Independent resource. This site is not McAfee. It is not affiliated with, endorsed by, or operated by McAfee, LLC. McAfee®, McAfee+™, and LiveSafe® are trademarks of McAfee, LLC (6220 America Center Drive, San Jose, CA 95002). We publish troubleshooting documentation only. Type your 25-character product key nowhere except mcafee.com/activate on the genuine McAfee domain. No page on this site asks for a key, a password, or a payment method.
Written by John Lenon· Verified against McAfee published documentation · Last updated September 2026
Short version. mcafee.com/activate is the McAfee-operated redemption endpoint. You type a 25-character alphanumeric product key, McAfee validates it, McAfee binds the subscription to one email address, and McAfee releases the installer. Each key redeems exactly once. Redemption is not installation — two separate operations.
What follows, in order: where the activation code is printed, how to redeem it, verified system requirements, why a key gets rejected, the "Key already in use" error, blank activation pages, failed installs, the MCPR removal tool, adding more devices, and how counterfeit activation sites capture codes.
Most people land here because the key was rejected, the page threw a blank screen, or the software installed and still reports no subscription. Those are three different faults with three different fixes. This page separates them.
What mcafee.com/activate actually does
mcafee.com/activate converts a printed product key into an account entitlement. The page checks the key against McAfee's licensing database, attaches the entitlement to the email address you sign in with, and marks the key as consumed. The download link appears afterward as a consequence, not as the point.
Four things change server-side when redemption succeeds:
McAfee marks the 25-character key as consumed. The key never works again, on any account.
McAfee writes the entitlement to the email address you authenticated with. That address owns the subscription from then on.
McAfee starts the subscription clock. The term runs from the redemption date, not the purchase date.
McAfee exposes the matching installer inside My Account at home.mcafee.com and the dashboard at protection.mcafee.com.
Note the consequence of the second bullet. The email address you pick during redemption is permanent for practical purposes. Pick the address you will still control in three years. Support recovery, renewal notices, and device transfers all route through it.
Where your 25-digit McAfee activation code is printed
The product key sits in one of four places depending on how you bought the subscription: the back of a physical retail card, a fulfilment email, the retailer's digital order record, or a manufacturer pre-install voucher. The key uses 25 alphanumeric characters, grouped in five blocks of five.
Product key, activation code, or serial number — which is it?
All three names describe the same string. McAfee's retail packaging prints it as a 25-digit activation code, McAfee's redemption page calls it a product key, and older McAfee installers asked for a serial number. If somebody asks for your McAfee serial number, they mean the 25-character activation code.
There is no separate McAfee licence number, registration ID, or secondary release code. A subscription carries exactly one redeemable string, and it stops being useful the moment it is consumed.
Retail box or product card (Best Buy, Walmart, Staples) — Where the activation code sits: Printed on the reverse of the card, usually under a scratch panel · Common failure: Scratch panel damaged; characters scraped off
eCard bought online direct from McAfee — Where the activation code sits: Order confirmation email from McAfee · Common failure: Filtered into Promotions or Spam
Marketplace (Amazon, Flipkart, Newegg) — Where the activation code sits: Retailer's order page under digital codes or game & software library · Common failure: Buyer searches email instead of the order record
New PC bundle (Dell, HP, Lenovo, Acer) — Where the activation code sits: Voucher card in the box, or a pre-loaded trial that needs no key · Common failure: Pre-loaded trial needs sign-in, not redemption
ISP or carrier plan (Bell, Comcast, Verizon) — Where the activation code sits: Provider portal, not McAfee · Common failure: Key entered at mcafee.com instead of the provider portal
Read the key carefully before you type it. McAfee keys mix digits and uppercase letters, and four character pairs cause most rejections: 0 and O, 1 and I, 5 and S, 8 and B. Hyphens separate the blocks; the redemption form usually inserts them for you.
Best Buy, Geek Squad, and codes that are not where you expect
Best Buy delivers digital McAfee codes to the account order history and digital library, not reliably by email. Geek Squad protection plans are a separate Best Buy service and never produce a McAfee activation code. Check the order record before you conclude the code is missing.
This is the single biggest drop-off point for retailer purchases. Buyers search their inbox, find nothing, and assume the order failed. Sign in to the retailer account, open the order, and look for the digital content or software key panel attached to the line item.
Physical cards ship in the post and carry the code under the scratch panel. Digital versions never ship anything; the code exists only inside the retailer account. A Geek Squad membership, an installation service, or a protection plan bought alongside the software is a separate line item with no McAfee key attached to it at all.
Retail codes also stack. Redeem a second retail code against the same McAfee account and McAfee offers to extend the existing subscription rather than open a parallel one. Read the review screen before you submit, because the extension only applies when the account matches.
How to activate McAfee with a product key
Open mcafee.com/activate in a standard browser, type the 25-character key, sign in to a McAfee account or create one, confirm the region, and submit. McAfee validates the key, writes the entitlement to your account, and then offers the installer. The whole sequence takes under two minutes on a working connection.
