Skip to content

Glossary

Quarantine Attribute (com.apple.quarantine)

com.apple.quarantine is the extended attribute macOS adds to downloaded files, recording flags, a timestamp, the downloading app and an event UUID.

com.apple.quarantine is an extended attribute that quarantine-aware applications, such as browsers and mail clients, attach to files they download. It tells Gatekeeper to check the file before it is first opened.

The value is a semicolon-separated string: flags, a hexadecimal Unix timestamp, the name of the downloading agent, and a UUID. That UUID can link to a record in the per-user QuarantineEventsV2 database (~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2), which may also store the download and origin URLs.

View it with xattr -p com.apple.quarantine <file> or ls -l@. Files fetched with tools like curl, or copied from some media, are usually not quarantined. See Quarantine events and Gatekeeper.