ToolboxKit

What Is a Checksum, and Why You Should Use One to Verify Downloads

Every time you download software, you're trusting that the file you received is exactly the file the publisher uploaded — not a corrupted copy, and not something an attacker swapped in along the way. A checksum is the simple, decades-old tool that lets you verify that trust instead of just assuming it.

What a Checksum Actually Is

A checksum (also called a hash) is a fixed-length string of letters and numbers generated by running a file through a mathematical function — commonly SHA-256 or SHA-512. The same input always produces the same output, and changing even a single byte of the file completely changes the result. That makes a checksum a reliable fingerprint: if two files produce the same hash, they are, for all practical purposes, identical.

This is different from a password hash used for authentication. A checksum isn't secret and isn't meant to be — its whole purpose is to be published openly so anyone can compare it against their own copy of the file.

Why It Matters

Reputable software projects and Linux distributions publish a checksum alongside every download, usually on the same page or in a .sha256 file. Comparing it against the file you actually received catches two different problems:

  • Corruption: a download that was interrupted or damaged in transit will produce a different hash, even if the file appears to open fine.
  • Tampering: if a mirror or a compromised download link serves a modified file — say, one bundled with malware — its checksum won't match the one the original publisher posted, giving you an immediate red flag before you run anything.

It's a small habit, but for install scripts, disk images, and any executable you're about to run with elevated permissions, it's the difference between trusting a source and verifying it.

How to Check One

Most operating systems have a built-in way to generate a hash from the command line — certutil -hashfile on Windows, shasum on macOS, and sha256sum on Linux. The process is always the same:

  1. Download the file and note the checksum published by the source.
  2. Run the file through the same hash algorithm on your machine.
  3. Compare the two strings character by character. If they match exactly, the file is intact and unmodified.

The same idea is useful beyond downloads, too — verifying that a code snippet, license key, or block of text matches an expected value, or generating a quick hash to reference in documentation. Our Hash Generator computes SHA-1, SHA-256, SHA-384, and SHA-512 hashes of any text you paste in, entirely in your browser using the Web Crypto API — nothing is sent to a server.