Security Tools

Checksum Verifier

Do what sha256sum -c does, in your browser. Paste the checksum list a publisher provides, or a single hash, then choose the downloaded files. The verifier recognises the algorithm from the hash length, matches each file to its line by name, hashes the files on your device and marks each one as OK or FAILED.

  • Runs in your browser
  • No sign-up
  • Free to use

Paste a SHA256SUMS, MD5SUMS or similar file, one “hash file name” per line, or a single hash. The algorithm is recognised from the length.

Verification results
FileAlgorithmResult

How to use Checksum Verifier

  1. Paste the checksum list or a single expected hash.
  2. Choose or drop the files you downloaded.
  3. Wait while the files are hashed locally.
  4. Check that every file is marked OK.

Checksum Verifier features

Standard formats

GNU “hash name”, binary “hash *name” and BSD “SHA256 (name) = hash” lines.

Algorithm detection

MD5, SHA-1, SHA-256, SHA-512 and CRC32 by length.

Name matching

Files are matched to lines by name, ignoring folders.

Missing files

Lists entries you did not select.

Single-hash mode

Paste just one hash to check one file.

Local only

Nothing is uploaded.

When to use Checksum Verifier

  • Verifying a Linux ISO or software release.
  • Checking a batch of files received from a partner.
  • Confirming backups or archives are intact.
  • Validating firmware images before flashing.

Checksum Verifier FAQ

Where do I find the checksum list?

On the publisher’s download page, usually as a file named SHA256SUMS, CHECKSUMS or similar, or listed next to each download.

What does FAILED mean?

The file’s hash differs from the expected one. Download it again; if it still fails, the file may have been altered and should not be used.

Are my files uploaded?

No. They are hashed in your browser.

Is a match enough to trust the file?

It proves the file matches the list. If the list itself could be tampered with, check its signature, for example SHA256SUMS.gpg, with the publisher’s key.

Why “not listed”?

The file name does not appear in the checksum list. The download may have been renamed; rename it back or use single-hash mode.

Does it support MD5?

Yes, but MD5 only detects accidental corruption. Prefer SHA-256 lists where available.

The last step of every download

Software publishers publish checksums so that users can confirm a download is complete and unmodified. On Linux and macOS this is a one-line command; on other systems, and for people who prefer not to use a terminal, it is often skipped. This tool makes it as easy as choosing the files.

Checksum lists follow a few standard formats. The GNU format writes the hash, two spaces and the file name; an asterisk before the name marks binary mode. BSD tools write the algorithm, the name in brackets and the hash. The verifier reads all of them and works out the algorithm from the length of each hash.

Each selected file is hashed locally in slices and compared with its expected value in constant time. Results are listed per file, along with entries in the list that you did not select, so that nothing is silently skipped.

A checksum protects against corruption and against tampering only if the list comes from a trustworthy source. Projects that sign their checksum lists let you verify that too; for critical software, check the signature before trusting the checksums.

Other useful tools