Check a file's SHA-1, SHA-256 or MD5 hash without uploading it.

A free SHA-1 hash checker that also does MD5, SHA-256, SHA-384 and SHA-512. Drop a file or paste text to get all five. Paste a hash to find out what it is and whether it can still be trusted, or paste the checksum from the download page and see straight away whether it matches.

  • Free, no sign-up
  • Files are never uploaded
  • MD5 to SHA-512
Drop a file hereor click to choose. Hashed on your device, never uploaded.

New to this? : it hashes a short sentence and checks it against a published SHA-256.

Show as

Result

Hashes show up hereDrop a file or type some text on the left. All five hashes appear here, and a pasted checksum gets a Match or No match.

How to verify a SHA-1 checksum (or any file hash)

  1. Add the file

    Drop the downloaded file on the box, or click to choose it. Pasted text works too.

  2. Paste the published checksum

    Copy the SHA-1, SHA-256 or MD5 checksum from the download page into the hash box. A line from sha1sum or a checksum file works as well.

  3. Read the verdict

    A match means the file is the one the publisher hashed. Anything else means it was damaged or changed.

A hash is a short fingerprint worked out from every byte of a file. If even one byte changes, the fingerprint changes completely. Software publishers list the hash next to the download so you can confirm that the file you got is the file they made. This tool works it out on your device, with no upload.

What it does

  • Five algorithms in one go: MD5, SHA-1, SHA-256, SHA-384 and SHA-512.
  • Paste an expected checksum and it tells you whether it matches, and which algorithm it is.
  • Paste any hash on its own and it identifies it from its length and format: MD5, SHA-1, the SHA-2 family, CRC, Base64 and SRI values, and password hashes such as bcrypt and Argon2.
  • Paste a whole checksum list (SHA256SUMS or BSD style) and drop the files: each one is matched to its line by name.
  • Every algorithm is labelled Strong or Broken, and a match made only with MD5 or SHA-1 comes with a warning.
  • Hashes several files at once, or text you type.
  • Copy as lowercase hex, uppercase hex or Base64.
  • Uses your browser’s built-in Web Crypto, so large files are handled without any upload.

Why MD5 and SHA-1 are marked broken

A hash is only good proof if nobody can make a second file with the same value. For MD5 that has been easy for years: two different files with the same MD5 take seconds on a laptop. For SHA-1 it became real in February 2017, when researchers at Google and CWI Amsterdam published SHAttered: two different PDF files with the same SHA-1. It took about nine quintillion SHA-1 calculations, roughly 6,500 years of CPU time and 110 years of GPU time. In 2020 a second team went further with “SHA-1 is a Shambles”, where the attacker chooses the start of both files, for about US$45,000 of rented GPUs.

Browsers stopped trusting SHA-1 certificates in 2017, and NIST has said SHA-1 should be phased out completely by the end of 2030. MD5 and SHA-1 still catch a download that got damaged on the way, but they cannot prove that nobody swapped the file. For that, use SHA-256 or SHA-512, which have no known practical attack.

File Hash Checker: questions and answers

How do I verify a SHA-1 hash?

Drop the file on the box above (or paste the text), then paste the 40-character SHA-1 checksum from the download page, or a line from sha1sum, into the hash box. It shows Match or No match straight away. A SHA-1 match proves the file was not damaged on the way, but SHA-1 is broken, so if the publisher also lists SHA-256, check that too.

What is a file hash?

A fixed-length fingerprint calculated from a file’s contents. The same file always gives the same hash, and any change to the file gives a different one.

How do I check that a download is genuine?

Hash the file here, then paste the checksum from the publisher’s page into the compare box. If it matches, the file is exactly what they published. If it does not, download it again, ideally from the official site.

Is my file uploaded?

No. The hash is calculated in your browser, using Web Crypto for the SHA family and a small built-in routine for MD5. Nothing is sent anywhere.

Which algorithm should I trust?

Use SHA-256 or SHA-512 when you want to be sure a file has not been tampered with. MD5 and SHA-1 still catch accidental damage, but both are broken: an attacker can make two different files with the same value, so they are weak as proof.

Has Google broken SHA-1?

Yes, for collisions. In 2017 Google and CWI Amsterdam published SHAttered, two different PDF files with the same SHA-1, and in 2020 another team showed a cheaper attack where the attacker picks what both files contain. SHA-1 has not been reversed: nobody can get a file back from its hash. It just can no longer prove a file is genuine.

Can this tool tell me what kind of hash I have?

Yes. Paste it into the hash box with nothing else and it names the likely algorithm from its length and format, says how many bits it has, and labels it Strong or Broken. It also recognises Base64 and SRI values, checksum-file lines and password hashes such as bcrypt, Argon2 and the Linux $6$ format.

Is there a file size limit?

The browser reads the file into memory first, so the limit depends on your device. Around 2 GB is the practical ceiling on a computer, and phones handle less.

Why is my text hash different from another tool’s?

Usually a trailing newline, different line endings or a different text encoding. This tool hashes the text exactly as typed, encoded as UTF-8.

More free tools

Photo Metadata RemoverSee and remove GPS and camera dataOpen tool →Password GeneratorRandom passwords made on your deviceOpen tool →QR Code GeneratorStatic codes that never expireOpen tool →
Available for full-time and freelance

Need a custom tool, site or store?

I scope, design and build tools, websites and Shopify stores for teams in India and abroad. Send a short brief and I will reply within 48 hours.