Third-Party App Stores on iPhone and VPN Apps: What to Check First
Third-party app stores on iPhone are new in the EU under the Digital Markets Act. Here's how to tell a real VPN app from an impostor before you install.
Answer First
Definition: Third-party app stores on iPhone are alternative app marketplaces that can install apps outside the App Store. They exist because of the EU’s Digital Markets Act (DMA): starting with iOS 17.4 in March 2024, Apple was required to allow alternative distribution to users in the 27 EU countries. A marketplace is itself an app — you install it from the marketplace developer’s website, approve the source on your iPhone, and then install apps through it. Apps distributed this way pass Apple’s notarization, a baseline security review, but not the full App Store review.
Why: For most of the iPhone’s history, “where did this app come from?” had one answer: the App Store. The DMA changed that in the EU, and the question is newly relevant for VPN apps in particular. A VPN app installs a system VPN configuration and carries a large share of your traffic, so it’s exactly the kind of app an impostor would copy: similar name, similar icon, listed in a marketplace you’ve never used. The risk this guide addresses is installing a lookalike app through an unfamiliar store — not the network itself.
Example: You’re in an EU country, and a marketplace you heard about once shows a VPN app with the name and icon of a product you trust. The listing looks official: same colors, same tagline. You install it and grant the VPN permission. The app is an impostor — the developer’s name is a few letters off, and the listing’s developer field doesn’t match the vendor’s website. That’s the failure mode to check for before you tap Install.
Key Facts
- The DMA is an EU regulation, and the European Commission designated iOS, Safari, and the App Store as “core platform services” under it, making Apple a gatekeeper with obligations — including allowing alternative app distribution. Apple’s response, alternative app marketplaces, arrived with iOS 17.4 in the 27 EU countries beginning in March 2024, and direct web distribution of apps followed with iOS 17.5.
- Geography matters: outside the EU, the App Store remains the only source for iPhone apps. Alternative marketplaces and web distribution are EU-only features, so “which store?” is a question that exists only there (and for EU-linked Apple IDs).
- Every app distributed outside the App Store must still pass Apple’s notarization: automated checks plus human review aimed at known malware, basic integrity, and egregious fraud. Notarization is a baseline, not a recommendation or an endorsement.
- Apple itself states that the new distribution options “open new avenues for malware, fraud and scams” and that its safeguards reduce — but do not eliminate — the risk.
- Marketplace operators, not Apple, carry responsibility for content rules, anti-fraud measures, and refunds on their storefronts. Apple says it has less ability to help users with problems from apps installed outside the App Store, and features like Ask to Buy and Family Purchase Sharing do not work with those apps.
- VPN apps are a special case because they ask for a VPN configuration on your device. The App Store’s own history — Facebook’s Onavo VPN app was removed over data-collection practices — is a reminder that the store a VPN comes from is part of how you evaluate it.
Expert Explanation
What the DMA actually changed
Before the DMA, the App Store was the only sanctioned way to install apps on an iPhone, and its review process was the only gate. The DMA forced a structural change: it requires designated gatekeepers to allow third parties to interoperate with core platform services, and Apple implemented that for iOS by letting authorized marketplace developers distribute apps in the EU. The practical result for users: there is now more than one place an iPhone app can come from, and the storefronts are not all held to the same standard.
Apple’s implementation has three user-facing pieces. First, notarization: every iOS app, regardless of distribution channel, is checked by a combination of automated scans and human review to catch known malware, apps that misrepresent what they do, and egregious fraud. Second, installation transparency: before you install an app from a marketplace or a developer’s website, iOS shows a system sheet with the app name, developer name, description, screenshots, and age rating, and you must approve the source in Settings. Third, marketplace authorization: operators must meet Apple’s requirements and commit to ongoing obligations around content moderation, anti-fraud, and payments.
What notarization does and doesn’t do
The important nuance is scope. Apple describes notarization as a baseline that applies to all apps; what differs is everything around it. App Store apps also go through the standard App Review process, including enforcement of content and commerce policies, and Apple backs them with refunds, purchase history, and support. Apps from alternative marketplaces get the baseline, but the marketplace operator — not Apple — is responsible for what’s in the catalog, how fraud is handled, and how refunds work.
| In practice | App Store | Alternative marketplace (EU) |
|---|---|---|
| Malware and integrity baseline | Yes | Yes — via notarization |
| Human review | Full App Review | Notarization (security/privacy basics) |
| Content, commerce, and anti-fraud enforcement | Apple enforces App Store guidelines | Marketplace operator is responsible |
| Refunds, purchase history, subscription help | Apple | The marketplace or developer; Apple can’t assist |
| Family Sharing and Ask to Buy | Supported | Not compatible with these apps |
That table is why the “which store?” question matters for VPN apps specifically. A VPN app is not a passive utility: it installs a VPN configuration, and iOS routes your traffic through it while it’s active. If the app is genuine, that’s the vendor you intended to trust. If it’s an impostor, you’ve just granted the impostor exactly the permission a real VPN needs — and no baseline malware scan changes who you handed the traffic to. This is the same category of risk as the Onavo case: the App Store removed that VPN app because of what it did with the data it was allowed to collect, and the lesson is that the distribution channel is part of the trust chain.
Decision Framework
The pre-install checklist
Work through these before installing any VPN app from outside the App Store. If any step fails, stop.
- Start at the official source. Open the VPN vendor’s website — the domain you can verify — and find its official download or marketplace links. Don’t begin inside an unfamiliar store and don’t trust search results inside it.
- Match the developer name exactly. Compare the listing’s developer field, character by character, with the name on the vendor’s site. Impostors use near-matches: one letter swapped, a missing space, “Technologies” instead of “Tech.”
