How to verify a file checksum
Compare the bytes you downloaded with the publisher's reference. Use SHA-256, a legacy MD5 value or your operating system's built-in command.
Free toolHash GeneratorGenerate MD5, SHA-256 and four more checksums. Hash files locally, verify a digest or create HMAC and SRI values.Generate a checksumThe short answer
Hash the downloaded file with the publisher's algorithm, then compare the entire result with their expected checksum. A match means those values agree. A mismatch means you should investigate before using the file.
- Find the checksum on the publisher's official release page. Note the algorithm and the exact filename.
- Generate that algorithm's digest from your downloaded file. Use one of the commands below or the browser tool.
- Compare every character. Hexadecimal letter case does not matter, but a missing character does.
Use SHA-256 for a new checksum. MD5 and SHA-1 remain useful for matching old published values. They are unsuitable for resisting deliberate collision attacks.
Check a file on Windows, macOS or Linux
You can calculate a file checksum without installing a new app. Replace the example filename with your download's path.
| System | SHA-256 command | For a published MD5 value |
|---|---|---|
| Windows PowerShell | Get-FileHash -LiteralPath '.\download.zip' -Algorithm SHA256 | Change SHA256 to MD5. |
| macOS Terminal | shasum -a 256 'download.zip' | md5 'download.zip' |
| Linux terminal | sha256sum 'download.zip' | md5sum 'download.zip' |
These commands read the file. They do not change it. Windows shows the digest in the Hash column; macOS and Linux print it beside the filename.
Verify a checksum manifest
On Linux, a publisher's standard SHA-256 manifest can check several downloads together. Put the files beside the manifest and run:
sha256sum -c SHA256SUMSOn macOS, use shasum -a 256 -c SHA256SUMS. Read the result for each file. Missing files and mismatches need attention.
Verify a checksum in your browser
The hash generator calculates file digests locally and compares a pasted reference. It does not upload your files.
- Choose Files and select or drop the downloaded file.
- Wait for the file digests. All six algorithms are calculated together.
- Paste the complete reference into Expected checksum. The tool checks it against each available digest.
Use the file itself rather than pasting its text. File hashing keeps the original encoding, line endings and any byte order mark.
Why a checksum does not match
A mismatch means the inputs, algorithm or reference differ. Check these causes before assuming the download was tampered with.
| What to check | What to do |
|---|---|
| Different release or platform | Match the version, operating system and architecture to the reference filename. |
| Wrong algorithm | Select SHA-256 for a SHA-256 reference. Do not compare it with MD5. |
| Archive versus extracted file | Hash the exact object named in the release instructions. |
| Incomplete download | Compare the file size with the publisher's value, then download it again if needed. |
| Edited text or metadata | Use the untouched download. Saving a file again can change its bytes. |
| Copied reference | Check for a missing character or a copied filename. Compare the full digest. |
Text can look identical and still have different bytes
A trailing newline changes a hash. So does letter case. Even two visually identical accented letters can use different Unicode sequences.
We calculated these examples on 4 October 2026 with Node.js v24.18.0. Each string became a UTF-8 buffer, then passed to createHash('sha256').
| Input | Bytes | Hex bytes | SHA-256, first 16 characters |
|---|---|---|---|
| Empty text | 0 | (none) | e3b0c44298fc1c149 |
| abc | 3 | 61 62 63 | ba7816bf8f01cfea |
| abc followed by LF | 4 | 61 62 63 0a | edeaaff3f1774ad2 |
| ABC | 3 | 41 42 43 | b5d4045c3f466fa9 |
| é, one code point | 2 | c3 a9 | 4a99557e4033c353 |
| e + combining acute accent | 3 | 65 cc 81 | bf12767b0f2a56b2 |
Prefixes make this table readable. Always compare the full 64-character SHA-256 value when verifying a file.
For exactly three UTF-8 bytes, abc, the complete SHA-256 digest is:
ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015adYou can reproduce the no-newline example in a macOS or Linux terminal:
printf 'abc' | shasum -a 256On Linux, printf 'abc' | sha256sum works too. Avoid echo abc for this example: it normally adds a newline.
What a file hash cannot prove
A checksum alone does not establish who published a file. Trust depends on where you got the expected value.
If the same compromised page serves both a modified download and its matching checksum, the comparison still passes. Follow the publisher's signature verification instructions when authenticity matters.
Do not use a fast file hash to store passwords. Password storage needs a dedicated scheme such as Argon2id. This guide's commands are for file integrity checks.
Sources and reproducibility
The byte examples above are our calculations. The algorithm guidance and command behaviour come from the following references.
- Microsoft: Get-FileHash, algorithms and file content hashing.
- GNU Coreutils: SHA-2 utilities, digest generation and manifest checking.
- Perl: shasum, SHA algorithms and checksum verification.
- RFC 6151, MD5's security limits.
- NIST: retiring SHA-1, collision resistance and stronger replacements.
- OWASP: Password Storage Cheat Sheet, dedicated password hashing.