Check a file's SHA-1, SHA-256 or MD5 hash without uploading it.
A free SHA-1 hash checker that also does MD5, SHA-256, SHA-384 and SHA-512. Drop a file or paste text to get all five. Paste a hash to find out what it is and whether it can still be trusted, or paste the checksum from the download page and see straight away whether it matches.
- Free, no sign-up
- Files are never uploaded
- MD5 to SHA-512
New to this? : it hashes a short sentence and checks it against a published SHA-256.
Result
How to verify a SHA-1 checksum (or any file hash)
Add the file
Drop the downloaded file on the box, or click to choose it. Pasted text works too.
Paste the published checksum
Copy the SHA-1, SHA-256 or MD5 checksum from the download page into the hash box. A line from sha1sum or a checksum file works as well.
Read the verdict
A match means the file is the one the publisher hashed. Anything else means it was damaged or changed.
A hash is a short fingerprint worked out from every byte of a file. If even one byte changes, the fingerprint changes completely. Software publishers list the hash next to the download so you can confirm that the file you got is the file they made. This tool works it out on your device, with no upload.
What it does
- Five algorithms in one go: MD5, SHA-1, SHA-256, SHA-384 and SHA-512.
- Paste an expected checksum and it tells you whether it matches, and which algorithm it is.
- Paste any hash on its own and it identifies it from its length and format: MD5, SHA-1, the SHA-2 family, CRC, Base64 and SRI values, and password hashes such as bcrypt and Argon2.
- Paste a whole checksum list (SHA256SUMS or BSD style) and drop the files: each one is matched to its line by name.
- Every algorithm is labelled Strong or Broken, and a match made only with MD5 or SHA-1 comes with a warning.
- Hashes several files at once, or text you type.
- Copy as lowercase hex, uppercase hex or Base64.
- Uses your browser’s built-in Web Crypto, so large files are handled without any upload.
Why MD5 and SHA-1 are marked broken
A hash is only good proof if nobody can make a second file with the same value. For MD5 that has been easy for years: two different files with the same MD5 take seconds on a laptop. For SHA-1 it became real in February 2017, when researchers at Google and CWI Amsterdam published SHAttered: two different PDF files with the same SHA-1. It took about nine quintillion SHA-1 calculations, roughly 6,500 years of CPU time and 110 years of GPU time. In 2020 a second team went further with “SHA-1 is a Shambles”, where the attacker chooses the start of both files, for about US$45,000 of rented GPUs.
Browsers stopped trusting SHA-1 certificates in 2017, and NIST has said SHA-1 should be phased out completely by the end of 2030. MD5 and SHA-1 still catch a download that got damaged on the way, but they cannot prove that nobody swapped the file. For that, use SHA-256 or SHA-512, which have no known practical attack.
File Hash Checker: questions and answers
How do I verify a SHA-1 hash?
What is a file hash?
How do I check that a download is genuine?
Is my file uploaded?
Which algorithm should I trust?
Has Google broken SHA-1?
Can this tool tell me what kind of hash I have?
Is there a file size limit?
Why is my text hash different from another tool’s?
More free tools
Need a custom tool, site or store?
I scope, design and build tools, websites and Shopify stores for teams in India and abroad. Send a short brief and I will reply within 48 hours.