File Hash Calculator — Verify Downloads with MD5, SHA-1, SHA-256, SHA-512

Drag and drop a file to instantly calculate its MD5, SHA-1, SHA-256, and SHA-512 hashes. Compare against the checksum published by the source to confirm your download is not corrupted or tampered with. Files are never uploaded to a server.

Hash Algorithm Comparison

Algorithm Output Size Hex Characters Typical Use
MD5 128-bit 32 chars Lightweight integrity checks only — cryptographically broken, unsuitable for passwords or digital signatures
SHA1 160-bit 40 chars Safer than MD5, but collision attacks are proven. Still used for non-security purposes like Git commit hashes
SHA256 256-bit 64 chars Currently considered secure — the standard choice for verifying software download integrity
SHA512 512-bit 128 chars Even longer output than SHA-256; can be faster on 64-bit CPUs

What Is a File Hash?

A hash is a fixed-length string calculated from an entire file's contents — essentially a fingerprint for that file. Change even a single byte and the value comes out completely different, so comparing it against the value published by the source lets you confirm your download wasn't corrupted or tampered with. This tool computes MD5, SHA-1, SHA-256, and SHA-512 all at once as soon as you drop in a file.

Everything is computed in your browser, so the file's contents are never sent anywhere. That said, the whole file is loaded into memory, so multi-gigabyte files can be slow or fail outright. Also, MD5 and SHA-1 both have proven collision attacks, so neither is suitable for detecting malicious tampering.

How to Verify a File Hash

  1. Drop in the file Drag the file you want to check into the box, or click to select it. For large files, keep the tab open until the computation finishes.
  2. Check the hash values Results for all four algorithms appear side by side. Look for whichever one matches the algorithm the source publishes.
  3. Compare against the published value Paste the hash from the official site into the comparison field, and it automatically detects which algorithm matches.
  4. Don't use the file if it doesn't match First check for a copy-paste mistake. If it still doesn't match, delete the file without running it and download it again from the official source.

Tips for getting more out of it

  • If the source does not specify which algorithm was used, just paste the hash into the comparison field — it automatically detects the matching algorithm.
  • Large files (hundreds of MB or more) use significant browser memory, so computation may take several seconds to a minute. Keep the tab open while it works.
  • Verifying hashes is especially worthwhile for high-impact files like ISO images and installers, where tampering could cause serious harm.
  • MD5 and SHA-1 have proven collision attacks, so they are unsuitable for detecting malicious tampering. Use SHA-256 or higher for security-sensitive checks.

Where File Hash Verification Comes in Handy

Verifying ISO images and installers

OS images and executables can cause serious damage if tampered with. Make it a habit to compare against the official hash before running anything.

Catching transfer errors on large files

Confirm a file received over a shaky connection isn't missing any data — far more reliable than just checking the file size.

Confirming a backup matches the original

Compare the hash of a copied or moved file against the original to verify the contents are byte-for-byte identical.

Spotting duplicate files

If two files have different names but the same hash, their contents are identical — a solid basis for deciding which copies to clean up.

Hash-Related Terms

Hash value
A fixed-length string calculated from data. The same input always produces the same value.
Checksum
A published value used to confirm a file hasn't been corrupted. Hash values are widely used for this purpose.
Collision
When two different pieces of data produce the same hash value. This has been shown to be intentionally achievable for MD5 and SHA-1.
Avalanche effect
The property where a tiny change in input produces a completely different output — the basis for detecting even minor corruption.
SHA-256
An algorithm that produces a 256-bit hash. Currently the most widely used standard for verifying downloads.

Frequently Asked Questions

First double-check the official hash for copy-paste mistakes, like a stray newline or extra space. If it still does not match, the file may be corrupted or tampered with — delete it without running it and re-download from the official source.

Match whichever algorithm the source publishes. If several are listed, prefer the stronger SHA-256 or SHA-512. MD5 and SHA-1 are no longer cryptographically secure and are insufficient for detecting malicious tampering.

The algorithms are identical — only the input differs (binary file vs. text string). To hash a text string instead, use our sister tool, the all-in-one string hash calculator.

Yes, as long as your browser has enough available memory — the entire file is loaded into memory at once, so multi-gigabyte files may slow down or fail in some browsers.
Tool-kun

Side Note — Why Official Sites Publish Hash Values

You may have noticed a hash value like "SHA256: a1b2c3..." listed next to a download link on a software site. This lets users verify for themselves that the file is exactly what the publisher created, with no corruption during transfer or tampering on a mirror server.

This matters most for Linux distribution ISO images, which are often downloaded from mirror servers scattered around the world. Beyond ordinary transmission errors, there is a theoretical risk that a malicious actor could compromise a mirror and distribute a tampered copy containing malware. When the official site publishes a signed list of hashes (often with a GPG signature), users can verify safety from any mirror simply by computing the hash locally and comparing it.

Hash functions have an "avalanche effect" — changing even a single bit of input produces a completely different output. This reliably catches both deliberate tampering and subtle corruption from a bad download. Even if two files are the same size, differing by just one byte produces an entirely different hash, making this far more reliable than eyeballing file sizes.