Skip to content
Tools on Deck

How to Verify a File Checksum with SHA-256

4 min read

To verify a file checksum, calculate the file's hash with the same algorithm used by the publisher, then compare the complete hexadecimal values. If the published SHA-256 checksum and your calculated SHA-256 value match exactly, the bytes you received match the bytes used to create that published digest.

The hash generator calculates MD5, SHA-1, SHA-256, SHA-384, and SHA-512 locally. In File mode, add the download and paste the expected value into Compare. The matching row is highlighted with Match; if none of the five results equals it, the page reports No match.

What a file hash tells you

A cryptographic hash function reads an input of any length and produces a fixed-length digest. Change even one byte and the digest will normally change. That makes a checksum useful for detecting an incomplete transfer, storage corruption, an unexpected repackaging, or a file that differs from the one a publisher hashed.

A hash is not an antivirus scan and does not tell you whether matching software is safe. It only establishes equality with the referenced bytes, subject to the properties of the chosen algorithm and the trustworthiness of the published reference. If an attacker can replace both a download and the checksum shown beside it, a match does not protect you.

Obtain the expected checksum from an official page, signed release record, or another channel you trust. Confirm the filename and release version before comparing; two legitimate builds for different operating systems or architectures will have different hashes.

MD5, SHA-1, SHA-256, SHA-384, and SHA-512

MD5 produces 128 bits, SHA-1 produces 160 bits, SHA-256 produces 256 bits, SHA-384 produces 384 bits, and SHA-512 produces 512 bits. Their hexadecimal outputs therefore have different lengths. You must use the algorithm named by the publisher; a SHA-256 value cannot match an MD5 value for the same file because they are different functions and output sizes.

MD5 and SHA-1 have known collision weaknesses and should not be used to secure signatures, certificates, or other adversarial integrity systems. They can still identify accidental changes when a provider publishes only one of those legacy checksums, but they do not provide the collision resistance expected of a modern security choice.

SHA-256 is a common published download checksum and is the sensible default when you control both ends. SHA-384 and SHA-512 produce longer digests and belong to the SHA-2 family as well. A longer displayed value is not a substitute for obtaining it from a trustworthy source.

How to verify a file checksum with Tools on Deck

File hashing remains in your browser. The tool accepts any file up to 2 GB and reads it in 4 MB chunks, updating all five hash algorithms in one pass rather than loading the complete file into page memory.

  1. Open the hash generator and select the File tab.
  2. Drop the downloaded file into the picker or click to browse for it.
  3. Wait for Calculating five hashes to finish; use Cancel only if you want to stop the read.
  4. Copy the expected checksum from the publisher, taking care not to include a filename or label.
  5. Paste the expected value into Compare, which trims whitespace and compares without letter-case differences.
  6. Look for Match on the correct algorithm row; investigate or download again if the page shows No match.

How to compare a SHA-256 checksum correctly

A SHA-256 digest is normally shown as 64 hexadecimal characters. Compare the whole value, not the beginning or ending few characters. The Uppercase switch changes only presentation; hexadecimal letters in uppercase and lowercase represent the same digest, and the Compare box is case-insensitive.

Do not edit, unzip, or resave the file before hashing it. Renaming the file itself does not alter its bytes, but extracting an archive creates different files with their own hashes. Package managers and installers may also transform content, so hash the original downloaded artifact named by the checksum instructions.

If there is no match, first confirm that you chose the right release, platform, and algorithm. Then remove the file and obtain it again from the trusted source. Repeated mismatches can indicate a stale checksum, a changed mirror file, transfer trouble, or unwanted modification; do not simply ignore the result.

Command-line checksum alternatives

Windows includes certutil; run certutil -hashfile file SHA256 in Command Prompt, replacing file with the path. macOS commonly provides shasum, so shasum -a 256 file calculates SHA-256. On many Linux systems, use sha256sum file. Each command prints the digest for comparison with the publisher's value.

Paths containing spaces may need quotation marks, such as certutil -hashfile file SHA256 with a quoted full path or sha256sum "package name.zip". Run the command against the original artifact and ensure the algorithm token is SHA-256 rather than a default you did not intend.

The browser hash generator is convenient when you do not want to open a terminal, while command-line tools fit scripts and release workflows. Either method should produce the same SHA-256 digest for identical bytes.

Checksum mistakes that lead to false conclusions

The most common mistake is comparing values from different algorithms. Another is copying surrounding text such as SHA256: or the filename into the expected field. The Compare placeholder accepts an expected MD5, SHA-1, SHA-256, SHA-384, or SHA-512 digest, but only the digest itself should be pasted.

A successful match can also be overinterpreted. It does not authenticate a checksum copied from an untrusted forum, prove that software contains no malware, or confirm that a signing key is valid. Check signatures when a project provides them, retain normal operating-system protections, and verify that the checksum source belongs to the publisher.

Quick answers about file checksums

Use the exact algorithm named beside the download. For a SHA-256 checksum, calculate SHA-256 over the untouched file and compare all 64 hexadecimal characters. Uppercase versus lowercase does not matter, but every digit does.

A mismatch means the bytes differ from the referenced file. Confirm the release and source, then download again rather than installing a file you expected to match.

Try it free