Type mcafee.com/activate directly into the address bar. Do not arrive via a search advert or a forwarded link.
Verify the padlock and the domain. The address bar must read mcafee.com with no prefix or suffix attached to it — not mcafee-activate.net, not activate-mcafee.com.
Enter all 25 characters of the product key in the redemption field.
Select your country and language when prompted. The region you choose determines which regional licensing server handles the request.
Sign in with an existing McAfee account, or create one using an email address you will keep long-term.
Confirm the subscription name and term shown on the review screen before you submit. This is the last point at which a wrong key can be abandoned safely.
Submit the form. McAfee consumes the key and writes the entitlement.
Record the account email in a password manager. You now need it for every future install, renewal, and support ticket.
Redemption ends there. The software is still not installed on anything. That happens next, and it happens per device.
McAfee documents this sequence in support article 000001641, "Activate McAfee with a product key or activation code." Subscription management sits in article 000001676. Both live at mcafee.com/support/s/article/ followed by the number.
How to download McAfee after activation
Download the installer from My Account on each device you want protected. McAfee serves a small web installer that authenticates against your account, pulls the correct build for the detected operating system, and installs the entitled product. You do not re-enter the product key during installation.
Install McAfee on Windows 11 and Windows 10
Sign in to My Account on the Windows machine itself, using the same email you redeemed with.
Uninstall any other security suite first. Two real-time scanners fight over file-system filter drivers and one of them loses.
Click Download on the subscription tile. The browser saves a small McAfee setup executable, not the full product.
Run the downloaded file and approve the User Account Control prompt.
Wait through the device check phase. The installer profiles the operating system before it downloads the main payload.
Restart Windows when the installer asks. Filter drivers do not load until the reboot completes.
Open the McAfee app and confirm the subscription name appears in the account area.
Install McAfee on macOS 13 and newer
Sign in to My Account in Safari on the Mac.
Download the macOS installer package from the subscription tile.
Open the downloaded disk image and launch the installer inside it.
Approve the system extension prompt when macOS blocks it. Open System Settings, then Privacy & Security, then click Allow next to the McAfee entry.
Grant Full Disk Access to the McAfee scanner in the same Privacy & Security pane. Without it, the scanner cannot read protected directories and reports partial coverage.
Restart the Mac and reopen the app to confirm the subscription registered.
Install McAfee on Android and iOS
Install the McAfee Security app from Google Play or the Apple App Store. Ignore third-party APK mirrors entirely.
Open the app and choose the sign-in option rather than the free trial option.
Authenticate with the same email address that owns the redeemed subscription.
Grant the permissions the app requests for scanning and web protection. Android denies malware scanning without storage access.
Check the device count in My Account afterward to confirm the phone consumed a licence seat.
McAfee system requirements you should verify before you redeem
McAfee+, McAfee Total Protection, and McAfee LiveSafe share one requirement set: Windows 11 or Windows 10 RS5 and newer on x64, Windows 11 and newer on ARM64, macOS 13.x and above, Android 10 or higher, iOS 16 or later, ChromeOS 102.0.5005 and higher. Hardware minimum is 2 GB RAM.
These figures come from McAfee's published requirements, not from a vendor marketing page. Most competing guides still quote Windows 7 and macOS 10.12, which have been outside the supported range for years. Check the machine before you consume a one-shot key on it.
Windows (x64) — Minimum McAfee supports: Windows 11, or Windows 10 RS5 and newer
Windows (ARM64) — Minimum McAfee supports: Windows 11 and newer
macOS — Minimum McAfee supports: macOS 13.x and above, on product build 4.23 or higher
Android — Minimum McAfee supports: Android 10 or higher
iOS / iPadOS — Minimum McAfee supports: iOS 16 or later
ChromeOS — Minimum McAfee supports: ChromeOS 102.0.5005 and higher
RAM — Minimum McAfee supports: 2 GB
Free disk space — Minimum McAfee supports: 1.3 GB
Processor — Minimum McAfee supports: 1 GHz
Browsers — Minimum McAfee supports: Chrome, Firefox, Chromium-based Microsoft Edge, Safari on Mac and iOS
What "Windows 10 RS5" means on a spec sheet
RS5 is the internal Microsoft codename for Redstone 5, shipped publicly as Windows 10 version 1809, build 17763, in October 2018. McAfee writes RS5 rather than 1809 in its requirements. Any Windows 10 build older than 17763 falls outside the supported range.
Check the build before you redeem. Press Windows+R, type winver, and press Enter. The dialog reports the version and OS build. A number below 17763 means the machine needs a feature update before McAfee will install cleanly.
The Safe Connect and PC Optimizer exceptions
Two McAfee products carry looser requirements than the main suites. McAfee Safe Connect still supports Windows 8.1, 8, and 7, though it excludes Windows Enterprise. McAfee PC Optimizer supports Windows 11, 10, and 8.1, needs only 512 MB of RAM, and occupies roughly 110 MB of disk.
