In this article
- What a checksum is
- When it is worth checking
- Step 1: Get the official checksum
- Step 2: Compute the checksum of your file
- Step 3: Compare
- What a checksum does not do
- A complete example
- Comparing without squinting
- Checksum files and signatures
- SHA-256, SHA-1 or MD5?
- If the checksums do not match
- Frequently asked questions
Next to the download button on many software sites there is a long string of letters and numbers labelled SHA-256. It is a checksum: a fingerprint of the file. If your copy produces the same fingerprint, your copy is identical, down to the last bit.
In short: A matching SHA-256 checksum proves your download is identical to the file the publisher described. It takes one command and a comparison.
What a checksum is
SHA-256 is a hash function. It takes any amount of data and produces a fixed 64-character result. The same file always gives the same result, and changing even one bit of the file gives a completely different one. It is not practical to craft a different file with the same SHA-256 hash, which is what makes it useful for verification.
When it is worth checking
- Operating system images and installers, where a corrupted file can cause confusing failures.
- Security-sensitive software such as password managers and cryptocurrency wallets.
- Anything downloaded from a mirror or third-party host rather than the publisher directly.
- Large files moved over unreliable connections or old USB drives.
Step 1: Get the official checksum
Copy the SHA-256 value from the publisher's official website, reached over HTTPS. Take it from the project's own site, not from the same third-party page that hosted the file. An attacker who can swap the file can swap a checksum beside it.
Step 2: Compute the checksum of your file
In your browser
Open the Hash Generator, choose the file under “Or hash a file”, and read the SHA-256 row. The file is read on your device and is not uploaded. This suits files up to 100 MB.
Windows
Open PowerShell in the folder containing the file and run:
Get-FileHash .\filename.iso -Algorithm SHA256
Or, in Command Prompt:
certutil -hashfile filename.iso SHA256
macOS
Open Terminal and run:
shasum -a 256 ~/Downloads/filename.dmg
Linux
sha256sum filename.iso
In each case, replace the file name with your own. Typing the command and then dragging the file into the terminal window fills in the path for you on most systems.
Step 3: Compare
The two values must match exactly. Upper and lower case do not matter, but every character does. Rather than comparing 64 characters by eye, paste both into a text editor on separate lines, or search for the official value within the output.
On Linux and macOS, publishers often provide a checksum file so the comparison can be automatic:
sha256sum -c SHA256SUMS
This prints “OK” beside each file that matches.
What a checksum does not do
A checksum protects against corruption and against a file being swapped somewhere between the publisher and you. It cannot help if the publisher's own website was compromised and both the file and the checksum were replaced. For that, some projects also sign their releases with a cryptographic signature, which proves who produced the file. If a project offers signatures and the software is important to you, verify those as well, following the project's own instructions.
A complete example
Say you downloaded installer.iso and the publisher’s download page lists a SHA-256 value beside it. After running the command for your system, you get a line of 64 characters made up of the digits 0 to 9 and the letters a to f. That is your file’s fingerprint. If it is identical to the published value, character for character, the file is intact. Upper and lower case do not matter: 3A7B… and 3a7b… are the same value.
Comparing without squinting
- Let the computer compare. Paste both values into a text comparison tool such as Text Compare. If it reports no differences, they match.
- Use search. Copy your computed value, open the publisher’s checksum page and use your browser’s Find feature. If the value is found beside your file name, it matches.
- Do not rely on the first and last few characters. It is the habit most people fall into, and it is the one a careful attacker would count on.
Checksum files and signatures
Some projects publish a text file, often named SHA256SUMS, that lists the checksums of all their downloads. Tools such as sha256sum can check a download against it automatically with the --check option. Larger projects also sign that file with a cryptographic key. Verifying the signature confirms that the list of checksums itself came from the project, which closes the gap a plain checksum leaves open: if an attacker can replace the download, they may be able to replace a checksum shown on the same page too. For operating systems and security software, following the project’s signature instructions is worth the extra few minutes.
SHA-256, SHA-1 or MD5?
| Algorithm | Status | Use it for |
|---|---|---|
| SHA-256 | Current standard | Verifying downloads; the right default |
| SHA-512 | Also strong | Fine when the publisher provides it |
| SHA-1 | Deprecated for security | Only if nothing better is published |
| MD5 | Broken for security | Spotting accidental corruption, nothing more |
Researchers have produced different files with the same MD5 and SHA-1 values, so a match with those no longer rules out deliberate tampering. Prefer SHA-256 whenever it is offered.
If the checksums do not match
- Check you compared against the entry for the exact file name and version you downloaded.
- Download the file again. An interrupted or corrupted transfer is the most common cause.
- Make sure the checksum came from the publisher’s own site, not from the page of a mirror.
- If it still differs, do not open or install the file. Tell the publisher.
If you would rather not use a command line, drop the file into the Hash Generator; it is read on your device and not uploaded.
Frequently asked questions
What does it mean if the checksum does not match?
The file is not identical to the one the publisher described. Usually the download was incomplete or corrupted, so delete it and download again from the official source. If it still does not match, do not open the file.
Is MD5 good enough for verifying downloads?
MD5 will detect accidental corruption, but it is not secure against deliberate tampering because matching files can be manufactured. Prefer SHA-256 when the publisher offers it.
Does a matching checksum mean the file is safe?
It means the file is the one the checksum belongs to. If you took the checksum from the genuine publisher over a secure connection, that is strong evidence the file is authentic. It says nothing about whether the software itself is trustworthy.
