SHA256 file checksum: verify a file on any OS
One command per operating system tells you whether the file you downloaded is the file the author published. Below: the command for Windows, macOS and Linux, how to compare your digest against the published hash, and what a mismatch means.
What the checksum is for
A SHA256 checksum is a 64-character fingerprint of a file's bytes. The publisher hashes the file and lists the digest next to the download; you hash your copy and compare. Two identical strings mean the bytes match, so the download arrived intact. Two different strings mean something changed on the way to your disk.
The command is one line on every system, and the tools are preinstalled:
- Windows (Command Prompt):
certutil -hashfile FILE SHA256 - macOS (Terminal):
shasum -a 256 FILE - Linux (any shell):
sha256sum FILE
Each prints the digest as 64 hexadecimal characters. Replace FILE with the path to your download.
Compare against the published hash:
- Hash your copy with the command for your system above
- Find the published digest on the download page (often in a
.sha256file or a checksums list) - Compare the two strings. Sixty-four hex characters are hard to eyeball, so on Windows use
(Get-FileHash FILE -Algorithm SHA256).Hash -eq "PUBLISHED"in PowerShell, which prints True or False - On Linux, let the tool do it: put the published digest in
checksums.txtasPUBLISHED_HASH file.zip(two spaces), then runsha256sum -c checksums.txtand read the OK
macOS accepts the same file check with shasum -a 256 -c checksums.txt.
What a mismatch means
A failed comparison means the bytes on your disk differ from the bytes the publisher hashed. The common cause is a corrupted or incomplete download: a stalled transfer, a bad mirror, a file that got truncated. The rarer cause is tampering. Either way the response is the same: do not install, open or run the file. Re-download from the original source and compare again. If the check still fails, pull the file and the hash from a different channel, because at that point the problem may be on the publisher's side.
One honest caveat: a checksum only proves the file matches the hash you were given. If that hash itself did not come from the publisher over a channel you trust, the check says less. Release signing covers that stronger case.
Publish checksums for your own downloads
Releasing a zip or tarball? Hash it once and publish the digest alongside it:
sha256sum file.zip > file.zip.sha256
For a release with several files, generate one list:
sha256sum *.zip > checksums.txt
Ship the .sha256 or checksums.txt file with the release. Anyone on Linux or macOS can then verify the whole bundle with a single -c command, and Windows users can check individual files with certutil.
No terminal handy?
For a short file, or for plain text like a license or a config snippet, paste it into the Hash Generator. It computes SHA256 (plus MD5, SHA-1, SHA-384 and SHA-512) right in your browser, and dropped files are read locally, so nothing is uploaded anywhere.
Frequently Asked Questions
How do I check the SHA256 checksum of a file in Windows?
Open Command Prompt and run certutil -hashfile FILE SHA256, where FILE is the path to your download. Windows prints the 64-character digest, which you compare against the hash the publisher listed. PowerShell offers the same check: Get-FileHash FILE -Algorithm SHA256.
What does it mean when SHA256 checksums don't match?
The file on your disk is not byte-for-byte the file that was hashed. In practice that means a corrupted or incomplete download, or a file that was modified after the publisher hashed it. Do not install or run it: re-download from the original source and compare again. If it still fails, get the file and the hash from a different channel.
Is SHA256 the same as SHA-2?
SHA-2 is the family, SHA256 is one of its members. The SHA-2 family includes SHA-224, SHA-256, SHA-384 and SHA-512, named for their digest lengths in bits. When a download page says SHA-2 with no length, it almost always means SHA256.