File checksum verifier
Downloaded an installer and want to be sure it is the real one? Pick the file, paste the published hash and get a straight yes or no.
Guide
How to verify an installer
- On the official download page, find the published checksum, often labelled SHA-256, or a SHA256SUMS file listing every release file.
- Copy the hex string for your exact file and version.
- Here, choose the downloaded file. It is hashed on your machine, up to 200 MB.
- Paste the published value into the compare field and read the verdict badge.
- MATCH: run it. No match after a re-download: do not run it, and tell the project.
Examples
Worked examples
Your workplace requires verified installers. Choose the .msi, paste the vendor's SHA-256 and screenshot the MATCH badge for the change record.
A 150 MB tool keeps crashing on install. Its hash does not match, the download was truncated. Re-downloaded, it matches and installs cleanly. No malware, just a bad connection.
A supplier emails a tool and, separately, its checksum. Hashing the attachment before opening it confirms the file was not swapped in transit.
Method
How it works
Your browser reads the file into memory and computes five digests: SHA-256, SHA-384 and SHA-512 via the Web Crypto API, plus SHA-1 and MD5 for legacy checksums. Whatever you paste is normalised (case, spaces, colons stripped) and compared against all five, so you never need to know which algorithm the publisher chose.
Built by Wolds Cyber, and deliberately serverless: an uploader that hashes your files for you is exactly the kind of tool you should not trust.
FAQ
Frequently asked questions
Why verify a checksum at all?
Two reasons: corruption and tampering. A dropped connection can truncate a download that still opens, and a compromised mirror can serve a modified installer. A matching hash rules out both against the published original.
Do I need to know which algorithm the site used?
No. Paste whatever they published; it is compared against MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at once, and the badge shows which one matched.
Is it safe to pick a sensitive file here?
The file is read by your own browser and hashed on your machine with the Web Crypto API. No upload happens, which you can confirm by going offline first.
The hashes do not match. Now what?
Re-download and check again, transfer corruption is the common cause. If it fails twice from the official source, stop: do not run the file, and report it to the project.
What about very large files?
This page reads the whole file into memory, comfortable up to about 200 MB. For a multi-gigabyte ISO use the built-in commands: certutil -hashfile on Windows, shasum -a 256 on Mac and Linux.
What is a SHA256SUMS file?
A plain text list of hashes and filenames covering every file in a release. Find your file's line, copy the hex string at the start and paste it into the compare field.
More tools