Skip to content

File hash and checksum verifier

Check a downloaded file against its published checksum — MD5, SHA-1, SHA-256 or CRC32.

Drop your file here

It is processed on your device — nothing is uploaded.

Up to 1024 MB · free · no signup
    Paste the checksum from the download page and this will tell you plainly whether it matches.

    What a checksum is actually for

    Two different things, and the difference matters. Against accidental corruption — a truncated download, a bad disk, a flaky mirror — any checksum works, including CRC32. Against deliberate tampering, only a cryptographic hash helps, and only if you got the expected value from somewhere the attacker does not control. A SHA-256 published on the same compromised page as the file proves nothing.

    Both uses are legitimate. It is just worth knowing which one you are doing.

    Paste the checksum and get a plain answer

    The comparison field takes whatever you copied from the download page — spaces, capitals, a leading filename, all fine — and tells you match or no match rather than leaving you to compare sixty-four hex characters by eye. That is the part people get wrong: eyes check the first four characters and the last four and skip the middle, which is exactly where a difference would be.

    If the checksum you paste is not the same length as the algorithm selected, it says so rather than reporting a mismatch, because the usual reason a SHA-256 does not match is that it was actually an MD5.

    Why MD5 is here at all

    MD5 has been broken for collision resistance since 2004, and nothing new should use it. WebCrypto does not implement it, deliberately. But this tool exists to check files against what projects have already published, and a great many still publish only an MD5. A checksum tool that cannot check the checksum you actually have is not much use, so it is implemented here directly — and verified against a real implementation on every build, from an empty input to a two-hundred-kilobyte binary blob.

    For verifying that a download completed intact, MD5 is entirely adequate. For verifying that a download has not been tampered with, use SHA-256 and get the expected value from somewhere independent.

    Nothing is uploaded — which is the point

    Most online checksum tools ask you to upload the file. Think about what that means: to check that a 900 MB installer arrived intact, you would send all 900 MB to a stranger's server. Here the file is read straight from disk by the page and hashed in memory. There is no upload request, so there is no bandwidth cost, no queue and no file sitting on someone else's machine.

    Comparing two files

    A hash is also the fastest way to know whether two files are byte-for-byte identical — quicker and more reliable than comparing sizes and dates, which match constantly on files that differ. Hash both and compare the results.

    The command line equivalents

    If you would rather do this locally: sha256sum file on Linux, shasum -a 256 file on macOS, and Get-FileHash file in PowerShell on Windows. All three produce exactly what this page does.

    01

    Common questions

    Which algorithm should I use?

    SHA-256 if the project publishes one. MD5 only if that is all you have — it is fine for detecting a corrupt download and inadequate against deliberate tampering.

    My checksum does not match. What now?

    Download the file again, ideally from a different mirror. A mismatch is far more often a truncated or interrupted download than an attack.

    Is my file uploaded?

    No. It is read from disk and hashed in your browser. Nothing is sent anywhere, which is why there is no size queue or daily limit.

    Why is MD5 still offered if it is broken?

    Because plenty of projects still publish only an MD5, and a tool that cannot check the checksum you have is no help. It is broken for collision resistance, not for spotting a corrupt download.

    How big a file can it handle?

    Up to about a gigabyte in the browser, since the file has to be held in memory to be hashed. Beyond that, use sha256sum, shasum or Get-FileHash locally.

    Can I check whether two files are identical?

    Yes, and it is the most reliable way. Hash both and compare — matching sizes and timestamps prove nothing.