Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

File Recovery for Mac Drives (APFS and HFS+ from a Disk Image)

Undelete files from an image of a drive formatted on a Mac, with names and folders.

Data Recovery No upload Works offline Free preview, no sign-upIncluded in your pass Ultimate tool Ultimate pass: ₹1,199 for 30 days

Free preview.

  • Free preview: every file found with its name, folder, size and condition, small watermarked thumbnails and the first half of each video (up to 10 seconds), marked.
  • Locked until you unlock it: download and saving to your device.
  • Unlock: Ultimate pass, ₹1,199 for 30 days, a one-time payment that never renews.

Ways to unlock shows how to get the full result.

See passes (opens in a new tab)

Printing this result is locked in the free preview.

Before you scan

  • Stop using the card or drive now. Deleted data is still there only until something new is written over it: every photo, file or update saved to it now can land on the space a deleted file used.
  • Save the image and the recovered files on a different drive. Writing to the card or drive you are recovering overwrites the very data you want back.
  • Is it an SSD inside a computer? Windows (7 and later) and Macs with Apple SSDs send a TRIM command as soon as a file is deleted, and the SSD then erases those blocks, so files deleted from an internal SSD are almost always gone. Over USB, TRIM support is newer and patchier, so an external SSD has a fair chance. R-Studio: data recovery from SSDs · DiskDigger: TRIM over USB
  • Was it a full format? A full format (for example Windows format /P, or a “zeroing” or secure erase) writes over every sector, so nothing is left. A quick format replaces only the file system’s tables and usually leaves the files’ data in place. Microsoft: the format command
  • Is it encrypted (BitLocker, FileVault, or a card that its device encrypted)? An encrypted volume is unreadable without its key, and this page does not decrypt volumes.
  • Is the card or drive failing (clicking, read errors, disconnecting)? Apple’s Disk Utility guide says not to make a disk image of a disk you believe to be failing. Use GNU ddrescue, which copies the good parts first and keeps a mapfile so it can resume, or a data recovery lab. Apple: create a disk image with Disk Utility
  • Nothing is uploaded. The image is read on your device, a few megabytes at a time, by code that runs in this page. No file data leaves it.
  • Use it only on cards and drives you own or may examine. Deleted files can be private: recover them only from your own cards and drives, or with their owner’s permission. This page never cracks passwords and never unlocks devices.

A web page cannot read a card, USB stick or disk directly, so you first make an image of it: a single file with every sector, made with a disk-imaging program. The Data Recovery Assistant shows how, step by step, and lists the routes worth trying before that (the Recycle Bin, cloud trash folders, backups).

What this page works on

  • External drives, USB sticks and memory cards formatted on a Mac (APFS, or Mac OS Extended, which is HFS+), as a disk image. The internal SSD of a Mac is not a good candidate: macOS erases the blocks of deleted files on it (TRIM), and on Macs with Apple silicon or a T2 chip its volumes are encrypted with keys kept in the Mac.
  • APFS never writes over a file’s old records in place, so older copies of them stay in the drive’s unused space until new data lands there. The page searches every block for them; on a large drive that takes a while.
  • HFS+ keeps older copies of its catalog in its journal, which is how recently deleted files are found on it.
  • Encrypted volumes (FileVault, or a drive encrypted when it was formatted) cannot be read without their password. Unlock the drive on the Mac and copy the files you can see; for deleted files, the volume has to be readable.

Choose the disk image

Next steps

About the File Recovery for Mac Drives (APFS and HFS+ from a Disk Image)

First make a disk image of the drive: one file that holds every block of it, kept on another drive with room for it (the Data Recovery Assistant shows the steps on a Mac, on Windows and on Linux). Then open the image here. The page reads the drive’s APFS container or HFS+ (Mac OS Extended) volume the way Apple documents their structures, and lists the files that were deleted, with their names, folders, sizes and dates, and how likely each one is to be whole.

APFS never changes its records in place: when a file is deleted, the parts of its file-system tree that listed it are written anew elsewhere, and the old copies stay in the drive’s unused space until new data lands there. The page searches every block of the container for them, and also reads the volume’s snapshots and older checkpoints. HFS+ keeps older copies of its catalog in its journal, which the page reads too. Then each photo, video, PDF, ZIP archive and Office file found is checked by its own content and marked Opens fully, Partly damaged or Can’t be opened; kinds of file the page cannot check, such as plain text, are marked Not checked. Nothing is uploaded: the image is read on your device, a few megabytes at a time.

How to use it

  1. Stop using the drive, and make an image of it on a different drive (the Data Recovery Assistant gives the exact steps; on a Mac, diskutil list, then diskutil unmountDisk and sudo dd in Terminal). An image saved by Disk Utility as a DMG is turned into a raw image first by the Disk Image Converter.
  2. Read the checklist above the scanner (SSD, full format, encryption, a failing drive): it says when there is nothing left to find.
  3. Choose the image file (.img, .dd, .bin, .raw, .cdr, or an image saved in parts, .001, .002 …, chosen together). The page shows the partitions it found, with each Mac volume’s name, kind and size.
  4. Press Find deleted files. For an APFS drive, keep Search every block of the APFS container ticked (it starts ticked for containers up to 256 GB): it reads the whole drive, which takes a while on a large one, and finds the most. Tick Also list files that were not deleted to copy files off a drive the Mac will not mount.
  5. Filter the list by kind or condition, look at the thumbnails, play the first seconds of the videos, and select the files you want.
  6. With an Ultimate pass, save them to a folder on another drive (Chrome or Edge on a computer) or as a ZIP; without one, the list, the checks and the watermarked previews are the free preview.

