Protecting a Mac from malware starts with Apple’s built-in Gatekeeper, notarization checks, and Privacy & Security “Allow applications from” settings — not a scary pop-up that demands you call a number. Apple’s Mac User Guide explains how to limit app sources and what to do if macOS says a download is malware: put it in the Trash and empty the Trash. This guide is Mac-only built-in hygiene, not Windows Microsoft Defender, not Android Play Protect, and not fake virus warning pop-ups. Buy-nothing is a valid outcome.

1. What Apple’s built-in layers do

  1. App Store / known developers: macOS can require apps from the Mac App Store only, or App Store plus identified developers (Gatekeeper + notarization on modern macOS).
  2. First-open approval: macOS asks before opening newly downloaded software so you are not tricked into running unexpected apps.
  3. Known malware block: If Apple detects known malware, macOS can refuse to open the app and move it to the Trash (see Apple’s safely-open-apps article).
  4. User choice matters: Overriding warnings or running unsigned / unnotarized software raises risk — Apple documents this clearly.

2. Set “Allow applications from” (household default)

  1. Choose Apple menu → System SettingsPrivacy & Security (scroll if needed).
  2. Under Security, open Allow applications from.
  3. Prefer App Store for the strictest household setting, or App Store and Known Developers if you install trusted developer apps.
  4. Keep automatic updates on so security data and macOS patches arrive.
  5. Treat odd “your Mac is infected — call this number” full-screen pages as scams — same pattern as fake Windows pop-ups.

3. If macOS says a download is malware

  1. Do not open the file again.
  2. Move it to the Trash and empty the Trash (Apple’s malware overview).
  3. Prefer re-downloading later only from a site or developer you verified yourself — same caution as checking downloads before opening on Windows.
  4. Change important passwords from a different trusted device if you already ran something suspicious.
  5. For a machine you no longer trust before sale or hand-me-down, follow wipe before selling.

4. Household habits (still buy-nothing)

  1. Do not install “Mac cleaner” or “virus remover” from pop-up ads.
  2. Be careful with scripts, web archives, and random disk images from email.
  3. Shared family Macs: keep the stricter Allow-applications setting and a standard user account for kids when practical.
  4. Phones in the same home still need their own tools (Play Protect / iOS updates) — Mac settings do not cover them.

FAQ

How do I protect a Mac from malware without buying antivirus?

Use Privacy & Security → Allow applications from (App Store or App Store + known developers), keep macOS updated, and trash items macOS flags as malware (Apple Support).

What should I do if macOS says a file is malware?

Put it in the Trash and empty the Trash; do not override the warning unless you fully trust the source.

Is Gatekeeper the same as Windows Defender?

Different platforms. Gatekeeper/notarization control what runs on Mac; Defender is Microsoft’s Windows protection. Both can be “buy nothing” baselines on their OS — see Is Microsoft Defender enough?.

Are full-screen “call Apple support” warnings real?

Usually not — treat them like fake virus pop-ups. Use real Apple Support URLs you type yourself.

Do I need a paid Mac antivirus?

Not required for this baseline. Buy-nothing with Apple’s built-ins is valid. Paid suites are optional for multi-device households.

Mac malware hygiene can stay on Apple’s built-in tools. If you want multi-device paid protection across PCs and phones, use only these on-site paid links: TotalAV (paid link), Norton (paid link), Bitdefender (paid link), McAfee (paid link), Avast (paid link).