How to verify a download with SHA-256 on Windows, macOS and Linux
A SHA-256 checksum is a 64-character fingerprint of a file. If even one byte changes, the fingerprint changes completely. By calculating the checksum of a file you downloaded and comparing it with the value the publisher lists (files hosted here show it on the app page; see how we publish checksums), you can confirm the file arrived complete and unaltered.
Windows
Open PowerShell in the folder that contains the file (Shift + right-click in the folder, then "Open PowerShell window here", or use the Terminal app) and run:
PowerShell
Get-FileHash .\file-name.exe -Algorithm SHA256
To let PowerShell do the comparison for you, paste the expected value between the quotes. The result is True when the checksums match:
PowerShell
(Get-FileHash .\file-name.exe -Algorithm SHA256).Hash -eq "PASTE-EXPECTED-SHA256-HERE"
In the classic Command Prompt, the built-in certutil tool does the same job:
Command Prompt
certutil -hashfile file-name.exe SHA256macOS
Open Terminal, type the command followed by a space, then drag the file into the window to insert its path:
Terminal
shasum -a 256 ~/Downloads/file-name.dmgLinux
Terminal
sha256sum ~/Downloads/file-name.iso
Many projects publish a checksum file such as SHA256SUMS next to their downloads. Put it in the same folder as the file and let sha256sum check everything listed in it; it prints OK for each file that matches:
Terminal
sha256sum -c SHA256SUMS --ignore-missingReading the result
- The values match: the file is identical to the one the checksum was calculated from.
- The values differ: do not open the file. Download it again, ideally from the publisher’s own site; if it still differs, report it.
- Letter case does not matter:
A1B2anda1b2are the same value.
A checksum proves integrity, not trust: it only tells you the file matches the published value. That is why the value should come from a source you trust, such as the publisher’s website. Where a project also offers a digital signature (for example a GPG .asc or .sig file), verifying it gives stronger assurance that the publisher produced the file.
Frequently asked questions
What is the difference between MD5, SHA-1 and SHA-256?
They are all hash functions, but MD5 and SHA-1 are considered broken for security purposes. Use SHA-256 (or stronger) whenever a publisher offers it.
Do I need extra software to check a checksum?
No. Windows (PowerShell and certutil), macOS (shasum) and Linux (sha256sum) all include the necessary tools.
Where do I find the expected checksum?
On the publisher’s download page or in a checksum file next to the download. On this site, files we host show their SHA-256 on the app page; for files that link to the official download elsewhere, use the checksum the publisher lists.
The checksum matches, so is the program safe?
A match shows the file is exactly what was published. It does not judge the program itself, so also make sure you trust the publisher.
More guides
How to create a bootable USB drive (with Ventoy) · How to check SSD and HDD health