This matters for one reason: a key that redeems successfully does not guarantee every bundled component runs. A McAfee+ entitlement on a machine below spec will redeem fine and then fail to install the antivirus engine. Redemption is a licensing operation; the operating system check happens later, during install.
Why mcafee.com/activate rejects your product key
Rejections fall into three buckets: the key was already consumed, the key was mistyped, or the key belongs to a different channel entirely. The error text tells you which. Read it before you retype anything, because retyping a consumed key fifty times changes nothing.
"Invalid product key" or the field refuses to accept the code
This is a character-level problem in almost every case. McAfee keys use 25 alphanumeric characters, and the confusable pairs 0/O, 1/I, 5/S, and 8/B account for most rejections. Auto-fill, trailing spaces pasted from email, and smart-quote substitution cause the rest.
Type the key manually rather than pasting it. Email clients append invisible whitespace.
Substitute the confusable characters one at a time if manual entry still fails.
Disable browser auto-fill for the page. Password managers sometimes inject a stored value over the field.
Confirm the key is 25 characters, not 20 or 26. A 16-character code is not a McAfee key.
Check the card is McAfee-branded. Retailers shelve several vendors' cards together, and a Norton or Kaspersky key will never validate at mcafee.com.
The key redeems but no subscription appears
You are signed in to the wrong account. Redemption writes the entitlement to whichever email authenticated at redemption time, and browsers frequently reuse a stale session from an earlier McAfee sign-in. The subscription exists; the account you are looking at does not own it.
Sign out of McAfee completely and close every McAfee tab.
Search your mail for the McAfee redemption confirmation. The recipient address on that message is the account that owns the subscription.
Sign in with that address specifically.
Reset the password if you never set one. Accounts get provisioned without a chosen password more often than people expect, for reasons covered below.
Region and culture mismatch on the redemption request
McAfee provisions product keys per region and routes redemption through a culture parameter in the activation URL. A key sold in one market can be rejected, or attach a wrong-region entitlement, when redeemed against another market's session. Redeem on the regional McAfee site that matches the purchase.
Look at the address bar during redemption. McAfee appends a culture value such as ?culture=en-us to the activation URL, and that value decides which regional licensing server answers. Land on the wrong one and a perfectly valid key returns a generic rejection with no useful detail.
Identify the market the key was sold into. Retail cards print regional SKU markings; digital codes carry the retailer's storefront country.
Open the matching regional McAfee site before you redeem, so the culture value is set correctly from the start.
Disconnect any VPN. An exit node in a third country overrides your intended region and produces exactly this failure.
Check the subscription name on the review screen. A wrong-region entitlement often redeems successfully and then refuses to install, which is worse than an outright rejection.
Stop after the third rejection. The key is either consumed, mistyped, or wrong-region, and none of those conditions changes on attempt four.
"Key already in use": what consumed your activation code
This is the error that sends most people looking for help, and the whole first page of results tells them to clear their cache. That advice addresses a page that will not load. It does nothing for a code the licensing server already recorded as spent.
What the error means at the licensing layer
Redemption is a one-way state change. McAfee validates the code, writes an entitlement against one account identifier, and flags the code as spent. The flag is the authoritative record. Nothing on your end — retyping, a different browser, a fresh account — alters a flag held server-side.
This is worth stating plainly because the entire first page of search results for this error tells people to clear their cache and try a different browser. Those steps address a page that will not load. They do nothing for a code the server already recorded as used.
McAfee documents the error in support article 000001892. Quote that number when you open a ticket. It saves you the first ten minutes of the conversation.
What actually consumes a McAfee activation code
Five events consume a code: you redeemed it previously, a household member redeemed it, a manufacturer or provider session absorbed it, the retail card was opened before you bought it, or a counterfeit activation page captured and redeemed it. Each leaves a different evidence trail.
You redeemed it and forgot — Evidence to look for: A McAfee confirmation email in any inbox you control · Recoverable?: Yes — sign in and use it
Household member redeemed it — Evidence to look for: Confirmation on a shared or partner address · Recoverable?: Yes — the subscription exists
Absorbed by a manufacturer or provider identity — Evidence to look for: No confirmation anywhere, but McAfee is already installed and licensed · Recoverable?: Usually — see below
Card opened before purchase — Evidence to look for: Damaged or lifted scratch panel · Recoverable?: Retailer refund only
Captured by a counterfeit activation page — Evidence to look for: You typed the code somewhere other than mcafee.com · Recoverable?: Retailer refund only
Notice which column matters. The first three are identity problems dressed up as licensing problems. The last two are losses, and no amount of troubleshooting converts them back.
How federated ISP and carrier identities swallow retail keys
Internet providers and mobile carriers that bundle McAfee do not hand you a McAfee account in the normal sense. They federate: the provider holds the identity, McAfee holds the entitlement, and the two are linked by an identifier you never see. A retail key redeemed inside that session binds to it.
This is the single most misdiagnosed cause on the desk, because the symptom is indistinguishable from theft. The code is gone, no confirmation email arrives, and the subscription appears nowhere you can reach. The entitlement is not missing. It is attached to an identity you cannot authenticate against directly.
