How-to guide

How to verify a download with SHA-256 on Windows, macOS and Linux

A SHA-256 checksum is a 64-character fingerprint of a file. If even one byte changes, the fingerprint changes completely. By calculating the checksum of a file you downloaded and comparing it with the value the publisher lists (files hosted here show it on the app page; see how we publish checksums), you can confirm the file arrived complete and unaltered.

Windows

Open PowerShell in the folder that contains the file (Shift + right-click in the folder, then "Open PowerShell window here", or use the Terminal app) and run:

PowerShell

Get-FileHash .\file-name.exe -Algorithm SHA256

To let PowerShell do the comparison for you, paste the expected value between the quotes. The result is True when the checksums match:

PowerShell

(Get-FileHash .\file-name.exe -Algorithm SHA256).Hash -eq "PASTE-EXPECTED-SHA256-HERE"

In the classic Command Prompt, the built-in certutil tool does the same job:

Command Prompt

certutil -hashfile file-name.exe SHA256

macOS

Open Terminal, type the command followed by a space, then drag the file into the window to insert its path:

Terminal

shasum -a 256 ~/Downloads/file-name.dmg

Linux

Terminal

sha256sum ~/Downloads/file-name.iso

Many projects publish a checksum file such as SHA256SUMS next to their downloads. Put it in the same folder as the file and let sha256sum check everything listed in it; it prints OK for each file that matches:

Terminal

sha256sum -c SHA256SUMS --ignore-missing

Reading the result

  • The values match: the file is identical to the one the checksum was calculated from.
  • The values differ: do not open the file. Download it again, ideally from the publisher’s own site; if it still differs, report it.
  • Letter case does not matter: A1B2 and a1b2 are the same value.

A checksum proves integrity, not trust: it only tells you the file matches the published value. That is why the value should come from a source you trust, such as the publisher’s website. Where a project also offers a digital signature (for example a GPG .asc or .sig file), verifying it gives stronger assurance that the publisher produced the file.

Frequently asked questions

What is the difference between MD5, SHA-1 and SHA-256?

They are all hash functions, but MD5 and SHA-1 are considered broken for security purposes. Use SHA-256 (or stronger) whenever a publisher offers it.

Do I need extra software to check a checksum?

No. Windows (PowerShell and certutil), macOS (shasum) and Linux (sha256sum) all include the necessary tools.

Where do I find the expected checksum?

On the publisher’s download page or in a checksum file next to the download. On this site, files we host show their SHA-256 on the app page; for files that link to the official download elsewhere, use the checksum the publisher lists.

The checksum matches, so is the program safe?

A match shows the file is exactly what was published. It does not judge the program itself, so also make sure you trust the publisher.

← All how-to guides