Opening a password-protected ZIP on macOS
macOS will prompt you for a password on an encrypted ZIP and then fail on some of them anyway. The reason is that "encrypted ZIP" describes two different things, only one of which is worth trusting.
An encrypted ZIP arrives. You double-click, macOS asks for the password, you type it, and either it works or you get an unhelpful error that tells you nothing about why.
The confusion comes from the fact that ZIP encryption is not one thing.
Two encryptions wearing the same file extension
ZipCrypto — the original, from 1989. It is the reason "password-protected ZIP" has a bad reputation, and the reputation is deserved: it is breakable. There are well-known attacks that recover contents without the password, and if an attacker has even a small piece of a known file inside the archive, recovery is fast. Treat ZipCrypto as obfuscation, not protection.
AES-256 — added later, genuinely strong, and what any modern tool should produce. An AES-encrypted ZIP with a decent password is a reasonable way to send something sensitive.
Both produce a file ending in .zip. Nothing in Finder tells you which you have, and the password prompt looks identical.
This matters in both directions. If you are receiving, you cannot assume the contents were protected. If you are sending something confidential, you need to know your tool produced AES and not the 1989 version — several still default to ZipCrypto for compatibility.
Why macOS sometimes fails on a valid archive
The built-in Archive Utility handles standard ZIP well and has gaps around the edges:
- Some AES variants are not supported by the built-in tool even though the archive is perfectly valid.
- Archives created by Windows tools occasionally use extensions Archive Utility does not read.
- Filename encoding. A ZIP made on a Windows machine with Turkish, Cyrillic or CJK filenames may use a legacy code page rather than UTF-8. macOS renders the names as nonsense or refuses the entry entirely. The archive is fine; the name is being misread.
- Large archives over 4GB, or with more than 65,535 entries, need ZIP64 extensions. Support is inconsistent in older tools at both ends.
The pattern to recognise: if one tool fails and another opens the same file without complaint, the archive is usually fine and the first tool has a gap.
What to do when the password does not work
Before assuming you have the wrong password:
- Check for trailing whitespace. Copying a password from an email or a chat message frequently picks up a trailing space. Paste it into a text field where you can see it.
- Check the keyboard layout. A password typed on a Turkish layout and re-entered on a US layout produces different characters for several symbols.
- Try a different extractor. If the archive uses an encryption variant the built-in tool cannot read, the error may be about support rather than the password.
- Confirm the file arrived intact. A truncated download fails in ways that look like every other failure. Compare the file size against what the sender says it should be.
If none of that works, the password is wrong. There is no recovery path for a correctly AES-encrypted archive, and anything advertising one is either targeting ZipCrypto or selling you a brute-force tool that will not succeed against a real password.
Sending something sensitive properly
If you are on the other side of this:
- Use AES-256, and check that your tool actually produces it.
- Send the password through a different channel. A password in the same email as the archive protects against nothing.
- Use a long passphrase rather than a short complex one. Length beats symbols.
- Remember that ZIP encryption hides file contents, not always the file list. Depending on the tool, someone may be able to see the names of the files inside without the password. If the filenames themselves are sensitive, put everything in a folder with a neutral name first.
What Ziploom does
Ziploom extracts RAR, ZIP and 7Z archives with optional password support, and creates ZIP and 7Z. It runs natively on Apple silicon.
For encrypted archives specifically, it handles the password prompt as part of the normal flow rather than failing with an ambiguous error, and — as with any extraction — it runs its safety checks first: unsafe paths, symbolic links, suspicious compression ratios, oversized jobs and available disk space. An encrypted archive from an unknown sender is exactly the case where those checks earn their place.
You decide how existing destinations are handled before anything is written, follow progress while it works, and reveal the result in Finder.
Everything happens on your Mac. No accounts, no analytics, no telemetry, no network features — the archive and its password never go anywhere.