Why the entitlement lands somewhere you cannot see
Redemption binds to whichever identity is authenticated at that moment, not to whichever email you typed into a form. A federated session already carries an authenticated identity. The redemption flow accepts it, writes the entitlement, and never prompts you to sign in at all.
The sequence runs like this. Your provider provisions McAfee during service activation. You later buy a retail card for a second machine. You open the activation page in the same browser that still holds the provider session. McAfee sees an authenticated user, skips the sign-in prompt entirely, and attaches the new entitlement to the provider identity.
From your side, nothing went wrong. You typed the code, the page accepted it, and the flow completed. You just never noticed that you were never asked who you were.
Cached session tokens and silent re-authentication
Browsers hold authenticated session tokens after a sign-in, and web applications reuse them rather than prompting again. That is the intended behaviour. It becomes a fault when the cached token belongs to a different identity from the one you believe you are operating as.
Three conditions make this worse than it sounds.
Tokens outlive the visit. A session established weeks earlier can still be valid, so there is no visual cue that you are signed in as somebody.
Sign-out is per-surface, not global. Signing out of a provider portal does not necessarily clear the linked McAfee session, and the reverse is also true.
Shared machines inherit sessions. A family computer holds whoever authenticated last, which is rarely whoever is redeeming today.
The fix is unglamorous and reliable: force the flow to ask who you are before you ever type a code.
Open a private or incognito window before you go anywhere near the activation page. No stored tokens, no silent reuse.
Sign in deliberately, as the first action, before the code goes anywhere. Confirm the email shown in the account area is the one you intend.
Redeem only after the account is confirmed on screen.
Screenshot the review screen showing the subscription name and the account email. This is your only contemporaneous record if something later disagrees.
Do this every time, on every key. It costs twenty seconds and removes the entire class of failure described above.
How to find the account that holds your subscription
Probe before you create. A password reset request against an address either sends a reset link, which proves the account exists, or it does not. Creating a new account first destroys the evidence and gives you two identities to reconcile instead of one.
List every address in play: your primary, your partner's, the one on the hardware order, the one on the internet or mobile bill, and any old address the household used years ago.
Request a password reset on each, one at a time. A reset email arriving is a positive result.
Search all of those inboxes for McAfee mail, including Promotions, Updates, and Spam. Search the sender domain rather than the word McAfee; marketing mail buries the transactional message.
Check the provider portal directly if any McAfee subscription in the household arrived bundled with internet or mobile service. Start there, not at mcafee.com.
Open the installed McAfee app on any machine in the house that is already protected, and read the account email it reports. That address owns something, and it may own yours.
Stop and contact McAfee support with the retailer receipt if all six come back empty. Do not redeem a second key to "test" the theory; you will consume that one too.
The last point is the expensive mistake. People buy a replacement card, redeem it in the same browser, hit the same silent session reuse, and lose the second code the same way as the first.
What McAfee support can and cannot do
Support can locate an entitlement across accounts, merge or transfer a subscription, and reissue in documented cases of fulfilment failure. Support cannot un-redeem a code, override the one-use flag, or recover a code that a third party redeemed. Those are database states, not policy decisions.
Go in with evidence rather than frustration. The receipt, the order number, the card serial if the packaging shows one, and the list of addresses you have already eliminated. Article numbers help too: 000001892 for this error, 000001641 for the redemption flow, 000001676 for subscription management. All three live at mcafee.com/support/s/article/ followed by the number.
If a guide sends you to a McAfee article in the old TS###### format, it was written years ago and copied since. McAfee retired that scheme; consumer articles now carry nine-digit numeric IDs.
How to avoid consuming the next key wrongly
Three habits eliminate most of this. Redeem in a private window with a deliberate sign-in. Use one household email for every McAfee purchase, permanently. Type the activation address by hand rather than arriving from a search result or an advert.
Designate one email address as the household's McAfee identity and record it in a password manager alongside the password.
Redeem every future code from a private window, signed in as that identity, with the account email visible on screen before the code is entered.
Photograph the retail card before you scratch the panel, so a damaged or worn code is still legible afterwards.
Keep the receipt for the life of the subscription. It is the only instrument that works when the code does not.
Check whether a provider or manufacturer subscription already covers the device before buying a card at all. Stacking a retail key onto a bundled plan is how most of these accounts get tangled in the first place.
Why is mcafee.com/activate showing a blank white screen?
A blank white screen, an endless spinner, or a certificate warning at the activation page points at the network path rather than at McAfee. Content blockers, corporate DNS filtering, VPN exit nodes in unsupported regions, and stale cached redirects all produce it. Work outward from browser to router.
Disable every browser extension, then reload. Ad blockers and script blockers break the redemption form's validation calls.
Clear cookies and cache for mcafee.com specifically, not for the whole browser.
Disconnect the VPN. A VPN exit node in an unsupported region returns a region error or a blank response from the licensing server.
