What is backupd on Mac, and why is it using the network?

Last updated: 2026-08-08

backupd is Apple’s signed Time Machine backup daemon, not malware or an iCloud uploader. It transfers backup data over the network only when Time Machine is using a network destination. Large transfers can be normal, especially during the first backup or after large files have changed.

What it is

backupd is the Apple-provided daemon that creates Time Machine backups and manages backup history. It is part of macOS, carries the identifier com.apple.backupd, and runs from /System/Library/CoreServices/TimeMachine/backupd.

macOS starts backupd when it is needed. Users are not expected to launch it manually, and forcibly disabling it is not a supported way to manage Time Machine. If backupd appears in a process or network monitor, its presence alone does not mean that a backup is being uploaded continuously.

The destination matters. When Time Machine backs up to a directly connected disk, the backup data does not travel over the network. Network transfer begins only when the configured Time Machine destination is reached through the network.

Why it talks to the network

backupd needs a network connection when Time Machine is configured to use a network backup destination. A connection may be triggered by an automatic backup, by choosing “Back Up Now,” or by starting a backup with tmutil. During that work, backupd connects to and writes data to the configured destination.

Supported destination types can include a Time Machine-compatible SMB NAS, a Time Machine destination shared by another Mac, and an AirPort Time Capsule or older AFP destination that remains supported by the current system. The transfer is going to the destination selected by the user, not to an unspecified Apple cloud service.

Bonjour notifications can take part in discovering a network backup server. However, Apple’s public information does not establish that all discovery traffic is attributed directly to backupd; components such as mDNSResponder may handle some of it. Time Machine also reconnects to a network disk when restoring data, but it has not been verified that the resulting recovery traffic is recorded directly under backupd.

These attribution limits matter when reading a per-process network monitor. The bytes shown for backupd may not represent every packet involved in discovering or accessing a Time Machine destination, and unrelated discovery traffic should not automatically be assigned to it.

How much traffic is normal

There is no reliable universal traffic range for backupd. A normal amount cannot be reduced to a particular number of megabytes or gigabytes because it depends on the amount of data included in the backup and on what has changed since the previous backup.

The first backup to a network destination is commonly a long-running, high-volume transfer. Its size follows the actual amount of included data. Subsequent backups mainly process changes made after the previous backup, so they are usually smaller. They can still be large when photos, videos, virtual machines, or large databases have changed.

When no backup is running, traffic used to check for or discover a destination is normally much smaller than the backup payload itself. With a directly attached backup disk, the backup payload produces no network traffic.

A sudden large transfer is therefore not enough to identify a problem. Check whether Time Machine is performing its first backup, whether a backup is currently active, whether the destination is on the network, and whether large files have recently changed. Those facts provide more useful context than comparing the process against a fixed traffic threshold that has no reliable basis.

Can you turn it off

Forcibly terminating or disabling backupd is not recommended. launchd can start it again when macOS needs it, and killing it while a backup is active may interrupt that backup. Apple’s manual page also states that users should not run the daemon manually.

If the goal is to stop scheduled automatic backups, change the frequency here:

Apple menu  > System Settings > General > Time Machine > Options > Back Up Frequency > Manually

This setting stops timed automatic backups. It does not disable backupd; macOS can still launch the process when needed. You must start future backups yourself, and if you leave them undone for a long time, the available restore versions will become increasingly old.

Moderate traffic limiting may simply make a network backup take longer, but that is not guaranteed to be the only effect. A limit set too low can prevent backups from finishing within the expected time, leave restore points stale, and increase the risk of timeouts or failures. Apple does not provide or endorse a system setting that applies a process-specific bandwidth limit to backupd.

What people get wrong

Seeing what it actually used

The next step is to compare backupd traffic in Bytetally with the time a backup ran and whether Time Machine was using a local or network destination. Check both upload and download totals instead of inferring behavior from the process merely being present. Remember that the exact share handled by discovery or file-system helper components has not been verified.

Related processes

Common questions

Is backupd malware?

No. backupd is Apple’s signed Time Machine system process and writes backups to the destination configured by the user.

Why is backupd using so much data?

A first network backup can transfer a large amount of data. Later backups are usually smaller, but changed photos, videos, virtual machines, or large databases can still produce heavy traffic.

Can I stop or disable backupd?

You should not forcibly disable backupd. You can change Time Machine’s backup frequency to Manually, which stops scheduled automatic backups but does not disable the daemon itself.

Does backupd upload my Mac to iCloud?

No. Time Machine does not use iCloud as a backup disk. Network backup data goes to the Time Machine destination configured by the user.

See exactly how much it used

Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.

Download Free on the Mac App Store

macOS 14 Sonoma or later · 100% on-device · No account