Checksum Calculator & Verifier

Hash files of any size with MD5, SHA-1, SHA-256, SHA-384 and SHA-512. Export a manifest, verify a published hash, or check a whole folder against a .sha256 or .md5 file.

Calculator Media & Files Updated Oct 5, 2026
How to Use
  1. Choose Calculate to hash files, Verify a hash to check one file against a published value, or Check a manifest to test many files against a .sha256 or .md5 list.
  2. Drop one or more files (or a whole folder), or type text into the box to hash it as UTF-8.
  3. Tick the algorithms you need. In Verify mode, paste the expected hash: its length picks the algorithm (32 characters = MD5, 64 = SHA-256).
  4. Read the result in the readouts and the table. Click a hash to copy it.
  5. In Calculate mode, download the results as a sha256sum/md5sum file, BSD tags, TSV or JSON. The Show Work section explains how your own file was padded and hashed.
Input
Drop files or a folder, or
Any type, any size — read on your device, never uploaded
UTF-8
algorithm from length
sha256sum, md5sum, BSD, TSV or JSON
Presets
Hash Visualization
Files
—
Total size
—
Fingerprint
—
Time
—

Worked Example

Hashing the three bytes “abc”. SHA-256 works on 64-byte blocks, so the 3 bytes are padded: one 0x80 byte, then (55 − 3) = 52 zero bytes, then the length, 24 bits, as an 8-byte number. 3 + 1 + 52 + 8 = 64 bytes, exactly one block. Its SHA-256 is ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad and its MD5 is 900150983cd24fb0d6963f7d28e17f72 — the published test values in FIPS 180 and RFC 1321.

Verifying a download. A publisher lists a 64-character hash, so the algorithm is SHA-256 (64 × 4 = 256 bits). The tool hashes your file with SHA-256 and compares all 64 characters. One wrong character anywhere means Mismatch: the tool reports the first position that differs, and the file should be downloaded again.

The common mistake: a hidden newline. The SHA-256 of the five bytes “hello” is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824. echo hello | sha256sum hashes six bytes, “hello” and a line feed, and prints 5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03. Saved by a Windows editor with CRLF it is seven bytes and cd2eca3535741f27a8ae40c31b0c41d4057a7a7b912b33b9aed86485d1c84676. All three are correct; they are hashes of different bytes.

Show Work

Choose a file or a preset to see how it was padded, read and hashed.

Formulas

Padding: MD5, SHA-1, SHA-256
zeros = (55 − n) mod 64
n data bytes + 0x80 + zeros + an 8-byte length fill whole 64-byte blocks
Blocks: MD5, SHA-1, SHA-256
blocks = ⌊(n + 8) / 64⌋ + 1
3 bytes is 1 block; 56 bytes already needs 2
Padding: SHA-384, SHA-512
zeros = (111 − n) mod 128
128-byte blocks with a 16-byte length field
Hash length
hex chars = bits / 4
MD5 32, SHA-1 40, SHA-256 64, SHA-384 96, SHA-512 128
Chunks read
chunks = ⌈n / 4,194,304⌉
Files over 256 MiB are streamed 4 MiB at a time
Collision work (ideal)
effort ≈ 2bits/2
2128 for SHA-256; SHA-1 fell to about 263 in 2017

From MD5 to SHA-2

MD5 was designed by Ron Rivest and published as RFC 1321 in April 1992. The US National Security Agency designed SHA-1, which NIST published as FIPS 180-1 in 1995, and the SHA-2 family — SHA-256, SHA-384 and SHA-512 — followed in FIPS 180-2 in August 2002. All of them use the same plan: pad the message to whole blocks, then mix each block into a fixed-size internal state.

MD5’s collision resistance fell in 2004, when Xiaoyun Wang and colleagues showed two different inputs with the same MD5. SHA-1 followed in February 2017, when Google and CWI Amsterdam published two different PDF files with the same SHA-1 (the “SHAttered” attack). NIST announced in December 2022 that SHA-1 should be phased out by the end of 2030. SHA-256 and SHA-512 have no known practical attacks and are what download pages, package managers and Git’s newer object format use.