Switch browsers. Test in Chrome or Chromium-based Edge before you conclude the page is broken.
Flush the DNS resolver cache. On Windows, open Command Prompt as administrator and run ipconfig /flushdns. On macOS, run sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder.
Change the resolver temporarily to 1.1.1.1 or 8.8.8.8 if your ISP's DNS returns nothing for mcafee.com.
Tether to a phone's mobile hotspot to bypass the local network entirely. If the page loads over cellular, the fault is your router, your ISP resolver, or a corporate filter.
Disable IPv6 on the adapter as a last test. Broken IPv6 with working IPv4 produces exactly this symptom on some ISPs.
Faults that survive a cache clear
Four faults outlive a browser reset: a skewed system clock that breaks certificate validation, strict cookie blocking that kills the session handoff between McAfee subdomains, a poisoned hosts file that blackholes the domain, and HTTPS inspection by a previously installed security suite.
Clock skew. TLS validation compares the certificate window against the local clock. A machine several days out of date rejects valid certificates and renders nothing. On Windows, open Command Prompt as administrator and run w32tm /resync, then reload.
Cookie and tracking policy. Redemption crosses more than one McAfee host on its way from the key form to the account dashboard. Safari's tracking prevention and Firefox's strict mode both break that handoff, which presents as a blank screen or an endless spinner rather than an error. Allow cookies for mcafee.com specifically and retry.
Poisoned hosts file. Malware and cracked software routinely write security-vendor domains into C:\Windows\System32\drivers\etc\hosts pointing at 127.0.0.1, so the machine cannot reach the vendor that would remove it. Open that file in Notepad as administrator and look for McAfee entries. If you find them, you have a live infection and an activation problem, in that order of priority.
HTTPS inspection. A previous security suite, a parental-control agent, or a corporate middlebox terminating TLS will hand the browser a substituted certificate. The irony of one antivirus product blocking another's activation page is lost on nobody. Remove the old product properly before you troubleshoot further.
Proxy auto-config. On a managed machine, check for a PAC file under proxy settings. A stale auto-config script routes McAfee traffic to a decommissioned gateway and returns nothing at all.
Why installation fails after successful activation
Post-redemption install failures come from residue: a previous security suite that uninstalled badly, an earlier McAfee build that left registry keys and drivers behind, or an operating system below the supported floor. McAfee ships two repair utilities for exactly this, and they run in a specific order.
Installer stalls during the device check phase — Most likely cause: Corrupt system components or an out-of-date Windows build · Action: Apply pending Windows updates, then run the Pre-Install tool
Install stops partway with a component failure message — Most likely cause: Remnants of a previous McAfee or third-party suite · Action: Run MCPR, restart, reinstall
Uninstall returns error code 104.0 or 104.3 — Most likely cause: Broken uninstall entry · Action: Run MCPR with a freshly downloaded copy
Product installs but reports no subscription — Most likely cause: Signed in with the wrong account · Action: Sign out, sign in with the redemption email
Download never starts — Most likely cause: Browser blocking the executable · Action: Allow the download explicitly, or use a different browser
Read the install log before you run another tool
McAfee writes installation logs to C:\ProgramData\McAfee\MCLogs, and Windows Installer writes its own into %TEMP%. Read those before you run another removal tool. A failed install usually names the component that broke, which turns guesswork into a targeted fix rather than another blind reinstall cycle.
Open C:\ProgramData\McAfee\MCLogs and sort by date. The folder is hidden by default; enable hidden items in File Explorer first.
Search the newest log for the word Error and read the line above it, which names the component that failed.
Press Windows+R, type %TEMP%, and check free space on that volume. The web installer extracts its payload there, not to the install target, and a full temp volume fails the install with a misleading message.
Confirm the Windows Installer service is running. Open services.msc and check that msiserver is not disabled.
Clear any pending reboot. Open Registry Editor, check HKLM\SYSTEM\CurrentControlSet\Control\Session Manager for a PendingFileRenameOperations value, and restart if one exists. Windows blocks driver installs while that flag is set.
Test the path to McAfee's distribution servers. Run ping download.mcafee.com from an administrative Command Prompt. A reply of 127.0.0.1 confirms the hosts-file fault described earlier.
Run the McAfee Pre-Install tool first
The Pre-Install tool, distributed as McPreInstall.exe, checks the machine against minimum requirements and repairs the system components McAfee's installer depends on. Run it before you run any removal tool. It repairs; it does not delete a working installation.
Download McPreInstall.exe from McAfee's support site and save it to the desktop.
Close every open application first. The tool touches shared components.
Double-click McPreInstall.exe and click Start inside the tool.
Read the warning message, then click OK.
Click OK again when the tool finishes, then Close.
Restart the computer before you retry the installation.
MCPR: what the McAfee removal tool strips from Windows
MCPR is a cleanup pass, not an uninstaller. McAfee requires you to remove the product through Windows first, then run MCPR second. Everything below assumes Windows; the tool has no macOS equivalent.