Examples

Photos deleted from an APFS external drive
Input
backup.img (an image of a 1 TB external drive formatted APFS), the folder Photos/2023 deleted and the Trash emptied
Result
Photos/2023/IMG_4012.HEIC · 2.8 MB · Opens fully · found in an old copy of the volume’s records in unused space

Deleting the folder wrote new versions of the tree without it; the old versions, still in unused space, keep each photo’s name, folder and blocks.

A document deleted from an HFS+ USB stick
Input
stick.img, an HFS+ (Mac OS Extended, Journaled) stick, a report deleted an hour earlier
Result
Documents/report.docx · Opens fully · found in an older copy of the catalog in the journal

HFS+ removes a deleted file’s record from its catalog, but the journal still held a copy of the catalog node from before the deletion.

Files deleted after a snapshot
Input
An APFS drive with a snapshot (made by Time Machine or a backup program), files deleted since
Result
Projects/plan.key · Opens fully · found in a snapshot of the volume

A snapshot keeps the whole tree of the moment it was taken, so files deleted after it come back with their names and folders, as long as their blocks have not been reused.

Common uses

  • Getting back photos, videos and documents deleted from an external drive or USB stick formatted on a Mac, also after the Trash was emptied.
  • Restoring files from an APFS drive with snapshots, under their names and folders.
  • Copying files off an APFS or HFS+ drive that the Mac will not mount, from its image (tick “Also list files that were not deleted”).
  • Checking which deleted files are still whole before deciding what to save.

Why you need an image first

A web page cannot read a drive block by block, and no browser setting changes that: the WebUSB standard does not let a page claim USB storage devices, and the File System Access API gives pages files and folders, never raw devices. A disk image (a file with every block of the drive, deleted areas included) is what recovery needs, and imaging is also the safe way to work: the drive is read once and never written to again.

On a Mac, find the drive with diskutil list (for example disk4), unmount it with diskutil unmountDisk /dev/disk4, and copy it with sudo dd if=/dev/rdisk4 of=/Volumes/Other/drive.img bs=4m in Terminal (press Ctrl+T to see the progress), saving the image on a different drive. Disk Utility’s “Image from” saves a DMG, which the Disk Image Converter turns into a raw image.

How deleted files are found on APFS and HFS+

APFS (Apple File System Reference) keeps each volume’s files in a tree of records: an inode for each file, with its name, its folder and its size, and file extents that say which blocks hold its data. Nodes of the tree are never changed in place: a change writes a new version of a node to an unused block and releases the old one, and every node carries a checksum. Deleting a file writes new nodes without its records, so the old nodes, with the records, stay in unused space until those blocks are reused. The page reads the tree as it is now, the trees of the volume’s snapshots and older checkpoints, and, with Search every block ticked, every block of the container for old nodes whose checksum is still right, and takes the newest version of each deleted file’s records.

HFS+ (Technical Note TN1150) keeps every file’s record in its catalog, a B-tree whose records hold the name, the folder, the size and the first eight extents of the data. Deleting a file removes its record and frees its blocks in the allocation bitmap. The journal writes whole copies of the catalog nodes each change touches, in a ring that is reused from its start once full, so it often still holds a copy from before the deletion; the page reads the whole ring, also the copies already written in place, and also catalog nodes no longer in use.

On both, the blocks a deleted file used are checked against what uses them now (files that exist, the file system’s own structures, files deleted after it), and macOS’s housekeeping files (Spotlight’s index, the event log) are counted apart.

What the conditions mean

  • Opens fully: the file’s own structure checks out from its first byte to its last (a JPEG to its end marker, every PNG chunk checksum, a video’s index and data, every file inside a DOCX or ZIP).
  • Partly damaged: it starts correctly, but part of it is missing or was written over; or some of its blocks now belong to other files.
  • Can’t be opened: its first block now belongs to another file, or no record says where its data was. Its name is still listed.
  • Not checked: a kind of file whose content the page cannot check (text files, for example). The note says whether another file uses its blocks now.

Measured on test images

NIST’s CFReDS deleted-file-recovery test images include two made with macOS, each with four HFS+ volumes (journaled or not, case-sensitive or not), with NIST’s record of the files deleted from them and the sectors they used (NIST tags each 512-byte block with its file and position). On osx-01 the page found 2 of the 4 deleted files, each whole: the two on journaled volumes; NIST’s own record says the other two have nothing left that says where they were. On osx-04, 48 files with names in Devanagari, Arabic, Hebrew, Cyrillic, Korean, Japanese, Chinese and German characters were deleted, 12 per volume: the page found the 24 on the journaled volumes, each whole under its name, and none on the others.

