What Is a Checksum, and Why You Should Use One to Verify Downloads
Every time you download software, you're trusting that the file you received is exactly the file the publisher uploaded — not a corrupted copy, and not something an attacker swapped in along the way. A checksum is the simple, decades-old tool that lets you verify that trust instead of just assuming it.
What a Checksum Actually Is
A checksum (also called a hash) is a fixed-length string of letters and numbers generated by running a file through a mathematical function — commonly SHA-256 or SHA-512. The same input always produces the same output, and changing even a single byte of the file completely changes the result. That makes a checksum a reliable fingerprint: if two files produce the same hash, they are, for all practical purposes, identical.
This is different from a password hash used for authentication. A checksum isn't secret and isn't meant to be — its whole purpose is to be published openly so anyone can compare it against their own copy of the file.
Why It Matters
Reputable software projects and Linux distributions publish a checksum alongside every download, usually on the same page or in a .sha256 file. Comparing it against the file you actually received catches two different problems:
- Corruption: a download that was interrupted or damaged in transit will produce a different hash, even if the file appears to open fine.
- Tampering: if a mirror or a compromised download link serves a modified file — say, one bundled with malware — its checksum won't match the one the original publisher posted, giving you an immediate red flag before you run anything.
It's a small habit, but for install scripts, disk images, and any executable you're about to run with elevated permissions, it's the difference between trusting a source and verifying it.
How to Check One
Most operating systems have a built-in way to generate a hash from the command line — certutil -hashfile on Windows, shasum on macOS, and sha256sum on Linux. The process is always the same:
- Download the file and note the checksum published by the source.
- Run the file through the same hash algorithm on your machine.
- Compare the two strings character by character. If they match exactly, the file is intact and unmodified.
The same idea is useful beyond downloads, too — verifying that a code snippet, license key, or block of text matches an expected value, or generating a quick hash to reference in documentation. Our Hash Generator computes SHA-1, SHA-256, SHA-384, and SHA-512 hashes of any text you paste in, entirely in your browser using the Web Crypto API — nothing is sent to a server.