What Add/Remove Programs leaves behind
Security suites do not live in a folder. They register boot-start drivers, file-system minifilters, network filter drivers, and privileged services, then write installation state across three separate registry locations. An uninstaller that fails partway through leaves those components registered and loading.
That residue is why a second install attempt fails with a message that names a component rather than a reason. Windows is refusing to register a driver that is already registered, or to install a product the Installer database thinks is present.
Kernel-mode filter drivers
McAfee installs drivers in the mfe family, loaded at boot before most of Windows is running. They include a link driver, a file-system filter, a firewall driver, and a Windows Filtering Platform driver. The exact set varies by product and version, and orphaned entries survive a failed uninstall.
The names you will see in the driver stack follow a pattern: mfehidk.sys, mfeavfk.sys, mfewfpk.sys, mfefirek.sys, and an Early Launch Anti-Malware component. They sit in C:\Windows\System32\drivers\.
Two of those matter more than the rest. The file-system minifilter attaches to volumes at a fixed altitude in the filter stack, and Windows will not load a second scanner cleanly while a stale registration occupies that slot. The ELAM driver loads before ordinary boot-start drivers by design, which means a partial removal leaves a hook running from the earliest moment of boot — before anything you can see in Task Manager exists.
Service registrations and registry hives
McAfee writes product state to HKLM\SOFTWARE\McAfee, mirrors part of it under WOW6432Node on 64-bit Windows, and registers each driver as a service under CurrentControlSet. A failed uninstall leaves those keys populated, and the next installer reads them as evidence the product is present.
HKLM\SOFTWARE\McAfee — What lives there: Product configuration, version state, subscription markers
HKLM\SOFTWARE\WOW6432Node\McAfee — What lives there: 32-bit component state on 64-bit Windows
HKLM\SYSTEM\CurrentControlSet\Services\ — What lives there: One service entry per mfe driver, with start type and load order
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ — What lives there: The entry that populates Add/Remove Programs
C:\ProgramData\McAfee\ — What lives there: Logs, definition data, per-machine configuration
C:\Program Files\Common Files\McAfee\ — What lives there: Shared binaries used by several McAfee components at once
Inspect these, do not edit them. Deleting service keys by hand while the corresponding driver is still registered produces a machine that fails to boot cleanly. Read the locations to confirm what is left; let MCPR do the removal.
Windows Installer cache and orphaned product records
Windows Installer keeps a cached copy of every MSI and patch it has applied, plus a product registration database. When an uninstall fails midway, the cached package and the product record survive. The next installer consults that record, concludes the product exists, and refuses to proceed.
The cache sits in C:\Windows\Installer, a hidden system folder full of files with random names. Product registrations live under the Installer branch of the classes hive. This is the layer that produces the most confusing symptom of all: the product does not appear in Add/Remove Programs, does not appear in Program Files, and still blocks reinstallation.
Do not delete anything in that folder manually. It is shared by every MSI-installed application on the machine, and removing the wrong cached package breaks the uninstall path for software that is working fine.
When MCPR is the right tool
MCPR is a repair step, not routine maintenance. Run it after a failed uninstall, before a reinstall that keeps failing, or when error 104.0 or 104.3 appears. Do not run it to remove a working installation; use Windows Settings for that.
Working McAfee you simply want gone — Run MCPR?: No, not first · Do this instead: Settings, Apps, Installed apps — MCPR only if that fails
Uninstall returns error 104.0 or 104.3 — Run MCPR?: Yes · Do this instead: Fresh MCPR download, then restart
Install stalls partway naming a component — Run MCPR?: Yes · Do this instead: MCPR, restart, then reinstall from My Account
Installer stalls during the device check — Run MCPR?: Not yet · Do this instead: Windows updates and the Pre-Install tool first
Product absent everywhere but blocks reinstall — Run MCPR?: Yes · Do this instead: MCPR clears the Installer product record
McAfee pop-ups with no McAfee installed — Run MCPR?: No · Do this instead: Check browser notification permissions and extensions
Removing McAfee PC Optimizer — Run MCPR?: No · Do this instead: MCPR does not touch it; use Windows Settings
That last row catches people. McAfee states plainly that MCPR does not remove PC Optimizer. Running it twice will not change that.
Both codes indicate the uninstaller could not complete its removal sequence. McAfee covers them in support article 000002577 and directs you to MCPR as the resolution. The codes tell you the uninstall broke; they do not tell you which component broke it.
Read the logs before you assume anything. The log locations and what to search for are covered under "Read the install log before you run another tool" above; the component named in the newest entry is what actually broke the uninstall.
Related article numbers worth knowing: 000002766 covers the MCPR procedure itself, and 000001694 covers installation error code 0 on Windows. All three sit at mcafee.com/support/s/article/ followed by the number. Anything still citing the old TS###### format is quoting a scheme McAfee retired.
Uninstall through Windows first, download a fresh copy of MCPR, run it as administrator, pass the case-sensitive validation prompt, and restart. The restart is mandatory. Driver registrations do not clear until the machine reboots, and skipping it wastes the entire operation.
