File Checksum Calculator (SHA-256, MD5, SHA-1, CRC-32)

Free online file checksum calculator. Get the SHA-256, SHA-512, SHA-1, MD5 or CRC-32 of any file and check it against the published one — in your browser, nothing uploaded.

Runs in your browserNothing uploadedFree · no signup
Drop files here, or click to chooseAny file, any size — an ISO, a .zip, an installer. Read in your browser a few megabytes at a time and never uploaded.

Every ticked checksum is computed in a single pass over the file, so adding one costs arithmetic but not a second read. On a multi-gigabyte file, unticking what you do not need is still the quickest way to finish sooner.

A checksum only proves the file you have is the file that was hashed. It catches a truncated download, a corrupted disk and a mirror serving stale bytes, which is most of what goes wrong. It does not prove who published it: an attacker who can replace the download can usually replace the checksum on the same page. For that you need a signature — a GPG-signed SHA256SUMS.gpg, or the vendor's own code signature — verified against a key you already trust.

CRC-32 is not a hash. It is a 4-byte error-detecting code, the one zip, gzip and PNG store, and it answers "did this transfer cleanly". It is trivial to produce a different file with the same CRC-32, so never use it to decide a file is genuine. MD5 and SHA-1 are broken for collisions too — fine for spotting corruption, and still what a lot of older software publishes, but SHA-256 is the one to trust when you have the choice.

Hashing a large file in a browser is slower than sha256sum on the command line — the work is real arithmetic over every byte, in JavaScript. Nothing is uploaded, and the file is read a few megabytes at a time rather than loaded whole, so a 4 GB ISO costs you patience rather than memory. To hash text rather than a file, use the hash generator; to sign a message with a secret key, the HMAC generator.

Frequently asked questions

Is my file uploaded to check its checksum?
No, and that is the main reason to use this rather than an upload-based checker. The file is read straight off your disk by the browser, a few megabytes at a time, and every digest is computed on your own machine. Nothing is sent anywhere, which also means you can safely check a private archive, a database dump or a signed installer you would never hand to a website.
How big a file can it handle?
There is no fixed limit. The file is read in 4 MB chunks and each one is fed into the running digest and then dropped, so memory stays flat whether the file is 4 KB or 4 GB. That is the whole reason the algorithms are written out here rather than handed to the browser's built-in crypto, which can only digest a buffer you have already loaded whole — a 4 GB ISO would mean 4 GB of memory. Expect a large file to take a while: the work is real arithmetic over every byte, and a browser is slower at it than the sha256sum command.
How do I check a download against the checksum a site published?
Paste it into the compare box. It takes whatever form the publisher used — a bare digest, a SHA256SUMS line like “abc123… ubuntu.iso”, the BSD style “SHA256 (ubuntu.iso) = abc123…”, a Base64 digest of the sort S3 and Azure report, or the entire sums file with a dozen releases in it. The algorithm is worked out from the digest's length, the comparison is made on the underlying bytes so upper- and lower-case hex are the same value, and when you paste a whole sums file each of your files is matched to the line filed under its name.
Which checksum should I use?
SHA-256 unless the publisher gives you something else. MD5 and SHA-1 are both broken for collision resistance, meaning someone can construct two different files with the same digest — that rules them out for deciding a file is genuine, though they are still perfectly good at catching a truncated or corrupted download, and plenty of older software still publishes them. CRC-32 is not a hash at all: it is a 4-byte error-detecting code, the one stored inside zip, gzip and PNG files, and it can be forged by hand in seconds.
The checksum does not match. What now?
Download the file again, ideally from a different mirror, and check it once more — a truncated or interrupted transfer is far and away the most common cause, and the file size alone often gives it away. Also confirm you are comparing against the right line: a release page usually lists several images, and the checksum for the desktop ISO will never match the server one. If a fresh download from a second source still disagrees with the published value, stop and do not run the file.
Does a matching checksum mean the file is safe?
It means the file you have is byte-for-byte the file that was hashed. It does not tell you who did the hashing. If an attacker can replace a download they can usually also edit the checksum printed next to it, so a match on a compromised page proves nothing. What defeats that is a signature: a GPG-signed SHA256SUMS.gpg, or the vendor's own code signature, verified against a key you already trusted beforehand.
Can I compare two files without a published checksum?
Yes. Drop both in at once and, if their SHA-256 digests are the same, they are the same file byte for byte and the tool says so — useful for confirming a copy, a re-download or a backup is intact without needing a reference value from anywhere.