How to verify the checksum of a downloaded file before you open it

How to verify the checksum of a downloaded file before you open it

Installer, disk image, and firmware pages often print a long hex string next to the download link. Hash your copy and compare it with that value before you run the file.

What a checksum tells you about a download

A checksum is a short value computed from every byte of a file. Change a single byte and the value changes completely. Publishers print it so you can compute the same value from your copy and compare. A match means your file holds the same bytes as the one they hashed.

A mismatch means something changed on the way: a download that stopped early, a damaged mirror, or a file someone swapped. An installer in that state can fail halfway through, or run code the publisher never shipped.

Hash the file and compare it in your browser

Drop the file on the File Hash Generator. It calculates MD5, SHA-1, SHA-256, SHA-512, SHA3-256, or CRC32 for files up to 50 MB, and up to 20 files at a time. SHA-256 is ticked to start with. A Web Worker reads each file in 4 MB pieces inside your browser, so the page stays responsive and nothing about the file is sent to the server.

Paste the published value into Expected checksum. The row that matches gets a Match badge. If the download page offers a SHA256SUMS or .sha256 file instead, open Verify a checksum list and paste its contents. Both the sha256sum form and the BSD form are read, and files are paired with lines by name, so a line for dist/app.zip still matches a file called app.zip. Press Download checksums to save your own results in the same format.

When a page lists several algorithms, compare the SHA-256 value. MD5, SHA-1, and CRC32 catch accidental damage, but a file can be changed on purpose to keep the same value.

Verify a downloaded file against its checksum

  1. Copy the checksum from the download page and note which algorithm it names.
  2. Open the File Hash Generator and drop the downloaded file on the box.
  3. Tick the same algorithm. SHA-256 is already ticked.
  4. Paste the checksum into Expected checksum.
  5. Look for the Match badge. If it doesn't appear, download the file again and repeat the check.

What a checksum check can't prove

  • Each file can be at most 50 MB. For a disk image or a large archive, run sha256sum, shasum -a 256, or Get-FileHash on your own computer.
  • A match only proves the file equals the value on the page. If the page itself was tampered with, you need a signature check such as GPG.
  • MD5, SHA-1, and CRC32 can be forged on purpose. Prefer SHA-256 when it is offered.
  • In a sha256sum list, a 64-character hash can be SHA-256 or SHA3-256. Both are tried only when both are ticked.

Frequently asked questions

How do I verify a downloaded file?

Drop the file in the File Hash Generator, paste the checksum from the download page into Expected checksum, and look for the Match badge on the row of the same algorithm.

Why doesn't my checksum match?

Either the file was damaged or changed, or the algorithms differ. An MD5 value is 32 hex characters and a SHA-256 value is 64. Check the algorithm, then download the file again.

Is my file uploaded to calculate the checksum?

No. The file is read and hashed inside your browser, and nothing about it is sent to the server.

Which command checks a checksum on my own computer?

sha256sum on Linux, shasum -a 256 on macOS, and Get-FileHash in Windows PowerShell.

Tools used in this guide

  • File Hash GeneratorDeveloper Tools

    Checksums of local files, with a match check and SHA256SUMS verification.

More from the blog

All guides