← Blog

SSH Key Fingerprints: What They Are and How to Check Them

The first time you connect to a new server over SSH, your client prints a long string of hex characters and asks whether you want to trust it. Most people type “yes” without reading a thing. That prompt is not a formality; it is the only defense you have against man-in-the-middle attacks. The string on your screen is the server’s SSH key fingerprint, and knowing how to check it is what separates a secure connection from one that silently connects to the wrong machine.

What Is an SSH Key Fingerprint?

An SSH key fingerprint is a short hash of a much longer public key, designed for humans to compare. SSH keys are 2048 to 4096 bits long, far too unwieldy to eyeball. The fingerprint reduces that key to a compact digest, usually 32 bytes (SHA-256), that is effectively unique to the key. When you see SHA256:mPjD3l... in an SSH prompt, that is the fingerprint of the server’s host key, not the key itself.

Every SSH server presents a host key to prove its identity. The key is generated on first install, stored in /etc/ssh/ssh_host_*_key, and is supposed to remain stable for the life of the server. Your client remembers the fingerprint the first time you accept it and stores it in ~/.ssh/known_hosts. On every later connection it compares the presented fingerprint against the remembered one. If the server’s key changed, you get an alarming warning and the connection is refused.

A mismatch means one of three things: the server was reinstalled and generated a new host key, the administrator rotated the key, or you are talking to a different machine entirely, which is what happens in a man-in-the-middle attack. Verifying the fingerprint against a trusted source is the only way to tell the difference.

How to Check a Host Key Fingerprint with ssh-keygen -lf

The standard tool for inspecting fingerprints is ssh-keygen. Point it at a public key file with the -l (list) and -f (file) flags, and it prints the fingerprint:

ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub
256 SHA256:hXtOT5o6EgLjDwMKYg6tFSzF68KmYl0t/clM74lq2D4  root@server (ED25519)

The same command works on your own keys:

ssh-keygen -lf ~/.ssh/id_ed25519.pub

By default ssh-keygen -lf prints the SHA-256 fingerprint, which is what modern OpenSSH clients display. Add -E md5 to get the older 128-bit MD5 format used by legacy systems:

ssh-keygen -lf ~/.ssh/id_ed25519.pub -E md5
256 MD5:55:94:7d:ee:fc:4c:01:01:bf:41:80:52:48:89:53:be root@server (ED25519)

To get the same fingerprint for a running server, use ssh-keyscan to fetch its host keys and pipe them through ssh-keygen -lf:

ssh-keyscan server.example.com 2>/dev/null | ssh-keygen -lf -

Reading a Fingerprint: Algorithm Prefixes

Modern fingerprints carry an algorithm prefix that tells you which host key you are looking at. Servers publish several keys, and matching the right one matters:

Prefix Algorithm Recommendation
ED25519 EdDSA Prefer when available
ECDSA NIST curve ECDSA Good, widely supported
RSA 2048/4096-bit RSA Acceptable for compatibility

The SHA256: prefix on the fingerprint itself identifies the hash algorithm, not the key algorithm. When a server shows you an ED25519 fingerprint, verify it against the ED25519 host key published by the administrator, not the RSA one.

Verifying a Server’s Fingerprint Before First Login

The verification workflow is short. Before you accept a new host key, do this:

  1. SSH into the server from a trusted network, or use ssh-keyscan to fetch the host key fingerprint.
  2. Ask the administrator for the fingerprint, or compare it against the one printed in the server console, in the cloud provider’s metadata page, or on the team’s password manager entry.
  3. Run ssh-keygen -lf on the fetched key and compare the output to the published value, character by character.
  4. Only when they match, accept the connection and let the fingerprint land in known_hosts.

You can also inspect a public key file without any keys at hand using our SSH fingerprint tool: paste the .pub file’s contents and get the SHA-256 and MD5 fingerprints instantly, computed locally in the browser.

Check the Fingerprint Before You Trust It

The entire security model of SSH depends on the host key being genuine. If you accept a fingerprint without verifying it, an attacker who controls the network can serve you a fake key, capture your password or private key material, and relay your session. That first “yes” is the whole game.

Next time you connect to a fresh server, take ten seconds to check the host key fingerprint against a trusted source using the SSH fingerprint tool before you type “yes”. It is the cheapest protection you will ever add to your SSH workflow.

Try it now: open the ssh fingerprint tool — free, runs entirely in your browser, nothing is uploaded.