Hash a file or some text with SHA-256, SHA-512, SHA-1 or MD5, then paste the published checksum to find out whether your download is genuine and complete. Files of any size work.
Drop a file here, or choose one. It is read in 4 MB pieces, so very large files work.
Runs entirely in your browser. Nothing you type or upload is sent to a server.
What a checksum is
A checksum, more precisely a cryptographic hash, is a short fingerprint of a file. Feed the hash function any amount of data and it returns a fixed-length string of hexadecimal digits. Change a single bit in the input and the output changes completely, with no resemblance to the old one. The function runs one way only: nobody can work backward from the fingerprint to the file.
That behavior makes checksums useful for one thing above all: confirming that the copy of a file you have is identical to the original. Software publishers calculate the fingerprint of the file they released and print it next to the download link. You calculate the fingerprint of what actually arrived and compare. If the two strings are the same, every byte arrived intact. If they differ at all, something is wrong.
Choosing an algorithm
| Algorithm | Hex digits | Use it for |
|---|---|---|
| MD5 | 32 | Detecting accidental corruption when it is all the publisher offers. Not secure against deliberate tampering. |
| SHA-1 | 40 | Legacy systems, such as Git object names. A practical collision was demonstrated in 2017, so avoid it for security. |
| SHA-256 | 64 | The default for verifying downloads. Fast and not known to be broken. |
| SHA-512 | 128 | Same family, longer output. Some publishers use it. It is often faster than SHA-256 on 64-bit native code but slower in a browser. |
Whenever you have a choice, use SHA-256. When the publisher only gives you MD5, the check is still valuable for spotting a download that was interrupted or corrupted, which is by far the most common problem.
What a match does and does not prove
A match proves your file is identical to the one the checksum came from. It says nothing about whether that file is safe.
The weak point is where you got the checksum. If it sits on the same web page as the download, an attacker who can alter the file on that server can alter the checksum beside it, and the check will pass for malware. The check is strongest when the checksum reaches you by a different route: a signed announcement, a separate trusted domain, or a GPG signature over the checksum file itself. Linux distributions publish a signed list of checksums for exactly this reason. For ordinary downloads from a reputable site, a matching checksum still protects you against truncated transfers, flaky mirrors and disk errors.
How to compare correctly
Paste the whole value. Capital letters, lowercase letters and stray spaces make no difference here, because this tool normalizes them before comparing. It also understands the line format printed by sha256sum, which is the hash, two spaces and the file name, so you can paste a line straight from a SHA256SUMS file. When you paste several lines, the one whose file name matches your file is used.
Do not compare by eye beyond the first few characters. People checking by eye tend to read the beginning and end and skip the middle, and a typo or a truncated copy can hide in the part nobody reads. A tool comparing every digit does not get tired.
Doing the same on the command line
# Linux
sha256sum ubuntu.iso
sha256sum -c SHA256SUMS --ignore-missing
# macOS
shasum -a 256 ubuntu.iso
# Windows PowerShell
Get-FileHash .\ubuntu.iso -Algorithm SHA256
# Windows Command Prompt
certutil -hashfile ubuntu.iso SHA256For MD5 use md5sum on Linux, md5 on macOS, or -Algorithm MD5 in PowerShell. The browser tool is handy when you are on a machine where you cannot or would rather not open a terminal, or when you want to check several algorithms at once.
How very large files are handled
The browser's built-in hashing function needs the entire input in memory at once, which fails on a file of several gigabytes. This tool instead reads the file in 4 MB slices and feeds each slice into a hash that keeps only a small running state. Memory use stays flat from a 1 KB file to a 50 GB image. Because hashing is deterministic, the result is identical to what a command-line tool prints for the same file. Speed is limited by your processor and disk, and the progress bar shows what remains. Tick only the algorithms you need, since each one costs a full pass over the data.
Hashing text
The Text tab hashes exactly what is in the box, encoded as UTF-8. That is useful for checking a string you plan to store, comparing two values without revealing either, or reproducing a hash another system computed. Be careful with invisible differences: a trailing newline, a space, or a Windows line break changes the hash entirely. For passwords, a plain fast hash like these is the wrong tool, since they are designed to be quick. If you need a strong password in the first place, try the password generator, and to convert data between representations before hashing, see the Base64 converter.

