What a checksum actually proves
Computing a file’s hash and comparing it to a published value answers exactly one question: is my copy bit-for-bit identical to the copy the publisher hashed? That’s genuinely useful — it catches truncated downloads, mirror corruption, and in-transit modification. But it’s a narrower guarantee than people assume, because its trustworthiness depends entirely on the hash itself being trustworthy (see the FAQ above). Hold both ideas at once: a matching checksum confirms integrity against a known-good hash, nothing more.
Picking the algorithm — match the publisher
Always verify with the same algorithm the publisher used, since a SHA-256 hash will never match a SHA-512 hash of the same file. This tool auto-detects from the length of the hash you paste:
| Length | Algorithm |
|---|---|
| 32 hex chars | MD5 |
| 40 | SHA-1 |
| 64 | SHA-256 |
| 128 | SHA-512 |
When you get to choose, SHA-256 is the modern default — fast, strong, and universally supported.
Reading a mismatch correctly
A failed match has a small set of likely causes, in rough order of probability:
- Wrong file/version — many projects publish separate hashes per OS and architecture; confirm you grabbed the matching build.
- Corrupted download — re-download; a flipped bit anywhere changes the entire hash.
- Wrong algorithm — you compared a SHA-256 against a SHA-512 value.
- Tampering — if the source and channel are trustworthy and it still fails, don’t run the file.
A frequent false alarm: some tools hash in “text mode” and mangle line endings. This verifier reads the raw bytes (binary), which is the correct, portable behavior — so a mismatch here against a binary-mode sha256sum points to a real difference, not a mode quirk.
Private by design
Hashing happens entirely in your browser via the Web Crypto API (with a JS implementation for MD5, which Web Crypto doesn’t provide). Your file is read locally and never uploaded — safe for proprietary builds, confidential documents, and anything you wouldn’t send to a third-party server. The trade-off is that very large files (1GB+) are bound by your device’s memory and CPU; for those, native shasum / PowerShell Get-FileHash are faster. To compute and compare hashes of text or strings rather than files, the Hash Generator is the companion tool.