Skip to content
Engyna

Privacy & security

How to Verify a File Checksum (SHA-256)

Download pages often list a SHA-256 hash. Here's what it proves, how to compute one on Windows, macOS, Linux or in the browser, and how to compare the result.

Updated · 3 min read

Downloads of operating systems, installers and firmware often come with a line like:

SHA-256: 3a7bd3e2360a3d29eea436fcfb7e44c735d117c42d1c1835420b6b9942dd4f1b

That long string is a checksum, and comparing it takes less than a minute.

What a checksum proves

A cryptographic hash function like SHA-256 reads a file and produces a fixed-length value. Two properties matter:

  • The same file always gives the same value.
  • Changing a single bit gives a completely different value, and it's practically impossible to craft a different file with the same SHA-256.

So if your downloaded file has the same SHA-256 as the one published by the developer, the file is complete (no broken download) and unmodified.

One caveat: this only helps if the checksum itself comes from a trustworthy source. If an attacker controls the download page, they can replace both the file and the checksum. Checksums published on the official site over HTTPS, or signed by the developer, are what you want.

Check a checksum in your browser

  1. Open the checksum checker.
  2. Drop the downloaded file. Even multi-gigabyte files work, because they're read in chunks. The file isn't uploaded.
  3. Paste the expected value. The tool recognizes the algorithm by its length: 64 hex characters for SHA-256, 128 for SHA-512, 40 for SHA-1, 32 for MD5.
  4. It shows clearly whether the values match.

You can also drop several files at once, or compare two files with each other to see if they're identical.

Built-in commands

Windows (PowerShell):

Get-FileHash .\file.iso -Algorithm SHA256

or in the Command Prompt:

certutil -hashfile file.iso SHA256

macOS (Terminal):

shasum -a 256 file.dmg

Linux:

sha256sum file.iso

If you have a .sha256 file with the expected values, sha256sum -c file.sha256 checks automatically on Linux.

MD5, SHA-1, SHA-256: which to trust?

Algorithm Length (hex) Use today
MD5 32 Detects accidental corruption only
SHA-1 40 Detects accidental corruption only
SHA-256 64 Recommended
SHA-512 128 Recommended

MD5 and SHA-1 have known collision attacks: it's possible to deliberately create two different files with the same value. For verifying downloads against tampering, use SHA-256 or better.

When the checksum doesn't match

  1. Re-download the file. Interrupted or corrupted downloads are the most common cause.
  2. Check the algorithm. A SHA-1 value will never match a SHA-256 result.
  3. Check you copied the whole value, without extra spaces.
  4. Check the file version. Mirrors sometimes host a newer build than the checksum on the page.

If it still doesn't match, don't run the file.

Hashing text

To hash a string instead of a file, for example to compare API signatures, the UUID & hash generator computes SHA-256 and other hashes of text.

Frequently asked questions

Is a checksum the same as a digital signature? No. A checksum only proves that two copies are identical. A signature (for example GPG or code signing) also proves who created the file. Some projects publish both: a signed file that contains the checksums.

Does a matching checksum mean the file is safe? It means the file is exactly what the publisher released. It doesn't say anything about whether that release is trustworthy.

How long does hashing take? Hashing is fast. A multi-gigabyte ISO file usually takes seconds to about a minute, depending on your device and storage.