The icon in your Dock looks right. The name is right. The app works. None of that proves it’s the app the developer made. Recent Mac malware has replaced real apps with modified copies that look identical, and fake installers are promoted with search ads, social accounts and direct messages.
macOS gives you the tools to check, and it takes under a minute. Here is how to verify that an app, a disk image or an installer really comes from the developer you think it does.
What a signature tells you
Apps distributed outside the Mac App Store should be signed with a Developer ID certificate that names the developer, and notarized, which means Apple has scanned them for known malware. If anyone changes the app afterwards, the signature breaks. That is why tampered copies are usually re-signed with an ad-hoc signature, which names nobody.
A valid signature doesn’t prove an app is harmless; it proves who made it and that it hasn’t been altered since. Combined with downloading from the developer’s own site, that is most of the protection you need.
Check an installed app
Replace the app name with the one you want to check:
codesign -dvv "/Applications/AppName.app" 2>&1 | grep -E "Authority|TeamIdentifier|Signature"
codesign --verify --deep --strict --verbose=2 "/Applications/AppName.app"
spctl -a -vv "/Applications/AppName.app"
| You see | Meaning |
|---|---|
Authority=Developer ID Application: [name] and a TeamIdentifier | Signed by that developer |
valid on disk and satisfies its Designated Requirement | Not modified since signing |
accepted and source=Notarized Developer ID | Notarized by Apple |
source=Mac App Store | Installed from the App Store |
Signature=adhoc, TeamIdentifier=not set, rejected, or a sealed resource error | Don’t trust it. Delete and reinstall from the official source |
Apple’s own apps show Apple as the authority. For a developer you rely on, write down their Team ID once; many developers publish it on their site or support pages. A copy signed by a different Team ID is not theirs.
Check a download before you open it
- Where did it come from? macOS records the download address. Run
mdls -name kMDItemWhereFroms ~/Downloads/file.dmgto see the URL it was downloaded from. A lookalike domain is an instant answer. - Does the checksum match? If the developer publishes a SHA-256 checksum, compare it:
shasum -a 256 ~/Downloads/file.dmg. The long string must match exactly. - Installer packages can be checked with
pkgutil --check-signature ~/Downloads/file.pkg, which shows who signed it and whether Apple notarized it.
Warning signs no command needs to confirm
- Instructions to paste a command into Terminal to “install” or “fix” something. This is how many Mac stealers now get in, because it bypasses Gatekeeper entirely.
- Instructions to right-click and Open, or to allow the app in Privacy & Security, because it “isn’t verified yet”. Legitimate developers notarize their apps.
- A password prompt from an app you just opened, followed by a message saying the app is damaged and should be moved to the Trash. That sequence matches recent stealer behaviour.
- A link from a search ad, a direct message or a brand-new account. Type the developer’s address yourself.
If something looks wrong
- Don’t open the app again. Quit it if it’s running.
- Delete it, empty the Trash, and download it again from the developer’s own site. Check the new copy.
- If you already entered your Mac password into it, treat the Mac as compromised: disconnect it, change important passwords from another device, and see our guide to recognising MacSync for signs of a backdoor.
The short version
An icon proves nothing. Use codesign to see who signed an app and whether it has been changed, and spctl to confirm Apple notarized it. Before opening downloads, check where they came from and compare published checksums. Anything ad-hoc signed, rejected, or delivered with “paste this into Terminal” instructions should be deleted.