applicable rules and then connects either to the real destination server or to an upstream proxy configured by the user. The connection attributed to Surge may therefore represent a request initiated by another app.
Enhanced Mode also handles traffic captured through its virtual interface. That can include TCP, UDP, ICMP, and DNS traffic, including traffic from programs that ignore the system HTTP or SOCKS proxy configuration. Coverage is broader, but it can still depend on routing and exclusion rules.
Gateway Mode extends the possible source of the traffic again: Surge may be handling connections from other devices on the local network. In addition to forwarding traffic, Surge can make its own connections for remote configuration updates, DNS resolution, proxy availability or throughput tests, network requests made by scripts, and Ponte. The destinations and frequency depend on the user’s configuration, so there is no verified universal list of hosts that every installation contacts.
How much traffic is normal
There is no single reliable normal range for Surge. An idle configuration may produce almost no traffic apart from intermittent control activity. At the other end of the range, its total can be comparable to the combined throughput of every app, download, or downstream device whose connections it forwards.
Sustained high usage can be consistent with video traffic, large file transfers, or Gateway Mode. If another app starts a large download but Surge establishes the outward-facing connection on that app’s behalf, a monitor may attribute many of those bytes to Surge. The total alone cannot tell you that Surge itself chose to upload or download the content.
Not every byte belongs to another app, either. DNS requests, configuration updates, connectivity and throughput tests, scripts, connection handshakes, keepalives, and protocol overhead can all produce traffic of Surge’s own. The useful question is therefore not whether the number is “large” in isolation, but which features were active and which applications or devices were using Surge at that time.
Can you turn it off
You can turn Surge off when you do not need its proxy or network functions. On macOS 15 or later, if the extension is listed, the path is System Settings > General > Login Items & Extensions > Network Extensions > Surge, then turn it off. If Enhanced Mode appears as a VPN configuration, you can also disconnect it under System Settings > VPN > Surge. Surge’s exact display name in System Settings has not been verified for every release.
Turning it off stops the configured proxy routing, Enhanced Mode, DNS interception, rules, scripts, debugging features, and Gateway Mode. Services that are reachable only through the configured proxy will fail. Other connections may switch to a direct route and consequently bypass the privacy or access policy that Surge had been applying.
Force-quitting the process without clearing a system proxy setting that still points to Surge’s local port can leave some apps unable to connect. The visible process and the proxy configuration are separate parts of the path, so both states matter when disconnecting it.
What people get wrong
- “Surge is a built-in macOS process that cannot be disabled.” It is a user-installed third-party application and network extension, not an Apple system process.
- “Heavy Surge traffic proves it is secretly uploading data or downloading something by itself.” Surge may own outward-facing connections created for other apps or, under Gateway Mode, other devices. A large byte count is not enough to identify who initiated the underlying activity.
- “Setting Surge as the system proxy captures every app.” Some programs do not follow the system HTTP or SOCKS proxy settings. Enhanced Mode broadens capture through a virtual interface, but routing and exclusion rules can still affect what it handles.
- “Enhanced Mode is an obsolete kernel extension that should be removed.” The currently documented Enhanced Mode uses Apple Network Extension rather than the old driver-based approach.
- “Ending Surge is a side-effect-free network optimization.” It interrupts a proxy route that the user configured. If macOS or an app still points at Surge’s now-unavailable local proxy port, connectivity may fail.
- “Every byte under Surge must be duplicate traffic from another app.” Surge also generates DNS, update, test, script, handshake, keepalive, and protocol-overhead traffic of its own.
- “Already deduped in totals is guaranteed by macOS or Surge.” It is not. Deduplication is an accounting choice made by Bytetally, and other monitoring tools may count the same proxy path differently.
Seeing what it actually used
Open Bytetally’s per-process statistics and inspect Surge over the same time window in which the unexpected activity occurred. Compare that interval with active downloads, streaming, Enhanced Mode, scripts, tests, and any devices using Gateway Mode. Treat the result as process-level accounting, remembering that Surge’s connections can carry traffic initiated elsewhere.
Related processes
Common questions
Is Surge a macOS system process?
No. Surge is a third-party network application and network extension provided by Surge Networks.
Why is Surge using so much data?
Surge may be carrying traffic for other apps or, in Gateway Mode, other devices. Videos, large downloads, and combined downstream traffic can therefore appear under Surge.
Can I turn off Surge on my Mac?
Yes, if you do not need its proxy or network features. Turning it off stops its routing rules, Enhanced Mode, DNS handling, scripts, debugging, and Gateway Mode.
Does the macOS system proxy send every app through Surge?
No. Some programs do not follow the system HTTP or SOCKS proxy settings. Enhanced Mode expands coverage by handling traffic through a virtual network interface, subject to routing and exclusion rules.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account