How to Verify a SHA-256 Checksum on Windows, macOS, and Linux
DEV Community

How to Verify a SHA-256 Checksum on Windows, macOS, and Linux

How to Verify a SHA-256 Checksum on Windows, macOS, and Linux You download an ISO, installer, archive, or release binary. The publisher provides a long value such as: 9f86d081884c7d659a2feaa0c55ad015 a3bf4f1b2b0b822cd15d6c15b0f00a08 That value is a checksum, usually generated with SHA-256. Verifying it answers one practical question: Does the file you downloaded have exactly the same contents as the file the publisher hashed? A checksum mismatch can indicate a damaged download, an incomplete transfer, the wrong file version, or modified contents. Before verifying anything Get the expected checksum from a source you trust. Ideally, use the software publisher’s official website, release page, package repository, or signed checksum file. A matching checksum confirms that your file matches the data represented by the expected hash. It does not prove that the original publisher or website was trustworthy. If an attacker can replace both the download and the displayed checksum, they can make the two values match. For stronger authenticity verification, use a signed release when the publisher provides one. Verify SHA-256 on Windows Open PowerShell in the folder containing the downloaded file. Run: Get-FileHash ".\filename.iso" -Algorithm SHA256 Example: Get-FileHash ".\ubuntu.iso" -Algorithm SHA256 PowerShell returns something similar to: Algorithm : SHA256 Hash : 4A1F... Path : C:\Users\You\Downloads\ubuntu.iso Compare the value beside Hash with the checksum published by the download provider. Uppercase and lowercase letters do not matter in hexadecimal hashes. The characters themselves must otherwise match exactly. Compare automatically in PowerShell Instead of comparing two 64-character values manually, store the expected checksum and let PowerShell compare them: $expected = "PASTE_EXPECTED_SHA256_HERE" $actual = (Get-FileHash ".\filename.iso" -Algorithm SHA256).Hash if ($actual -eq $expected) { Write-Host "Checksum matches" } else { Write-Host "Checksum does not match" } Verify SHA-256 on macOS Open Terminal and run: shasum -a 256 filename.dmg Example: shasum -a 256 application.dmg The result contains the calculated checksum followed by the filename: 4a1f... application.dmg Compare the calculated value with the publisher’s expected SHA-256 checksum. Quotes are useful when a filename contains spaces: shasum -a 256 "Application Installer.dmg" Verify SHA-256 on Linux Most Linux distributions provide sha256sum through GNU core utilities. Run: sha256sum filename.iso Example: sha256sum linux-distribution.iso The output looks like this: 4a1f... linux-distribution.iso Compare the first value with the checksum from the publisher. Verify a SHA256SUMS file on Linux Some projects provide a file named SHA256SUMS , checksums.txt , or something similar. A GNU checksum line normally looks like: 4a1f... linux-distribution.iso When the checksum file and downloaded file are in the same directory, run: sha256sum --check SHA256SUMS The short form also works: sha256sum -c SHA256SUMS A successful result looks like: linux-distribution.iso: OK A failure may look like: linux-distribution.iso: FAILED This method is safer than visually comparing long values because the command performs the comparison directly. Verify a checksum without using the command line For occasional checks, I built the Olivez Hash Generator & Checksum Checker. It supports SHA-256, SHA-384, and SHA-512 for files and exact text. The verification field accepts several common formats: 4a1f... 4a1f... filename.iso SHA256 (filename.iso) = 4a1f... SHA-256: 4a1f... It can also read multiline checksum lists and select the entry matching the chosen filename. Files and text are processed locally and are not uploaded. The current file limit is 100 MB, so command-line tools remain the better option for large ISO images and multi-gigabyte archives. Why did my checksum fail? A mismatch does not automatically mean malware. Common causes include: You downloaded a different version Checksums change whenever file contents change. Version 2.1 and version 2.1.1 will normally have completely different hashes. The download was incomplete or corrupted Delete the file, download it again, and recalculate the checksum. You selected the wrong algorithm A SHA-256 value contains 64 hexadecimal characters. Common digest lengths are: | Algorithm | Hexadecimal characters | |---|---| | MD5 | 32 | | SHA-1 | 40 | | SHA-256 | 64 | | SHA-384 | 96 | | SHA-512 | 128 | Calculating SHA-512 will never match a published SHA-256 value, even when both were generated from the same file. The checksum belongs to another filename Checksum lists often contain values for several operating systems, architectures, or package formats. Confirm that you are comparing the entry for the exact file you downloaded. The expected value contains extra text Publishers may use GNU, BSD, labelled, or custom checksum formats. Make sure you are comparing the digest itself rather than copying punctuation, a filename, or the algorithm label into a field that expects only hexadecimal characters. SHA-256 is not password hashing SHA-256 is useful for file integrity, release verification, content identification, and similar tasks. Do not store passwords as plain SHA-256 hashes. Password storage requires a dedicated password-hashing function such as Argon2id, scrypt, bcrypt, or PBKDF2 with appropriate parameters and unique salts. The practical rule Use the operating system command when you regularly verify files or work with large downloads: Windows: Get-FileHash macOS: shasum -a 256 Linux: sha256sum Use a local-processing interface when you need to check a smaller file, compare text, parse a complete checksum line, or inspect a multiline checksum list without manually extracting the correct digest. Whichever method you use, obtain the expected checksum from a trusted source and make sure the algorithm, filename, and file version all match. Top comments (0)

Comments

No comments yet. Start the discussion.