About This Tool

This calculator hashes one file, a whole folder or a piece of text with MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at once, checks a file against a published hash, and checks a set of files against a sha256sum or md5sum manifest. It replaces the separate File Hasher and Checksum Verifier.

Every algorithm is implemented to work incrementally, so a file of any size is read in 4 MiB pieces and never held in memory whole; files up to 256 MiB use the browser’s Web Crypto for the SHA family. Everything runs in a background thread on your device. Nothing is uploaded, which makes it safe for private keys, contracts and evidence files.

It is for anyone who downloads installers and disk images, keeps backups, hands files to clients or needs a record that a file has not changed.

Related tools: SHA-256 Hash Generator, File Merger & Joiner, and ZIP & Unzip Tool.

Frequently Asked Questions

How do I verify the checksum of a download?

Choose Verify a hash, drop the downloaded file and paste the hash from the publisher’s site. The length of the hash tells the tool which algorithm to use: 32 hex characters is MD5, 40 is SHA-1, 64 is SHA-256, 96 is SHA-384 and 128 is SHA-512. If even one character differs you get Mismatch and the position of the first difference, which means the file is damaged, incomplete or not the file that was published.

Why does my hash of a word not match the one from the command line?

Usually a hidden newline. The SHA-256 of “hello” is 2cf24dba…, but echo hello | sha256sum hashes “hello” plus a line feed and gives 5891b5b5…, and a Windows file saved with CRLF gives cd2eca35…. Every byte counts, so tick “End with a newline” and pick the line ending to reproduce what the other program hashed.

Are MD5 and SHA-1 still safe to use?

For catching accidental damage, yes: a flipped bit changes about half of the output bits. Against an attacker, no. Xiaoyun Wang’s team published MD5 collisions in 2004, and in 2017 Google and CWI Amsterdam produced two different PDF files with the same SHA-1 after about 9.2 quintillion (263) SHA-1 computations. Use SHA-256 or SHA-512 when someone could deliberately swap the file.

Is there a file size limit?

No fixed one. Files over 256 MiB are read in 4 MiB chunks and every algorithm is updated chunk by chunk, so memory stays at a few megabytes. Speed depends on your computer: about 150 MB/s for SHA-256 in JavaScript means a 4.7 GB DVD image takes roughly 31 seconds. Smaller files use the browser’s built-in Web Crypto for the SHA family, which is faster still.

How do I check a folder against a sha256sum file?

Choose Check a manifest and drop the folder together with the .sha256 (or .md5, .sha1, .sha512) file, or paste the manifest text. GNU lines (hash name), BSD lines (SHA256 (name) = hash) and this tool’s own TSV and JSON exports are all read. Each file is marked matched, mismatched, missing or not listed, just like sha256sum -c. Your files are never uploaded.

How do I use the Checksum Calculator & Verifier?

Simply type your numbers and read the result, which refreshes the instant you change something. There is nothing to submit and nothing to wait for.

Does it cost anything or need an account?

No. The tool is completely free, there is no account to create, and it keeps working offline after the page first loads.

Is anything I type uploaded?

No. The tool works entirely on your device, so the values you enter never leave your browser.

Common Use Cases

Verify a Linux ISO

A 6 GB installer image is read in 1,431 chunks of 4 MiB and checked against the 64-character SHA-256 from the distribution’s SHA256SUMS file.

Backup and bit-rot checks

Hash 2,000 photos once, keep the sha256sum file with the backup, and re-check it next year: any file that comes back Mismatch has changed on disk.

Spot duplicate files

Drop three exports and the readout shows 2 unique contents: two of them are byte-for-byte identical, whatever their names say.

Hand-off to a client

Send 12 deliverables with a checksums.sha256 file so the client can confirm every one arrived intact with a single command.

Evidence records

Record MD5, SHA-1 and SHA-256 of an evidence file at the moment it is collected; a single changed byte later gives completely different values.

Last updated: