What a checksum is and why you need it

A checksum is a short string of characters that represents the contents of a file. Think of it like a fingerprint: if even one byte of the file changes, the checksum changes completely. You use checksums to verify that a file you downloaded is exactly what the creator intended — not corrupted during transfer, not tampered with, not replaced by malware.

When you download software, an operating system image, or any sensitive file from a website, the creator often publishes a checksum alongside it. After you download, you generate the checksum of your copy and compare it to theirs. If they match, the file is intact. If they don't, something went wrong and you should not use the file.

The most common checksum types are MD5, SHA-1, SHA-256, and SHA-512. SHA-256 is the current standard for security-conscious downloads. MD5 is older and faster but no longer considered secure against deliberate tampering, though it still catches accidental corruption.

Key Takeaways

  • Windows users can generate checksums using the built-in certUtil command in PowerShell or Command Prompt without installing anything.
  • Mac users can open Terminal and use the shasum or md5 commands, which come pre-installed on all modern Macs.
  • Linux users have sha256sum, md5sum, and other checksum tools available in the terminal by default.
  • Always compare the checksum you generate to the one published by the file creator — they must match exactly, character for character.
  • SHA-256 is the recommended checksum type for verifying downloads; MD5 is faster but weaker against intentional tampering.

Finding checksums on Windows using PowerShell

Open PowerShell by right-clicking on the Start menu and selecting "Windows PowerShell" or "Terminal" (depending on your Windows version). You can also press Win + X and choose PowerShell from the menu.

Navigate to the folder containing your file. If your file is on your Desktop, type cd Desktop. If it's in Downloads, type cd Downloads. Press Enter after each command.

To generate a SHA-256 checksum, type this command and press Enter:

certUtil -hashfile filename.ext SHA256

Replace filename.ext with the actual name of your file — for example, ubuntu-22.04-desktop-amd64.iso. PowerShell will display a long string of characters. This is your checksum. Copy it and compare it character-for-character to the checksum published on the website where you downloaded the file.

If you need MD5 instead, replace SHA256 with MD5 in the command above. For SHA-1, use SHA1.

Finding checksums on Mac using Terminal

Open Terminal by pressing Cmd + Space, typing "Terminal", and pressing Enter. Alternatively, open Finder, go to Applications, then Utilities, and double-click Terminal.

Navigate to the folder containing your file. If your file is in Downloads, type cd Downloads and press Enter. If it's on your Desktop, type cd Desktop.

To generate a SHA-256 checksum, type this command and press Enter:

shasum -a 256 filename.ext

Replace filename.ext with your actual filename. Terminal will display the checksum. Compare it to the published checksum from the file creator.

For MD5, use md5 filename.ext instead. For SHA-1, use shasum -a 1 filename.ext. On newer Macs, you can also use sha256sum instead of shasum -a 256 — both work the same way.

Finding checksums on Linux using the terminal

Open your terminal application. The exact name varies by Linux distribution — it might be called Terminal, Konsole, or xterm — but you can usually find it in your applications menu or by pressing Ctrl + Alt + T.

Navigate to the folder containing your file using the cd command, just as you would on Mac.

To generate a SHA-256 checksum, type this command and press Enter:

sha256sum filename.ext

For MD5, use md5sum filename.ext. For SHA-1, use sha1sum filename.ext. The output format is the same across all three: a long string of characters followed by the filename. Copy the checksum string and compare it to the published version.

Where to find the published checksum

The creator of the file publishes their checksum on the download page, in a README file, or in a separate checksums file. Look for a section labeled "Checksums", "Hashes", "Verification", or "Integrity". The published checksum is usually displayed as plain text on the page or in a file named something like SHA256SUMS, checksums.txt, or CHECKSUMS.md5.

Some creators publish multiple checksums — one for MD5, one for SHA-256, and so on. Make sure you are comparing the right type. If the page says "SHA-256", generate a SHA-256 checksum on your machine. If it says "MD5", generate MD5.

Be careful to copy the entire checksum string exactly. A single character difference means the checksums do not match. Some websites display checksums in a monospaced font to make them easier to read and copy accurately.

What to do if the checksums don't match

If your generated checksum does not match the published one, do not use the file. The mismatch could mean the download was corrupted, interrupted, or replaced. Delete the file and download it again from the official source.

If the checksum still does not match after a second download, try a different download method or contact the file creator to report the problem. Some creators host files on multiple servers; if one server is having issues, try another.

Checksum mismatches are usually caused by network errors during download, not by malware or tampering. But because you cannot know which it is without comparing, always treat a mismatch as a reason to re-download rather than proceed.

Frequently Asked Questions

Do I need to use SHA-256 or is MD5 okay?

SHA-256 is stronger and recommended for security-sensitive files like operating systems or security software. MD5 is faster and fine for catching accidental corruption, but it is not secure against deliberate tampering. Use whatever the file creator specifies; if they do not specify, SHA-256 is the safer choice.

What if the website only shows one checksum type but I generated a different one?

Generate the same type the website shows. If the site publishes SHA-256, run the SHA-256 command on your machine. You cannot compare an MD5 checksum to a SHA-256 checksum — they are different algorithms and will never match, even for the same file.

Can I use a graphical tool instead of the command line?

Yes. Windows users can download HashTab (free), which adds a checksum tab to file properties. Mac users can use Hashsum or similar apps from the App Store. Linux users have graphical tools available through their package manager. The command line is faster and works on any machine, but graphical tools are easier if you dislike typing commands.

Does the checksum prove the file is safe from malware?

No. A matching checksum proves the file is exactly what the creator published — it has not been corrupted or modified in transit. It does not prove the creator's version is free of malware. You still need to trust the source and use antivirus software as normal.

Why is my checksum different every time I generate it?

It should not be. If you run the checksum command on the same file twice, you should get the exact same result. If you get different results, the file is being modified between runs — which is unusual and suggests a problem with your system or storage device. Try generating the checksum again and contact technical support if the results keep changing.