Checksum Calculator

Hash a file or some text with SHA-256, SHA-512, SHA-1 or MD5, then paste the published checksum to find out whether your download is genuine and complete. Files of any size work.

Algorithms to calculate
Each extra algorithm adds to the time on a large file. SHA-256 is the usual choice.

Drop a file here, or choose one. It is read in 4 MB pieces, so very large files work.

Capital letters and extra spaces are fine. The algorithm is detected from the length: 32 digits is MD5, 40 is SHA-1, 64 is SHA-256, 128 is SHA-512.

Runs entirely in your browser. Nothing you type or upload is sent to a server.

What a checksum is

A checksum, more precisely a cryptographic hash, is a short fingerprint of a file. Feed the hash function any amount of data and it returns a fixed-length string of hexadecimal digits. Change a single bit in the input and the output changes completely, with no resemblance to the old one. The function runs one way only: nobody can work backward from the fingerprint to the file.

That behavior makes checksums useful for one thing above all: confirming that the copy of a file you have is identical to the original. Software publishers calculate the fingerprint of the file they released and print it next to the download link. You calculate the fingerprint of what actually arrived and compare. If the two strings are the same, every byte arrived intact. If they differ at all, something is wrong.

Choosing an algorithm

AlgorithmHex digitsUse it for
MD532Detecting accidental corruption when it is all the publisher offers. Not secure against deliberate tampering.
SHA-140Legacy systems, such as Git object names. A practical collision was demonstrated in 2017, so avoid it for security.
SHA-25664The default for verifying downloads. Fast and not known to be broken.
SHA-512128Same family, longer output. Some publishers use it. It is often faster than SHA-256 on 64-bit native code but slower in a browser.

Whenever you have a choice, use SHA-256. When the publisher only gives you MD5, the check is still valuable for spotting a download that was interrupted or corrupted, which is by far the most common problem.

What a match does and does not prove

A match proves your file is identical to the one the checksum came from. It says nothing about whether that file is safe.

The weak point is where you got the checksum. If it sits on the same web page as the download, an attacker who can alter the file on that server can alter the checksum beside it, and the check will pass for malware. The check is strongest when the checksum reaches you by a different route: a signed announcement, a separate trusted domain, or a GPG signature over the checksum file itself. Linux distributions publish a signed list of checksums for exactly this reason. For ordinary downloads from a reputable site, a matching checksum still protects you against truncated transfers, flaky mirrors and disk errors.

How to compare correctly

Paste the whole value. Capital letters, lowercase letters and stray spaces make no difference here, because this tool normalizes them before comparing. It also understands the line format printed by sha256sum, which is the hash, two spaces and the file name, so you can paste a line straight from a SHA256SUMS file. When you paste several lines, the one whose file name matches your file is used.

Do not compare by eye beyond the first few characters. People checking by eye tend to read the beginning and end and skip the middle, and a typo or a truncated copy can hide in the part nobody reads. A tool comparing every digit does not get tired.

Doing the same on the command line

# Linux
sha256sum ubuntu.iso
sha256sum -c SHA256SUMS --ignore-missing

# macOS
shasum -a 256 ubuntu.iso

# Windows PowerShell
Get-FileHash .\ubuntu.iso -Algorithm SHA256

# Windows Command Prompt
certutil -hashfile ubuntu.iso SHA256

For MD5 use md5sum on Linux, md5 on macOS, or -Algorithm MD5 in PowerShell. The browser tool is handy when you are on a machine where you cannot or would rather not open a terminal, or when you want to check several algorithms at once.

How very large files are handled

The browser's built-in hashing function needs the entire input in memory at once, which fails on a file of several gigabytes. This tool instead reads the file in 4 MB slices and feeds each slice into a hash that keeps only a small running state. Memory use stays flat from a 1 KB file to a 50 GB image. Because hashing is deterministic, the result is identical to what a command-line tool prints for the same file. Speed is limited by your processor and disk, and the progress bar shows what remains. Tick only the algorithms you need, since each one costs a full pass over the data.

Hashing text

The Text tab hashes exactly what is in the box, encoded as UTF-8. That is useful for checking a string you plan to store, comparing two values without revealing either, or reproducing a hash another system computed. Be careful with invisible differences: a trailing newline, a space, or a Windows line break changes the hash entirely. For passwords, a plain fast hash like these is the wrong tool, since they are designed to be quick. If you need a strong password in the first place, try the password generator, and to convert data between representations before hashing, see the Base64 converter.

Frequently Asked Questions

Choose or drop the file above with SHA-256 ticked, then paste the checksum published by the vendor into the compare box. A green MATCH means the file is byte-for-byte what the publisher hashed. On the command line, use sha256sum file on Linux, shasum -a 256 file on macOS, or Get-FileHash file in PowerShell.
The file is not uploaded. The hashing code runs in your browser tab, and the file is read from your disk in 4 MB pieces. Nothing you choose here is sent to a server.
Yes. The file is streamed in 4 MB pieces, so memory use stays small whatever the file size. Speed depends on your device and the algorithms you select: SHA-256 is fast, SHA-512 is slower in a browser because it does 64-bit arithmetic on 32-bit integers. A progress bar shows how far along it is, and you can cancel at any time.
MD5 is fine for catching accidental corruption, such as a download that was cut off. It is not safe for security, because attackers can deliberately create two different files with the same MD5. If a publisher offers SHA-256, use that. SHA-1 has the same weakness, though it is harder to exploit.
The usual causes are an incomplete or corrupted download, hashing a different file than the one the checksum is for, comparing different algorithms (a SHA-256 value will never equal an MD5 value), or text mode picking up an extra line break. If you copied the checksum from a web page, make sure you copied all of it. If the sizes also differ, download the file again.
MD5 produces 32 hexadecimal digits, SHA-1 produces 40, SHA-256 produces 64 and SHA-512 produces 128. This tool uses the length of the checksum you paste to work out which algorithm to compare against.
It proves the file is identical to the one the checksum was calculated from. It does not prove that file is trustworthy. If an attacker controls the page, they can change the download and the checksum together. Prefer checksums obtained over a different channel from the download, or a cryptographic signature from the publisher.
Yes. This tool hashes your text as UTF-8, which is what nearly every modern tool does. The same words saved as UTF-16 or a legacy code page produce a different hash. Line endings matter too: Windows (CRLF) and Unix (LF) line breaks give different results.
The Internet Omni-Tool