On test volumes made on a Mac, with files written, deleted and others written after: on APFS, with the search of every block, the 5 deleted files and the deleted folder, each file whole; on HFS+ (journaled), the 5 deleted files and the folder, 3 files whole and 2 marked as written over, which they were (macOS had put a new file and its own event log on their first blocks); and in an APFS container with two volumes, each volume’s deleted files, whole, under that volume. NIST’s osx-04 image and these test volumes are part of the page’s automated tests, with their checks, together with an encrypted APFS volume, which the page names as encrypted and does not read.

Mac, macOS, FileVault and Time Machine are trademarks of Apple Inc., registered in the U.S. and other countries and regions. MySmartCoPilot is not affiliated with Apple, and Apple has not sponsored or approved this page.

Limitations

  • Works on disk images only, not on drives directly (browsers do not allow it). Raw images (.img, .dd, .bin, .raw, .cdr), raw images saved in parts (.001, .002 …) and fixed-size VHD files open directly; DMG images (also those made by Disk Utility) are turned into raw images first by the Disk Image Converter, and sparse bundles with hdiutil convert on the Mac.
  • APFS and HFS+ only. Memory cards and USB sticks formatted with FAT or exFAT (also on a Mac) are undeleted by SD Card & USB Drive Recovery, Windows drives by NTFS Deleted File Recovery, Linux drives by File Recovery for Linux Drives; the deep scan finds photos, videos and documents on any drive by their content.
  • The internal SSD of a Mac is almost never recoverable: macOS sends TRIM to it, which erases the blocks of deleted files, and on Macs with Apple silicon or a T2 chip its volumes are encrypted with keys kept in the Mac, so an image of it does not read. External drives and USB sticks are the drives this page is for; external SSDs can be trimmed too.
  • Encrypted volumes (FileVault, or a drive encrypted when it was formatted) cannot be read without their password, and this page does not decrypt them. Unlock the drive on the Mac and copy the files you can see.
  • Files that macOS compressed (it does so for some of its own files and apps) are listed but cannot be saved here. Symbolic links and hard links are listed by name. A Fusion Drive’s container is spread over two drives: an image of one of them holds only part of it.
  • Data that has been written over cannot be recovered by any software. On HFS+, the journal holds the records of recently deleted files only: a busy volume reuses it within minutes or days. On APFS, the old copies of the records stay only until their blocks are reused.
  • The search of every block reads the whole container: on a large drive it takes about as long as copying the whole drive.
  • A drive with millions of files (a Time Machine backup disk, for example) needs plenty of spare memory, because the scan keeps the volume’s current records to tell the deleted files from the others: close other tabs first, or scan on a computer with more memory.
  • A web page cannot set a file’s date: files saved to a folder carry the day they were saved. The ZIP keeps the original dates, shown in this computer’s time zone.

Privacy

The image is read by your browser on your device, a few megabytes at a time, in background workers; no part of it or of the files in it is sent anywhere.

Frequently asked questions

What do I get without a pass?

Without a pass, File Recovery for Mac Drives (APFS and HFS+ from a Disk Image) shows every file found with its name, folder, size and condition, small watermarked thumbnails and the first half of each video (up to 10 seconds), marked. Until you unlock it, the result can’t be downloaded or saved to your device. An Ultimate pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.

Can I get back files deleted from my Mac’s internal disk?

Rarely from an image: macOS erases the blocks of deleted files on its internal SSD (TRIM), and on recent Macs the internal volumes are encrypted with keys that stay in the Mac. Look in Time Machine or another backup first. External drives and USB sticks are not trimmed in the same way and are readable, which is what this page is for.

I saved my drive as a DMG with Disk Utility. Can I open it here?

Turn it into a raw image first: the Disk Image Converter reads DMG images (also compressed ones) and saves the raw disk; on the Mac, hdiutil convert drive.dmg -format UDTO -o drive does the same and makes drive.cdr, which this page opens.

What does “Search every block of the APFS container” do?

APFS leaves the old copies of its records in unused space when it writes new ones. The search reads every block of the container and keeps the old records whose checksum is still right, which is where most deleted files are found. Without it, the page reads only the current tree, the snapshots and the few older checkpoints the container keeps, which is quick but finds only files deleted in the last moments before the drive stopped being used, or before a snapshot.

Should I look in Time Machine first?

Yes. If the drive was backed up with Time Machine, browse its backups (Time Machine in the menu bar or in System Settings) and restore the files from there: that needs no image and gets the files back whole. Use this page for what was never backed up.

Why are files from .Spotlight-V100 or .fseventsd counted apart?

They are macOS’s own housekeeping on the drive: the Spotlight index and the log of file-system events, which macOS writes and deletes all the time. They are found like any other deleted file but hidden from the list by default; tick “Show system files” to see them.

Where should I save the recovered files?

On a different drive from the one you are recovering: saving onto the same drive could overwrite the deleted data you are trying to get back.

Is anything uploaded?

No. The image never leaves your device: the page reads it in pieces with your browser and processes it in background workers. It works offline once the page has loaded.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.