You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Several MacOS daemons with Apple domains point to Russia

After scanning my Mac's network traffic with Little Snitch, I found out that several MacOS daemons (mDNSResponder, trustd, nsurlsessiond) and even Apple Maps, once fired up all point to a location in Russia (in Little Snitch map). All domains are apple.com domains. Does Apple still maintain servers in Russia? Could this be a case where some malware has inserted itself in my MacOS? Is this legit? The Apple domains ocsp2.apple.com, doh.dns.apple.com, mesu.apple.com and Maps's cdn2.smoot.apple.com look like legit apple domains but... in Russia???


Liitle Snitch snapshot:

MacBook Air (M1, 2020)

Posted on May 24, 2023 10:22 AM

Reply
5 replies

Jan 29, 2024 8:28 AM in response to BobTheFisherman

BobTheFisherman wrote:

The OP does not know apparently that there are Russian Apple sites: Официальная служба поддержки Apple

That's just a localized version of a website. Anyone can setup localized versions of a website in any language. That has nothing to do with the location of the server.


But Apple is a large computer with a very large internet presence. They most certainly maintain servers all over the world. It is standard practice to host copies of websites on content delivery networks (CDN) that are physically closer to customers so they get faster response times. These days, even small companies do that because it is actually easier than trying to setup a more locally hosted, traditional website. Strange, but true. I speak from experience.


Your advice to uninstall Little Snitch was definitely correct. I have no idea why it was giving the OP the idea that it was contacting Apple servers in Russia. Normally that would only happen for users who were actually in, or near, Russia. Most likely it is just a bug in Little Snitch. That product has had some good ones over the years. But considering the OP was running a tool like Little Snitch to begin with, there is a pretty good chance they were using a VPN and actually were routing all of their network traffic through Russia. 😄

Several MacOS daemons with Apple domains point to Russia

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.