Save open work and close every application. The tool touches shared components while it runs.
Uninstall McAfee through Settings, then Apps, then Installed apps, and let it finish or fail on its own terms.
Download a new copy of MCPR.exe from McAfee's support site. McAfee states explicitly that a fresh copy is required each time so the tool recognises current product versions. A copy from last year will not know about this year's components.
Right-click MCPR.exe, choose Run as administrator, and approve the User Account Control prompt.
Click Next, then Agree to accept the licence terms.
Type the validation characters exactly as shown. The check is case-sensitive and exists to stop the tool running unattended or by accident.
Wait for the CleanUp Successful message rather than closing the window early.
Restart Windows immediately. Nothing is finished until the reboot completes.
The machine is unprotected between removal and reinstall. Confirm Microsoft Defender Antivirus has switched itself back on after the restart, and stay off unfamiliar sites and downloads until your chosen product is running again.
What MCPR does not remove
MCPR targets McAfee consumer components. It does not remove McAfee PC Optimizer, it does not clean up a different vendor's leftovers, and it does not repair Windows components that a failed install corrupted. Each of those needs a different tool.
McAfee PC Optimizer — remove through Windows Settings; MCPR ignores it by design.
A previous vendor's remnants — Norton, Kaspersky, Avast and the rest each publish their own removal utility. Use theirs, not this one.
Browser extensions and notification permissions — McAfee WebAdvisor's browser component and any granted site notifications are browser-side and survive.
Broken Windows servicing state — if the install failed because Windows itself is damaged, run sfc /scannow and then DISM /Online /Cleanup-Image /RestoreHealth from an administrative Command Prompt.
Your subscription — removing the software does not cancel or consume anything. The entitlement stays on your account.
Verifying removal at the driver level
Checking Program Files proves nothing, because the components that block a reinstall are drivers and registry records rather than visible folders. Verify those directly instead. Two read-only commands and one folder check settle the question in under a minute.
Open Command Prompt as administrator after the restart.
Run fltmc filters. This lists every file-system minifilter currently loaded, with its altitude. No mfe entries should appear.
Run sc query mfehidk and repeat for any other mfe name you saw earlier. A clean machine returns a message saying the service does not exist.
Check C:\Windows\System32\drivers\ for files matching mfe*.sys. Sort by name; the group is easy to spot.
Open Registry Editor and confirm HKLM\SOFTWARE\McAfee is gone or empty. Read only — do not delete what remains.
Open Windows Security and confirm Defender shows real-time protection active.
If mfe minifilters still load after a restart, MCPR did not complete. Download the tool again, run it once more, and restart again before escalating. Two consecutive clean runs that still leave drivers registered is a support ticket, not a third attempt.
Reinstalling after a clean removal
Reinstall from My Account on the device itself, not from a downloaded installer you kept. Do not re-enter a product key; the entitlement already lives on the account, and re-entering a consumed code returns an error that has nothing to do with your actual problem.
Sign in to McAfee My Account on the machine you are rebuilding.
Confirm the subscription and expiry date appear before you download anything.
Download the installer from the subscription tile and run it.
Watch the device check phase. If it stalls again after a verified clean removal, the fault is Windows-side rather than McAfee-side — apply pending updates and run the Pre-Install tool.
Restart when prompted, then open the app and confirm the subscription name appears in the account area.
Run fltmc filters once more. The mfe minifilter should now be present, which is the positive confirmation that the driver stack registered properly this time.
How to add McAfee to another device
Additional devices consume licence seats from the existing subscription, not additional product keys. Sign in to My Account on the new device and download from there, or send an install link to it. Never redeem a second key to cover a second computer on the same plan.
Sign in to My Account on the new device with the subscription email.
Select the option to protect another device.
Send the install link by email, or scan the on-screen code with the phone you want covered.
Install from the link on the target device and sign in with the same account.
Remove a retired device from the account first if the plan has a seat limit and you have hit it.
Check what your plan covers before you count seats. Some McAfee plans list unlimited devices, and McAfee restricts those to household devices you own personally under a fair-use policy. Plans sold through a carrier or ISP frequently carry different seat counts from the retail equivalent.
How to confirm the subscription is genuinely active
Two checks settle it. The McAfee app on the device should name the subscription and show an expiry date, and My Account should list the same subscription with the same date and the device visible in the device list. A green status icon alone proves nothing.
Open the McAfee app and locate the subscription name and expiry date.
Sign in to My Account in a browser and compare the expiry date shown there.
Confirm the device appears in the account's device list under the name you expect.
Run a manual update inside the app. A subscription that cannot pull definition updates is not properly entitled, whatever the dashboard claims.
Wait a few minutes before you panic. Entitlement changes propagate from the licensing side to the installed app on a delay, and a sign-out and sign-in inside the app forces a refresh.
Check the auto-renewal setting while you are there, and turn it off if you do not want it. Some bundled benefits depend on auto-renewal staying enabled.
