Verify a file checksum (SHA-256, SHA-1, MD5)

Drop a downloaded file, paste the checksum published by the vendor and see at once whether they match. The file is hashed in your browser and never uploaded.

  • Free
  • No sign-up
  • Runs in your browser
file-checksum-checker

100% private — text and files are hashed in your browser and never uploaded.

How it works

Drop the file

Drop the downloaded file on the box. Files up to 500 MB work.

Paste the expected checksum

Paste the SHA-256, SHA-1 or MD5 from the download page into the compare box.

Read the verdict

A match highlights the row and says the checksum matches. Anything else means the file is not the one published.

How to verify a file checksum

To verify a file checksum, drop the downloaded file on the box above, paste the checksum published on the download page into the compare field, and check that a row is marked as a match. The tool computes MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at once, so it does not matter which one the vendor publishes. The file never leaves your device.

Why check a checksum

A checksum is a fingerprint of a file. If even one bit changed during the download, or someone replaced the file on a mirror, the fingerprint will not match the one published by the vendor. Checking it takes seconds and is the standard way to confirm that an ISO image, installer or firmware is exactly what the publisher released.

Checking from the command line

Commands to compute a SHA-256 checksum
SystemCommand
Windows (PowerShell)Get-FileHash .\file.iso -Algorithm SHA256
Windows (Command Prompt)certutil -hashfile file.iso SHA256
macOSshasum -a 256 file.iso
Linuxsha256sum file.iso

Reading the result

Compare the whole string, not only the first characters. Hexadecimal is not case sensitive, so an uppercase and a lowercase checksum are the same. A mismatch means the file is corrupted or different: download it again, ideally from the official site, and check again. Two consecutive mismatches on the same file are a good reason not to run it.

A checksum is not a signature

A checksum proves the file equals the one whose hash you have, but if an attacker replaced both the file and the checksum on the same page, the check would still pass. Get the checksum from a different channel than the file when you can, or verify the publisher's PGP or code-signing signature for extra assurance.

Private by design

The hash is computed by your own browser with the Web Crypto API (and a built-in routine for MD5, which Web Crypto does not offer). Nothing you type and no file you drop is sent to a server, so it is safe to hash private text and internal files.

Frequently asked questions

Which checksum should I compare, MD5 or SHA-256?
Compare whichever one the publisher gives. SHA-256 is preferred because MD5 and SHA-1 are vulnerable to deliberate collisions; MD5 is fine only to catch accidental corruption.
Is there a file size limit?
Files up to 500 MB are supported. Larger files should be verified with a command-line tool, because your browser has to read the whole file into memory.
Why does the checksum not match?
The download may have been interrupted or corrupted, you may have copied the wrong hash (for example the one for another version or platform), or the file may have been modified. Download it again and repeat the check.
Is this converter free?
Yes. There is no sign-up and no limit, and it runs in your browser, so nothing you type is sent to a server.
Does it work on a phone?
Yes. It works in any modern mobile browser, and the result updates as you type.