Drop the file
Drop the downloaded file on the box. Files up to 500 MB work.
Drop a downloaded file, paste the checksum published by the vendor and see at once whether they match. The file is hashed in your browser and never uploaded.
100% private — text and files are hashed in your browser and never uploaded.
Keep going with your result in another tool. Nothing is uploaded.
Drop the downloaded file on the box. Files up to 500 MB work.
Paste the SHA-256, SHA-1 or MD5 from the download page into the compare box.
A match highlights the row and says the checksum matches. Anything else means the file is not the one published.
To verify a file checksum, drop the downloaded file on the box above, paste the checksum published on the download page into the compare field, and check that a row is marked as a match. The tool computes MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at once, so it does not matter which one the vendor publishes. The file never leaves your device.
A checksum is a fingerprint of a file. If even one bit changed during the download, or someone replaced the file on a mirror, the fingerprint will not match the one published by the vendor. Checking it takes seconds and is the standard way to confirm that an ISO image, installer or firmware is exactly what the publisher released.
| System | Command |
|---|---|
| Windows (PowerShell) | Get-FileHash .\file.iso -Algorithm SHA256 |
| Windows (Command Prompt) | certutil -hashfile file.iso SHA256 |
| macOS | shasum -a 256 file.iso |
| Linux | sha256sum file.iso |
Compare the whole string, not only the first characters. Hexadecimal is not case sensitive, so an uppercase and a lowercase checksum are the same. A mismatch means the file is corrupted or different: download it again, ideally from the official site, and check again. Two consecutive mismatches on the same file are a good reason not to run it.
A checksum proves the file equals the one whose hash you have, but if an attacker replaced both the file and the checksum on the same page, the check would still pass. Get the checksum from a different channel than the file when you can, or verify the publisher's PGP or code-signing signature for extra assurance.
The hash is computed by your own browser with the Web Crypto API (and a built-in routine for MD5, which Web Crypto does not offer). Nothing you type and no file you drop is sent to a server, so it is safe to hash private text and internal files.
More utilities that also run without leaving your browser.