everyday mac tools

Find a downloaded file on a Mac by the website it came from

· 6 min read

When a browser saves a file, macOS usually records the web address it came from in the file’s metadata, under the name Where from. You can read it in Get Info, search for it in Finder by adding Where from as a search rule, or query it from Terminal with mdfind. That lets you find a downloaded file by website when the site is the only thing you remember.

It works for most files saved from a browser. It does not work for files you made yourself or copied from a drive, and the last sections cover what to do then.

See where a single file came from

  1. Select the file in Finder.
  2. Choose File, Get Info (Command-I).
  3. Open the More Info section.

Where from lists one or two addresses: usually the address of the file itself and often the page you were on when you clicked the link. If there is no Where from line, the file never had one recorded, or it was removed.

This is also the quickest way to settle “where did this file come from” when something unfamiliar turns up in Downloads.

Search by website in Finder

Finder can search on Where from, but the option is hidden in the list of extra search attributes.

  1. Open a Finder window and press Command-F.
  2. Click This Mac so the search covers everything, or leave it on the current folder if you know it is in Downloads.
  3. Click the first pop-up menu in the search rule (it usually says Kind) and choose Other.
  4. Type “where” in the search field at the top of the list, select Where from, tick In Menu so it appears directly next time, and click OK.
  5. Set the rule to contains and type part of the site’s address, such as example.com.

The results update as you type. Click the plus button to add a second rule, such as Kind is PDF or Date Created within the last 30 days, when the site gave you many files. Click Save to keep the search as a Smart Folder that stays current.

Finder search relies on the Spotlight index. If Spotlight indexing is off, or the folder is excluded from it, this returns nothing even though Get Info shows the address. Spotlight cannot find a file you know exists covers that case.

The same search from Terminal

The attribute behind Where from is called kMDItemWhereFroms, and mdfind can search it:

mdfind 'kMDItemWhereFroms == "*example.com*"c'

The stars match anything on either side, and the c after the closing quote makes it ignore capitals. Add -onlyin ~/Downloads after mdfind to keep the search to one folder.

To print the recorded addresses for one file:

mdls -name kMDItemWhereFroms ~/Downloads/report.pdf

mdfind: searching a Mac from the Terminal explains the query syntax if you want to combine conditions.

When the file has no Where from

Not every route records the address. Files you created, files copied from a drive or another Mac, files downloaded with command-line tools and files unpacked from an archive often have none. Then the trail runs through other places.

The browser’s downloads list. In Safari, choose View, Show Downloads (Option-Command-L), find the entry and click the magnifying glass to reveal the file in Finder. Safari clears the list on a schedule set in Settings, General, Remove download list items, so older downloads may already be gone from it.

Browser history. Search your history for the site (History, Show All History in Safari). The page you visited usually tells you what the file was called, and then any name search will find it.

Date Added. In Downloads, switch to list view, press Command-J and tick Date Added. Sorting by it shows files in the order they arrived, which is often enough when you know roughly when you visited the site.

The quarantine log. macOS keeps a record of downloaded files it flags for its security checks, including the address each one came from, and that record outlives the file:

sqlite3 ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 "select LSQuarantineDataURLString from LSQuarantineEvent where LSQuarantineDataURLString like '%example.com%'"

If it prints addresses, you know the download happened and what it was called, even if the file has since been deleted. If Terminal reports that it is not permitted to read the file, give Terminal Full Disk Access in System Settings, Privacy & Security, or skip this step.

The privacy side of Where from

The same metadata that helps you find a file travels with it in some cases. A zip made with Finder’s Compress command can carry it along, and download addresses can include long tokens, account names or other details you would not choose to share. Before sending a downloaded file to someone, you can remove the record:

xattr -d com.apple.metadata:kMDItemWhereFroms ~/Downloads/report.pdf

That deletes only the Where from line. The file itself is untouched. For documents, the metadata worth worrying about is usually inside the file rather than attached to it; Remove metadata from a PDF before you share it covers that.

Where a name search fits

Searching by website gets you the file, or at least its name. Once you have a fragment of the name, a name search is the fastest way to every copy of it, wherever it ended up.

Everywhere is built for that part. It catalogues every file on the Mac once and answers as you type, including mail attachments inside the Mail store and files on an external drive that is currently unplugged. Be clear about the limit, though: it searches names and paths, not metadata such as Where from, so it cannot search by website itself. What it does well is the next step: type part of the name, press Command-Return to reveal the file in Finder, or Command-D to find every other copy, such as the one you downloaded twice. It is free for a day with nothing held back and runs on macOS 13 Ventura or later.

Questions

Can I add a Where from column to Finder’s list view? No. List view offers a fixed set of columns, and Where from is not among them. Use Get Info, the Finder search rule above, or mdls.

Why does the Finder search miss a file that Get Info shows a Where from for? The file is probably in a location Spotlight does not index, or the index has not caught up. Try the mdfind command with -onlyin and the folder, or see rebuild the Spotlight index on a Mac.

Does removing Where from stop macOS checking the file? No. The security check uses a separate quarantine flag. Removing Where from only removes the recorded address.