Google Analytics helps us understand which tools you use and which actions work. Your files and entered text stay out of analytics.

How to verify a file checksum

Compare the bytes you downloaded with the publisher's reference. Use SHA-256, a legacy MD5 value or your operating system's built-in command.

Free toolHash GeneratorGenerate MD5, SHA-256 and four more checksums. Hash files locally, verify a digest or create HMAC and SRI values.Generate a checksum

The short answer

Hash the downloaded file with the publisher's algorithm, then compare the entire result with their expected checksum. A match means those values agree. A mismatch means you should investigate before using the file.

  1. Find the checksum on the publisher's official release page. Note the algorithm and the exact filename.
  2. Generate that algorithm's digest from your downloaded file. Use one of the commands below or the browser tool.
  3. Compare every character. Hexadecimal letter case does not matter, but a missing character does.

Use SHA-256 for a new checksum. MD5 and SHA-1 remain useful for matching old published values. They are unsuitable for resisting deliberate collision attacks.

Check a file on Windows, macOS or Linux

You can calculate a file checksum without installing a new app. Replace the example filename with your download's path.

SystemSHA-256 commandFor a published MD5 value
Windows PowerShellGet-FileHash -LiteralPath '.\download.zip' -Algorithm SHA256Change SHA256 to MD5.
macOS Terminalshasum -a 256 'download.zip'md5 'download.zip'
Linux terminalsha256sum 'download.zip'md5sum 'download.zip'

These commands read the file. They do not change it. Windows shows the digest in the Hash column; macOS and Linux print it beside the filename.

Verify a checksum manifest

On Linux, a publisher's standard SHA-256 manifest can check several downloads together. Put the files beside the manifest and run:

sha256sum -c SHA256SUMS

On macOS, use shasum -a 256 -c SHA256SUMS. Read the result for each file. Missing files and mismatches need attention.

Verify a checksum in your browser

The hash generator calculates file digests locally and compares a pasted reference. It does not upload your files.

  1. Choose Files and select or drop the downloaded file.
  2. Wait for the file digests. All six algorithms are calculated together.
  3. Paste the complete reference into Expected checksum. The tool checks it against each available digest.

Use the file itself rather than pasting its text. File hashing keeps the original encoding, line endings and any byte order mark.

Why a checksum does not match

A mismatch means the inputs, algorithm or reference differ. Check these causes before assuming the download was tampered with.

What to checkWhat to do
Different release or platformMatch the version, operating system and architecture to the reference filename.
Wrong algorithmSelect SHA-256 for a SHA-256 reference. Do not compare it with MD5.
Archive versus extracted fileHash the exact object named in the release instructions.
Incomplete downloadCompare the file size with the publisher's value, then download it again if needed.
Edited text or metadataUse the untouched download. Saving a file again can change its bytes.
Copied referenceCheck for a missing character or a copied filename. Compare the full digest.

Text can look identical and still have different bytes

A trailing newline changes a hash. So does letter case. Even two visually identical accented letters can use different Unicode sequences.

We calculated these examples on 4 October 2026 with Node.js v24.18.0. Each string became a UTF-8 buffer, then passed to createHash('sha256').

InputBytesHex bytesSHA-256, first 16 characters
Empty text0(none)e3b0c44298fc1c149
abc361 62 63ba7816bf8f01cfea
abc followed by LF461 62 63 0aedeaaff3f1774ad2
ABC341 42 43b5d4045c3f466fa9
é, one code point2c3 a94a99557e4033c353
e + combining acute accent365 cc 81bf12767b0f2a56b2

Prefixes make this table readable. Always compare the full 64-character SHA-256 value when verifying a file.

For exactly three UTF-8 bytes, abc, the complete SHA-256 digest is:

ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad

You can reproduce the no-newline example in a macOS or Linux terminal:

printf 'abc' | shasum -a 256

On Linux, printf 'abc' | sha256sum works too. Avoid echo abc for this example: it normally adds a newline.

What a file hash cannot prove

A checksum alone does not establish who published a file. Trust depends on where you got the expected value.

If the same compromised page serves both a modified download and its matching checksum, the comparison still passes. Follow the publisher's signature verification instructions when authenticity matters.

Do not use a fast file hash to store passwords. Password storage needs a dedicated scheme such as Argon2id. This guide's commands are for file integrity checks.

Sources and reproducibility

The byte examples above are our calculations. The algorithm guidance and command behaviour come from the following references.

Frequently asked questions

Can I verify a checksum after renaming a file?

Yes. A normal file checksum covers the file bytes, so renaming it does not change the digest. Editing a document or rewriting its metadata can change the bytes. A checksum manifest also records filenames, so its automatic verification command may require the original filename.

Why is my MD5 checksum different from the SHA-256 value?

They use different algorithms. MD5 produces 32 hexadecimal characters; SHA-256 produces 64. Choose the algorithm named by the publisher. Reformatting a digest cannot turn one algorithm into another.

Does a matching checksum prove a file is safe?

No. It shows that the file matches the reference digest. If an attacker replaces both the file and its checksum, they can still match. Get the expected value from a trusted source, or use the publisher's signed release and signature verification instructions.

Should I hash the downloaded ZIP or the extracted files?

Hash the exact item named beside the publisher's checksum. A ZIP checksum normally covers the downloaded archive, not its extracted files. Each extracted file has its own bytes and digest.

↑↓ move↵ openesc close