mdls
SafeShow file metadata
mdls <file>
Dumps Spotlight metadata; kMDItemWhereFroms reveals where a file was downloaded from.
Examples
mdls -name kMDItemWhereFroms suspicious.dmgCheck the download origin
Syntax
mdls [-name attr] <file>
Before you run it
Read only.
The same reference, with no signal at all
Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.
Get it free on the App Store