Skip to main content
Protect My Mac — FreeNo credit card required

syspolicyd (System Policy Daemon (Gatekeeper)) is a safe macOS security process. syspolicyd implements macOS Gatekeeper — the security feature that verifies applications are from identified developers or the Mac App Store before allowing them to run. It checks code signatures, notarization status, and quarantine attributes to prevent unsigned or tampered software from executing. syspolicyd checking apps before first launch is normal security behavior. Be concerned if Gatekeeper is being silently bypassed or if you find apps running that were never approved through the Gatekeeper flow — this could indicate malware that circumvented macOS's code signing requirements.

Security Process

What is syspolicyd on Mac?

System Policy Daemon (Gatekeeper)

Safe

syspolicyd implements macOS Gatekeeper — the security feature that verifies applications are from identified developers or the Mac App Store before allowing them to run. It checks code signatures, notarization status, and quarantine attributes to prevent unsigned or tampered software from executing.

Common Issues

Apps blocked from opening with 'unidentified developer' or 'damaged' errors

Slow first launch of new applications due to notarization check

High CPU during initial verification of large applications

Gatekeeper blocking legitimate apps downloaded from the internet

How to Fix

1

Allow a blocked application

If Gatekeeper blocks an app you trust, go to System Settings > Privacy & Security. After the block, you'll see an 'Open Anyway' button for the specific app. Alternatively, right-click the app in Finder and select 'Open' to bypass the first-launch check.

2

Remove quarantine flag

Apps downloaded from the internet get a quarantine flag. If an app is incorrectly flagged, remove it with 'xattr -d com.apple.quarantine /path/to/App.app' in Terminal. Only do this for apps you fully trust from known sources.

3

Check notarization status

Run 'spctl -a -vvv /path/to/App.app' in Terminal to see the detailed Gatekeeper assessment, including whether the app is notarized, signed by an identified developer, or unsigned. This helps you make an informed decision about whether to allow it.

4

Re-download the application

If an app shows as 'damaged,' the download may have been corrupted. Delete the app and download it fresh from the developer's website. Corrupted downloads fail code signature verification and Gatekeeper correctly blocks them.

When to Worry

syspolicyd checking apps before first launch is normal security behavior. Be concerned if Gatekeeper is being silently bypassed or if you find apps running that were never approved through the Gatekeeper flow — this could indicate malware that circumvented macOS's code signing requirements.

How CoreLock Helps

CoreLock performs deep code signature verification on all installed applications, going beyond Gatekeeper's first-launch check. It identifies apps with revoked certificates, expired signatures, or modified binaries that passed Gatekeeper initially but have since been tampered with.

Download CoreLock Free

Frequently Asked Questions

What is syspolicyd on Mac?

syspolicyd is the daemon behind macOS Gatekeeper. Gatekeeper is the security feature that checks every new application before it runs to verify it's from an identified developer (code-signed) and hasn't been tampered with. syspolicyd also checks notarization status — Apple's verification that the app was scanned and approved.

Why is my Mac blocking an app from opening?

macOS blocks apps that aren't code-signed by an identified developer or aren't notarized by Apple. This protects you from malware distributed as fake applications. If you trust the app and its source, you can allow it through System Settings > Privacy & Security > Open Anyway, or by right-clicking and selecting Open.

Should I disable Gatekeeper?

No. Gatekeeper is one of macOS's most important security features. Disabling it allows any software to run without verification, including malware. If you occasionally need to run unsigned software, use the per-app 'Open Anyway' option rather than disabling Gatekeeper system-wide.

Monitor Mac Processes with CoreLock

Download CoreLock to identify suspicious processes, detect threats, and keep your Mac running smoothly.

Download CoreLock Free

Available for macOS and Windows