The icon in your Dock looks right. The name is right. The app works. None of that proves it’s the app the developer made. Recent Mac malware has replaced real apps with modified copies that look identical, and fake installers are promoted with search ads, social accounts and direct messages.

macOS gives you the tools to check, and it takes under a minute. Here is how to verify that an app, a disk image or an installer really comes from the developer you think it does.

What a signature tells you

Apps distributed outside the Mac App Store should be signed with a Developer ID certificate that names the developer, and notarized, which means Apple has scanned them for known malware. If anyone changes the app afterwards, the signature breaks. That is why tampered copies are usually re-signed with an ad-hoc signature, which names nobody.

A valid signature doesn’t prove an app is harmless; it proves who made it and that it hasn’t been altered since. Combined with downloading from the developer’s own site, that is most of the protection you need.

Check an installed app

Replace the app name with the one you want to check:

codesign -dvv "/Applications/AppName.app" 2>&1 | grep -E "Authority|TeamIdentifier|Signature"
codesign --verify --deep --strict --verbose=2 "/Applications/AppName.app"
spctl -a -vv "/Applications/AppName.app"
You seeMeaning
Authority=Developer ID Application: [name] and a TeamIdentifierSigned by that developer
valid on disk and satisfies its Designated RequirementNot modified since signing
accepted and source=Notarized Developer IDNotarized by Apple
source=Mac App StoreInstalled from the App Store
Signature=adhoc, TeamIdentifier=not set, rejected, or a sealed resource errorDon’t trust it. Delete and reinstall from the official source

Apple’s own apps show Apple as the authority. For a developer you rely on, write down their Team ID once; many developers publish it on their site or support pages. A copy signed by a different Team ID is not theirs.

Check a download before you open it

  • Where did it come from? macOS records the download address. Run mdls -name kMDItemWhereFroms ~/Downloads/file.dmg to see the URL it was downloaded from. A lookalike domain is an instant answer.
  • Does the checksum match? If the developer publishes a SHA-256 checksum, compare it: shasum -a 256 ~/Downloads/file.dmg. The long string must match exactly.
  • Installer packages can be checked with pkgutil --check-signature ~/Downloads/file.pkg, which shows who signed it and whether Apple notarized it.

Warning signs no command needs to confirm

  • Instructions to paste a command into Terminal to “install” or “fix” something. This is how many Mac stealers now get in, because it bypasses Gatekeeper entirely.
  • Instructions to right-click and Open, or to allow the app in Privacy & Security, because it “isn’t verified yet”. Legitimate developers notarize their apps.
  • A password prompt from an app you just opened, followed by a message saying the app is damaged and should be moved to the Trash. That sequence matches recent stealer behaviour.
  • A link from a search ad, a direct message or a brand-new account. Type the developer’s address yourself.

If something looks wrong

  1. Don’t open the app again. Quit it if it’s running.
  2. Delete it, empty the Trash, and download it again from the developer’s own site. Check the new copy.
  3. If you already entered your Mac password into it, treat the Mac as compromised: disconnect it, change important passwords from another device, and see our guide to recognising MacSync for signs of a backdoor.

The short version

An icon proves nothing. Use codesign to see who signed an app and whether it has been changed, and spctl to confirm Apple notarized it. Before opening downloads, check where they came from and compare published checksums. Anything ad-hoc signed, rejected, or delivered with “paste this into Terminal” instructions should be deleted.