SHA-256 Checksum: How to Verify File Integrity
You download a program, a disk image, or a firmware update, and the site shows a long string of hex characters next to the download link. That string is a checksum, and it is your only cheap proof that the file you got is the file the publisher intended. Download pages can be hijacked, mirrors can serve tampered copies, and CDNs can serve corrupted bytes. A SHA-256 checksum lets you verify the file yourself in seconds. Here is what it is, how to verify a file hash on every major operating system, and what to do when the numbers do not match.
What Is a SHA-256 Checksum?
A SHA-256 checksum is the output of running a file through the SHA-256 cryptographic hash function: a fixed 64-character hex string (256 bits) that acts as a fingerprint of the file’s exact contents. Change one byte anywhere in a multi-gigabyte file and the entire checksum changes. Feed the same file to the algorithm twice and you get the identical value every time. That is the contract of a hash function: deterministic for the same input, wildly different for any input that differs by even a single bit.
It is important to be precise about what a checksum proves and does not prove. A SHA-256 checksum verifies integrity: it confirms the bytes you have match the bytes the publisher hashed. It is not authentication. An attacker who can modify the download can also publish their own matching checksum, which is why publishers sign the checksums themselves. Treat a matching hash as “this download is byte-for-byte what was released,” not as “this download is trustworthy.”
How to Verify a File Hash with sha256sum
The core tool is sha256sum, available on Linux and macOS (and in Windows via Git Bash, WSL, or PowerShell’s Get-FileHash). Running it against a file produces a single line: the 64-character hex digest, then the filename.
sha256sum file.iso
a7a5671ffd4bf06619688f4482d1e45c84dc949c96fdd0c97ee159b8fb73bd08 file.iso
To verify a file against the checksum printed on the download page, compute the digest and compare it to the published value character by character, or run sha256sum -c against a .sha256 file that already contains the expected value:
sha256sum -c file.iso.sha256
file.iso: OK
On macOS, shasum -a 256 file.iso is the equivalent command. On Windows, use Get-FileHash file.iso -Algorithm SHA256. All three produce the same digest for the same file, because SHA-256 is a public, standard algorithm.
What Happens When the Hash Does Not Match
If your computed checksum does not match the published one, stop using the file. Do not rationalize the mismatch as a quirk of the download. A mismatch means one of three things, and none of them are “fine”:
- The file was corrupted in transit, for example by a flaky connection or a broken mirror, and may fail to install or crash at runtime.
- The file was modified after release, which happens when a third-party mirror serves a different build than the one the publisher released.
- The file is a trojan or a repackaged build, common when malicious actors replace downloads on mirrors or hijack compromised sites.
The correct move is to delete the file and download it again, preferably from the official site over HTTPS, then re-verify. If it still mismatches, contact the project maintainers, because that is a supply-chain red flag worth reporting.
SHA-256 vs MD5 vs SHA-1
Older tutorials still tell people to verify with MD5 or SHA-1 checksums. Do not. Both algorithms have known collision attacks, and while a collision attack is harder to mount against a downloaded file than it sounds, there is no reason to rely on a weakened algorithm when SHA-256 is just as fast on modern hardware and supported everywhere.
| Algorithm | Digest length | Status | Use |
|---|---|---|---|
| MD5 | 128 bits | Broken | Never for security |
| SHA-1 | 160 bits | Broken | Legacy only |
| SHA-256 | 256 bits | Sound | Standard today |
When a download page offers several checksum formats, pick SHA-256. When it offers only an SHA-1 or MD5 value, prefer a download that ships a .sha256 file, and complain upstream.
Check a Checksum in Seconds
The fastest way to verify a file hash when you do not have a terminal handy is a checksum calculator that runs entirely in your browser. Drop the file into our free file checksum tool, and it computes the SHA-256, SHA-1, and MD5 digests locally, nothing uploaded to a server. You can also use the checksum calculator to compare several files without sending them to a third party.
Compare the resulting SHA-256 checksum to the one printed on the download page. If it matches, install with confidence; if it does not, delete the file and start over. Run the check on every critical download, especially installers, firmware, and anything that will run with elevated privileges. It takes ten seconds and closes a hole in your software supply chain.
Try it now: open the file checksum tool — free, runs entirely in your browser, nothing is uploaded.