How counterfeit activation pages harvest 25-digit keys
McAfee documents this directly: some sites impersonate McAfee customer service, capture activation codes typed into their forms, and redeem those codes before the buyer does. The buyer then sees "Key already in use" at the genuine page. The key is gone and support cannot reissue it.
The mechanics are unremarkable. A lookalike domain buys search ads or ranks for the navigational query, renders a form that resembles the McAfee redemption page, and posts whatever you type to an attacker-controlled endpoint. The page may then show a plausible error, or display a support telephone number and pivot to a remote-access scam.
Three rules cover it.
Type the address manually. Search results and adverts are the delivery mechanism. The address bar is not.
Read the registrable domain, not the whole string. The part immediately before the first single slash must be mcafee.com. Anything else — hyphenated variants, extra words, unusual endings — is somebody else's server.
Treat any telephone number on a third-party page as hostile. McAfee routes support through its own site. A support number printed beside an activation form is the tell.
If you already typed a key into a site that was not mcafee.com, treat that key as burned. The recovery sequence is below.
If a counterfeit activation page captured the code
McAfee states that sites impersonating its support channels capture codes typed into them and redeem those codes first. The buyer then sees this error at the genuine page. There is no recovery path through McAfee, because the redemption was technically valid.
Be honest with yourself about where you typed it. The lookalike pages are competent. They rank for the navigational query, they render a form that resembles the real one, and several of them display a telephone number that routes to a remote-access scam.
Treat the code as lost. It was redeemed by somebody, and McAfee cannot unwind that.
Contact the retailer, not McAfee, with proof of purchase. The retailer is the party that can replace or refund.
Change the password on any account whose credentials you entered on the same page, starting with the email address you used.
Run a full scan if you downloaded anything from that site or granted anyone remote access to the machine.
Report the domain. McAfee takes scam submissions at scam@mcafee.com; the Anti-Phishing Working Group reads reportphishing@apwg.org.
Frequently asked questions about mcafee.com/activate
Can I use my 25-digit McAfee activation code more than once?
No. McAfee states that a product key redeems exactly once. After redemption the entitlement lives on your account, so reinstalling on the same device or adding another device uses My Account rather than the key. Support cannot reset a consumed key, which is why key theft is unrecoverable.
Do I need the product key again to reinstall McAfee?
No. Reinstallation authenticates against your McAfee account, not against the printed key. Sign in to My Account on the device, download the installer from the subscription tile, and the entitlement applies automatically. Keep the account email and password; the physical card becomes irrelevant the moment redemption completes.
Which operating systems does McAfee still support?
McAfee supports Windows 11 and Windows 10 RS5 and newer on x64 hardware, Windows 11 and newer on ARM64, macOS 13.x and above, Android 10 or higher, iOS 16 or later, and ChromeOS 102.0.5005 and higher. Windows 7, Windows 8, and older macOS releases fall outside the supported range.
Why does my key work but the subscription not appear?
You are almost certainly signed in under a different email address. Redemption binds the entitlement to whichever account authenticated at that moment, and browsers often reuse an older McAfee session. Search your mail for the McAfee redemption confirmation and sign in with the address that received it.
How long does McAfee activation take?
Redemption itself completes in seconds once the key validates. Installation takes longer, because the web installer profiles the device and then downloads the full product payload. Budget a few minutes on a normal connection, plus a mandatory restart on Windows before real-time scanning loads.
Does McAfee work alongside Microsoft Defender?
Windows disables Defender's real-time protection automatically when a registered third-party antivirus installs, and re-enables it if that product is removed. Do not attempt to run both scanners simultaneously. Two real-time engines compete for the same file-system filter drivers and produce lockups and false detections.
What is the difference between redeeming and installing?
Redemption is a licensing transaction on McAfee's servers; installation is a local operation on one device. Redeeming converts the key into an account entitlement. Installing pulls software onto a specific machine using that entitlement. One redemption supports many installations, up to the plan's device limit.
Can I change the email address on my McAfee subscription?
Account email changes run through McAfee support or the account settings area, not through the activation page. Redeeming a second key will not move an existing subscription. Choose the redemption address carefully at the outset, because renewals, support tickets, and device management all key off it.
My ISP provides McAfee. Do I still use mcafee.com/activate?
Usually not. Carrier and ISP-supplied subscriptions provision through the provider's own portal, and the McAfee redemption page will reject or misfile those credentials. Start from your provider's security page. McAfee Multi Access exists specifically for subscriptions delivered by mobile and internet providers.
Is mcafee.com/activate the same as the McAfee login page?
No. The activation page redeems a product key and creates an entitlement. The login page authenticates an existing account and opens the dashboard. Once a key is redeemed you use the login page and My Account for everything else, and the activation page never again.
Official McAfee destinations
Every link below points at McAfee's own infrastructure. Nothing on this site accepts a product key.
Report a suspected McAfee impersonation site to McAfee at scam@mcafee.com and to the Anti-Phishing Working Group at reportphishing@apwg.org.