Guide
Do you need antivirus on a Mac?
Probably not the kind you are picturing. Here is what macOS already does, where the real gaps are, and what a tool can honestly add. We sell one, so read this with that in mind. We have tried to write the version we would want to read.
What macOS already does
Apple ships several layers, and they are good. Knowing their names is useful, because it tells you what you do not need to buy.
| Gatekeeper | Checks that an app was signed by a known developer and passed Apple's automated malware check before it will open. |
|---|---|
| XProtect | Apple's own malware scanner. It is built in, updates quietly, and removes known families. Your Mac has it right now. |
| Notarization | Developers submit apps to Apple for scanning before release. Unnotarized software needs a deliberate override. |
| Sandboxing and SIP | Limits what apps can touch, and stops even an administrator casually modifying system files. |
Between them, the old idea of a virus that spreads silently across Macs is close to extinct. If someone tells you that you need a resident scanner to survive the week, they are selling fear.
Where the real gaps are
Mac malware in practice is mostly not a virus. It is one of these.
- Things you installed on purpose. A cracked app, a fake Flash-style updater, a "cleaner" from a search ad. Gatekeeper asked, and the answer was yes.
- Adware and browser hijackers. Annoying rather than dangerous, and they reinstall themselves because they leave something behind that starts at login.
- Info stealers. The growth area. They want browser cookies, saved passwords and crypto wallets, and they only need to run once.
- Targeted spyware. Real, expensive, and aimed at specific people. If this is your threat model, Apple's own Lockdown Mode matters far more than any third party app.
The pattern in the first three is the same. Something got permission once, and then arranged to keep running.
What a tool can honestly add
Not a better virus database than Apple's. What it can do is show you the things macOS has no interest in showing you.
- Everything set to start itself at login, including entries from apps you removed.
- Who signed each of those, and whether that signature checks out.
- Things running from locations legitimate software does not use.
- Recent downloads that are unsigned or signed by nobody in particular.
- Configuration profiles, which can quietly change settings across the whole Mac.
What MacTidy is not. It is not a real time scanner. It does not sit between you and every file you open, and it does not install a kernel extension to do so. It checks when you ask it to.
It also cannot promise to find everything. It compares against a public list of known malware fingerprints and flags things by signature and location. Something brand new, signed with a stolen certificate, sitting in a normal place, can pass all of that. Any product claiming otherwise is overselling.
Why we do not install a kernel extension
Traditional antivirus gets its power by sitting deep in the system and watching everything. That is a large amount of trust to hand to any vendor, it costs performance, and the extension itself becomes something worth attacking. For the threats most Mac users actually meet, the trade is not worth it.
MacTidy runs as a normal app with the permissions you grant it, and asks before it does anything.
So what should I actually do?
- Turn on FileVault. It is the single highest value setting on the machine.
- Keep macOS updated. XProtect updates ride along with it.
- Read your login items once a year, and after every major upgrade.
- Do not install cracked software. This is how most people get hit.
- If you are a plausible target for a government or a commercial spyware operator, turn on Lockdown Mode and read what it costs first.
You can do all five by hand, for free, today. MacTidy exists because doing them by hand means visiting nine different settings panes and knowing what you are looking at.
MacTidy