Skip to content
toolsdocks

Verifying a download with SHA-256

2 min read · Updated 3 October 2026

When you download an operating system image, an installer or a large archive, the publisher often lists a checksum: a long string such as

ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad

That is the SHA-256 hash of the file's exact bytes. If even one bit of your copy differs (a broken download, a corrupted disk, a tampered file), its hash will be completely different.

How to check a file

  1. Find the checksum on the publisher's official site (often in a file named SHA256SUMS or next to the download link).
  2. Open the checksum verifier, add your downloaded file and paste the expected value (or drop the SHA256SUMS file).
  3. The tool reads the file on your device and reports Matches or Does not match.

Upper- or lower-case letters do not matter; hashes are hexadecimal and compared case-insensitively.

What a match proves, and what it does not

A match proves your file is identical to the one the checksum was made from. It does not prove that the checksum itself is genuine: if an attacker can change the download page, they can change both. That is why security-conscious projects also sign their checksum files (for example with GPG), and why you should copy the checksum from the official site over HTTPS rather than from a mirror.

Which algorithm?

  • SHA-256 and SHA-512: use these. No practical way is known to create two different files with the same SHA-256 hash.
  • SHA-1: collisions have been produced deliberately (the 2017 "SHAttered" attack), so it should not be trusted against tampering. It still detects accidental corruption.
  • MD5: broken for security purposes since the mid-2000s; fine only for spotting accidental damage.

A worked example

The three-byte text abc always has this SHA-256 hash:

ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad

Change it to abd and the hash shares no visible pattern with the first one. This "avalanche" property is what makes hashes useful for comparison.

Other uses