- Compare the name and icon. Lookalikes add words (“Pro,” “Lite,” “Secure”) or alter the icon slightly. The system installation sheet shows the app name and developer — read it, don’t skim it.
- Read what the app asks for before you grant it. A VPN app should ask for a VPN configuration. Be suspicious of extras such as local network access, which is a separate permission with its own privacy implications.
- Check the marketplace, not just the app. Who operates it? Do they publish content rules and anti-fraud commitments? Can any developer publish, or is there a review step? Apple requires operators to commit to these things, but the strength of enforcement varies by operator.
- Verify the app’s support and privacy links. A genuine VPN vendor has a working privacy policy and a support channel reachable from the listing. A dead or missing privacy policy in a store listing is a red flag.
- For VPN apps, cross-check the vendor’s other listings. If the vendor also publishes on the App Store, compare version numbers and descriptions. And after install, review Settings → VPN: the configuration should name the vendor you intended.
Practical limits
This checklist lowers the risk of installing an impostor; it cannot eliminate it. A careful lookalike can pass a baseline review, marketplace standards differ from Apple’s, and even a genuine app can misbehave later. Also keep the scope honest: a VPN protects the connection, and the FTC makes a related point about impostors — encryption does not protect you from whoever operates the service you connected to. A VPN is not a phishing filter, a malware scanner, or a guarantee against account compromise or all tracking. And if the question on your mind is public Wi-Fi safety rather than app origin, that is a separate topic with its own guidance.
Key Takeaways
- Third-party app stores on iPhone are an EU reality since iOS 17.4, created by the Digital Markets Act — and only in the EU. Elsewhere, the App Store is still the only source.
- Notarization means a baseline check for known malware and misrepresentation, not an App Store-level review, not an endorsement, and not a fraud guarantee.
- For VPN apps, source identity matters more than for most apps: you are granting a system VPN configuration, and an impostor would receive your traffic under a trusted name.
- Always start at the vendor’s official website, match the developer name exactly, read the system installation sheet, and scrutinize extra permissions like local network access.
- Marketplace operators — not Apple — own content rules, anti-fraud, and refunds on their storefronts, and Apple features like Ask to Buy don’t apply there.
- Even with a genuine VPN, the limits stand: it does not prevent phishing, malware, account compromise, or all tracking.
FAQ
Q: Are third-party app stores on iPhone legal and safe?
A: They are legal — they exist because the EU’s Digital Markets Act requires Apple to allow alternative distribution, and they became available with iOS 17.4 in the 27 EU countries. “Safe” is a separate question. Apps distributed that way still pass Apple’s notarization, a baseline review for known malware, basic integrity, and egregious fraud, and marketplace operators must commit to content rules and anti-fraud measures. But Apple itself says the new options “open new avenues for malware, fraud and scams,” and notarization is not the same as App Store review. Treat an unfamiliar marketplace as a higher-trust decision, not a normal download.
Q: I don’t live in the EU. Do I need to worry about this?
A: Outside the EU, alternative marketplaces are not available and the App Store remains the only source for iPhone apps, so the “which store?” question doesn’t apply to your daily installs. That can change if your Apple ID region is set to an EU country or you spend time in the EU — the option appears on the device. And lookalike apps are not EU-specific: the same checklist is worth using any time you install an app from outside the App Store or from a link you didn’t arrive at through the developer’s own site.
Q: Does Apple’s notarization mean an app is checked as thoroughly as an App Store app?
A: No. Notarization is a baseline review that applies to all apps regardless of distribution channel — automated checks plus human review, focused on known malware, whether the app functions as promised, and egregious fraud. It is not the full App Review process. For apps installed outside the App Store, Apple says it has less ability to address scams, fraud, and abuse, and that the marketplace operator is responsible for content rules, anti-fraud, and refunds.
Q: If a fake VPN app gets installed, won’t the VPN itself protect me?
A: No — and this is the key limit to understand. A VPN encrypts and routes your traffic between your device and the VPN server; it does not stop phishing, malware, account compromise, or all tracking. If the app you installed is an impostor, you have handed your traffic to the impostor, not to the VPN vendor. A VPN is a privacy tool for the connection, not a malware filter or a scam detector.
Sources
- Apple Newsroom — “Apple announces changes to iOS, Safari, and the App Store in the European Union” (January 2024): the DMA designation of iOS, Safari, and the App Store as core platform services; notarization; iOS 17.4 and the March 2024 rollout in the 27 EU countries; Apple’s warning that the new options open avenues for malware, fraud, and scams; and the Ask to Buy / Family Purchase Sharing limitations. https://www.apple.com/newsroom/2024/01/apple-announces-changes-to-ios-safari-and-the-app-store-in-the-european-union/
- Apple Developer — “Update on apps distributed in the European Union”: how users install apps from alternative marketplaces and developer websites (approval in Settings, system installation sheets, marketplace apps installed only from the marketplace developer’s website), the scope of notarization, and marketplace operators’ responsibility for content rules, anti-fraud, and refunds. https://developer.apple.com/support/dma-and-apps-in-the-eu/
- Apple Platform Security — “Virtual private network (VPN) security”: how VPNs work on iPhone, including client apps, VPN configurations, and supported protocols. https://support.apple.com/guide/security/vpn-security-sec802e8ab55/web
- FTC — “Are Public Wi-Fi Networks Safe? What You Need To Know”: the distinction between connection encryption and who operates the service you connect to, and how scammers impersonate trusted companies. https://consumer.ftc.gov/articles/are-public-wi-fi-networks-safe-what-you-need-know