What is transparencyd on Mac?
Last updated: 2026-07-31
transparencyd is an Apple-signed daemon that checks the public-key records used by iMessage Contact Key Verification. It verifies keys and cryptographic evidence, not message contents, and blocking it is not a supported way to save bandwidth.
What it is
transparencyd is an Apple-signed macOS system daemon. Its job is to verify Key Transparency information for identityservicesd and clients such as Messages. In practical terms, it helps iMessage Contact Key Verification check whether the public keys associated with an Apple Account appear consistently in Apple’s publicly auditable, verifiable, log-backed Key Transparency map.
That check matters because encrypted messaging depends on obtaining the correct public key for the person you intend to contact. transparencyd examines cryptographic evidence, keys, and related metadata so that Contact Key Verification can detect compromised key-directory data or inconsistent views of the directory. It does not inspect the contents of a conversation. Message text, photos, videos, and attachments are not the material it is verifying.
The executable is installed at /usr/libexec/transparencyd, uses the application identifier com.apple.transparencyd, and is started through Apple’s launchd configuration. Despite the similar wording, its purpose has nothing to do with App Tracking Transparency or advertising-related tracking.
Why it talks to the network
When iMessage Contact Key Verification is enabled, transparencyd communicates with Apple’s Identity Directory Service and Key Transparency service. Network work can occur when you enroll in the feature or opt out, sign in, validate the devices associated with your account, verify someone in a conversation, or respond to changes in keys and registrations.
The daemon also participates in periodic self-verification. As part of that work, it compares account state with an end-to-end encrypted CloudKit container. Apple Push Notification services and configuration services may trigger additional work when relevant state changes.
The inspected macOS launch configuration defined network-capable maintenance wakes at roughly four-hour, eight-hour, and twenty-four-hour intervals. Those intervals are not a promise that the daemon transfers data on every wake. A scheduled opportunity to run only shows that macOS may give it time to perform maintenance; it does not prove that a request was made or that bytes crossed the network. The schedule may also change between macOS releases.
Most peer-verification and self-verification behavior is associated with accounts that have enabled Contact Key Verification. Turning the feature off does not necessarily mean the process will never launch again: it may still perform eligibility, configuration, or account-state work.
How much traffic is normal
Apple has not published a normal byte range for transparencyd, so there is no verified number of kilobytes or megabytes that can be used as a universal baseline. Apple also has not published a stable, process-specific list of service hostnames. Any exact allowance presented without direct measurement would therefore be guesswork.
The documented workload consists mainly of intermittent public-key records, account and configuration metadata, and cryptographic proofs. That points to low, bursty control-plane traffic rather than the sustained transfers associated with message attachments, media synchronization, or backups. This is a description of the expected traffic pattern, not a verified byte limit.
Enrollment, adding or changing devices, registration or key changes, retries, and faults can all increase activity. If transparencyd shows sustained large transfers, investigate the actual measurements and timing instead of assuming that the volume is normal—or assuming from the process name alone that it is malicious.
Can you turn it off
The appropriate default is to keep transparencyd available. macOS does not provide a supported control for unloading or deleting this protected system daemon, and repeatedly killing or blocking it can interfere with security checks in Messages.
You can turn off the user-facing feature at:
System Settings > [your name] > Contact Key Verification > Verification in iMessage
That change disables Contact Key Verification across devices using the same Apple Account. You lose automatic Key Transparency validation, verification-error alerts, and support for manually verifying contacts. Ordinary iMessage end-to-end encryption remains enabled, but the additional protection designed to detect sophisticated attacks against iMessage key-directory services is removed.
Apple does not document the feature switch as a way to stop transparencyd itself. The daemon may continue to launch for eligibility, configuration, or account-state work even when verification is off. Deleting, blocking, or repeatedly terminating it is unsupported, and there is no reliable evidence that doing so produces meaningful bandwidth savings.
What people get wrong
- “It is part of App Tracking Transparency.” It is not.
transparencydverifies iMessage-related Key Transparency information; it does not track app use or advertising activity.
- “Network activity means it uploads my conversations.” The daemon works with public-key records, account metadata, configuration data, and cryptographic proofs. It does not read or upload iMessage text, photos, or attachments as part of this role.
- “An unfamiliar daemon must be third-party malware.”
transparencydis an Apple-signed component installed at/usr/libexec/transparencydand launched by Apple’s launchd configuration.
- “Key Transparency is a public directory of contacts and conversations.” Apple describes a privacy-preserving map indexed with a hash derived from a verifiable random function. It is not a public interface where people can browse phone numbers, contact lists, identities, or conversations.
- “Turning off Contact Key Verification turns off iMessage encryption.” Ordinary iMessage end-to-end encryption remains active. What disappears is the extra verification layer intended to detect compromised key-directory data, inconsistent directory views, and related sophisticated attacks.
- “Blocking the daemon is an easy network optimization.” Deleting, blocking, or repeatedly killing
transparencydcan disrupt Messages security checks. No reliable evidence shows that this produces meaningful bandwidth savings.
- “transparencyd and swtransparencyd are the same service.” They are distinct Apple daemons. Material about software transparency or Private Cloud Compute should not automatically be treated as documentation for this iMessage-focused process.
Seeing what it actually used
If the activity still looks unusual, the next step is to measure transparencyd by process and compare the bursts with sign-ins, device changes, verification actions, and scheduled maintenance periods. Bytetally’s per-process statistics can show the amount and timing without relying on an invented “normal” byte figure. Sustained transfers can then be investigated from evidence rather than inferred from a process name.
Related processes
Common questions
Is transparencyd malware?
No. transparencyd is an Apple-signed system component installed at /usr/libexec/transparencyd and launched through Apple's launchd configuration.
Does transparencyd read my iMessages?
No. It verifies public-key records, account metadata, and cryptographic proofs. It does not verify or upload message text, photos, or attachments.
Why is transparencyd using the network?
When Contact Key Verification is enabled, it contacts Apple's Identity Directory Service and Key Transparency service for enrollment, account and device validation, peer verification, key changes, and periodic self-checks.
Can I disable transparencyd?
macOS provides no supported switch for unloading or deleting the daemon. You can turn off Contact Key Verification, but Apple does not document that setting as preventing transparencyd from running.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account