Hash Generator (MD5, SHA-256)→Specialized Version
#️⃣

File Checksum Calculator

Calculate file checksums

The file is read in your browser and never uploaded.

SHA-256 checksum
—

File Checksum Calculator

Calculate file checksums to verify file integrity and detect corruption or tampering. Support for MD5, SHA-1, SHA-256, and SHA-512 hashes for comprehensive file verification.

Understanding File Checksums

PurposeHow It Works
Integrity verificationSame file = same hash
Download verificationCompare hash to source
Duplicate detectionIdentical files = identical hash
Tampering detectionAny change = different hash

Common Checksum Algorithms

AlgorithmLengthSpeedUse Case
MD532 charsFastestLegacy, quick checks
SHA-140 charsFastGit, legacy
SHA-25664 charsFastRecommended
SHA-512128 charsModerateMaximum security

Calculate Checksums (Command Line)

``bash # Linux/Mac md5sum filename.zip sha1sum filename.zip sha256sum filename.zip sha512sum filename.zip

# Mac alternative shasum -a 256 filename.zip

# Windows certutil -hashfile filename.zip MD5 certutil -hashfile filename.zip SHA256 `

Calculate Checksums (JavaScript)

`javascript // Browser: File input to hash async function calculateFileHash(file, algorithm = 'SHA-256') { const arrayBuffer = await file.arrayBuffer(); const hashBuffer = await crypto.subtle.digest(algorithm, arrayBuffer); const hashArray = Array.from(new Uint8Array(hashBuffer)); return hashArray.map(b => b.toString(16).padStart(2, '0')).join(''); }

// Usage with file input document.querySelector('input[type="file"]') .addEventListener('change', async (e) => { const file = e.target.files[0]; const hash = await calculateFileHash(file); console.log(SHA-256: ${hash}); });

// Node.js const crypto = require('crypto'); const fs = require('fs');

function calculateFileHashNode(filePath, algorithm = 'sha256') { return new Promise((resolve, reject) => { const hash = crypto.createHash(algorithm); const stream = fs.createReadStream(filePath); stream.on('data', data => hash.update(data)); stream.on('end', () => resolve(hash.digest('hex'))); stream.on('error', reject); }); } `

Verifying Downloads

1. Download the file 2. Get the official checksum from the source 3. Calculate your file's checksum 4. Compare them (must match exactly)

`bash # Verify against expected hash echo "expected_hash_here filename.zip" | sha256sum -c `

When Checksums Don't Match

Possible CauseSolution
Incomplete downloadRe-download
Corrupted fileRe-download
Wrong file versionCheck version
Malicious tamperingDon't use file
Wrong algorithmVerify algorithm used

The Avalanche Effect

A one-character change produces a completely different digest — not a similar one. That property is what makes a hash useful as a fingerprint:

InputMD5CRC32
hello5d41402abc4b2a76b9719d911017c5923610a686
hello.d94c10e437d18531e122ed0b45badd2a0a39d4f1
Hello8b1a9953c4611296a827abf8c47804d7f7d18982
hello and Hello differ by one bit of one byte, and share no part of their output. RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe` — same story.

Digest Length and Collision Resistance

AlgorithmOutputBirthday boundStatus
CRC3232 bits~77,000 valuesChecksum only
MD5128 bits2⁶⁴ in theoryBroken — collisions in seconds
SHA-1160 bits2⁸⁰ in theoryBroken — SHAttered, 2017
RIPEMD-160160 bits2⁸⁰No practical attack
SHA-256256 bits2¹²⁸Current standard
SHA-512512 bits2²⁵⁶Standard, faster on 64-bit
The birthday bound is where a 50% chance of *some* collision appears among random inputs. MD5 and SHA-1 fall far short of theirs because both have practical collision attacks — you can construct two different files with the same digest, which is precisely what a signature must prevent.

Never Hash a Password With These

A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.

Frequently Asked Questions

What is a file checksum?

A checksum is a hash value calculated from a file's contents. Any change to the file produces a different checksum. It's used to verify file integrity: if the checksum matches the expected value, the file hasn't been corrupted or modified. Common algorithms are MD5, SHA-1, and SHA-256.

Which checksum algorithm should I use?

Use SHA-256 for most purposes—it's secure, fast, and widely supported. Use SHA-512 for maximum security. Use MD5 only for legacy compatibility or quick non-security checks (like detecting accidental file corruption). Avoid SHA-1 for new implementations.

Can two different files have the same checksum?

Theoretically yes (called a collision), but practically no for SHA-256. For MD5 and SHA-1, intentional collisions can be created. For SHA-256, no known collisions exist and finding one would require computational resources beyond current capabilities. For file verification, SHA-256 collisions are not a practical concern.

Related Tools

Explore other tools you might find useful:

More Hash Generator (MD5, SHA-256) tools

You might also need