File Checksum Calculator (SHA-256, MD5, SHA-1, CRC-32)
Free online file checksum calculator. Get the SHA-256, SHA-512, SHA-1, MD5 or CRC-32 of any file and check it against the published one — in your browser, nothing uploaded.
Every ticked checksum is computed in a single pass over the file, so adding one costs arithmetic but not a second read. On a multi-gigabyte file, unticking what you do not need is still the quickest way to finish sooner.
A checksum only proves the file you have is the file that was hashed. It catches a truncated download, a corrupted disk and a mirror serving stale bytes, which is most of what goes wrong. It does not prove who published it: an attacker who can replace the download can usually replace the checksum on the same page. For that you need a signature — a GPG-signed SHA256SUMS.gpg, or the vendor's own code signature — verified against a key you already trust.
CRC-32 is not a hash. It is a 4-byte error-detecting code, the one zip, gzip and PNG store, and it answers "did this transfer cleanly". It is trivial to produce a different file with the same CRC-32, so never use it to decide a file is genuine. MD5 and SHA-1 are broken for collisions too — fine for spotting corruption, and still what a lot of older software publishes, but SHA-256 is the one to trust when you have the choice.
Hashing a large file in a browser is slower than sha256sum on the command line — the work is real arithmetic over every byte, in JavaScript. Nothing is uploaded, and the file is read a few megabytes at a time rather than loaded whole, so a 4 GB ISO costs you patience rather than memory. To hash text rather than a file, use the hash generator; to sign a message with a secret key, the HMAC generator.
Frequently asked questions
- Is my file uploaded to check its checksum?
- No, and that is the main reason to use this rather than an upload-based checker. The file is read straight off your disk by the browser, a few megabytes at a time, and every digest is computed on your own machine. Nothing is sent anywhere, which also means you can safely check a private archive, a database dump or a signed installer you would never hand to a website.
- How big a file can it handle?
- There is no fixed limit. The file is read in 4 MB chunks and each one is fed into the running digest and then dropped, so memory stays flat whether the file is 4 KB or 4 GB. That is the whole reason the algorithms are written out here rather than handed to the browser's built-in crypto, which can only digest a buffer you have already loaded whole — a 4 GB ISO would mean 4 GB of memory. Expect a large file to take a while: the work is real arithmetic over every byte, and a browser is slower at it than the sha256sum command.
- How do I check a download against the checksum a site published?
- Paste it into the compare box. It takes whatever form the publisher used — a bare digest, a SHA256SUMS line like “abc123… ubuntu.iso”, the BSD style “SHA256 (ubuntu.iso) = abc123…”, a Base64 digest of the sort S3 and Azure report, or the entire sums file with a dozen releases in it. The algorithm is worked out from the digest's length, the comparison is made on the underlying bytes so upper- and lower-case hex are the same value, and when you paste a whole sums file each of your files is matched to the line filed under its name.
- Which checksum should I use?
- SHA-256 unless the publisher gives you something else. MD5 and SHA-1 are both broken for collision resistance, meaning someone can construct two different files with the same digest — that rules them out for deciding a file is genuine, though they are still perfectly good at catching a truncated or corrupted download, and plenty of older software still publishes them. CRC-32 is not a hash at all: it is a 4-byte error-detecting code, the one stored inside zip, gzip and PNG files, and it can be forged by hand in seconds.
- The checksum does not match. What now?
- Download the file again, ideally from a different mirror, and check it once more — a truncated or interrupted transfer is far and away the most common cause, and the file size alone often gives it away. Also confirm you are comparing against the right line: a release page usually lists several images, and the checksum for the desktop ISO will never match the server one. If a fresh download from a second source still disagrees with the published value, stop and do not run the file.
- Does a matching checksum mean the file is safe?
- It means the file you have is byte-for-byte the file that was hashed. It does not tell you who did the hashing. If an attacker can replace a download they can usually also edit the checksum printed next to it, so a match on a compromised page proves nothing. What defeats that is a signature: a GPG-signed SHA256SUMS.gpg, or the vendor's own code signature, verified against a key you already trusted beforehand.
- Can I compare two files without a published checksum?
- Yes. Drop both in at once and, if their SHA-256 digests are the same, they are the same file byte for byte and the tool says so — useful for confirming a copy, a re-download or a backup is intact without needing a reference value from anywhere.