How to verify a file with SHA-256
- Choose File and drag the download onto the drop area, or choose Text to hash a string.
- Wait for the progress bar on large files. The SHA-256 appears at the top of the results, highlighted, with the file name and size.
- Paste the published checksum into the compare box. A green Match confirms the file is intact; a red message means it's different.
- Copy the hash with its copy button if you need to record it or share it with someone.
Features
- SHA-256 listed first and highlighted, with SHA-384, SHA-512, SHA-1 and MD5 below it.
- Computed by Web Crypto, the hashing engine built into modern browsers.
- Checksum verification that ignores spaces and letter case and tells you which algorithm matched.
- Text and file modes, with drag and drop for any file type.
- Large-file support with a progress bar and a warning above 100 MB.
- Uppercase or lowercase output, with a copy button on every row.
Why use Fileora's SHA-256 generator
The point of verifying a checksum is to trust nothing but the maths, and that includes the tool doing it. Fileora never receives your file: the browser reads it locally and hashes it with its own Web Crypto implementation. Private installers, signed contracts and backups stay on your machine, and the check runs even if you go offline after the page loads.
There's no charge, no account and no limit on how many files you check. It works on a phone too, which is handy for confirming an app package or firmware file you've downloaded to a mobile device.
Related tools: the MD5 generator for older download pages that only publish MD5, the hash generator for all five algorithms side by side, and the JWT decoder for tokens signed with HS256 or RS256, both of which use SHA-256 internally.
Checking SHA-256 on the command line
If you prefer a terminal, every major system can calculate SHA-256 too, and the result should be identical to the one shown here:
- Windows (PowerShell):
Get-FileHash file.isouses SHA-256 by default. - macOS:
shasum -a 256 file.iso - Linux:
sha256sum file.iso
Linux and macOS print the hash followed by the file name. Paste only the 64-character hash into the compare box.
What makes a checksum trustworthy
A checksum only proves that your file matches the one the checksum was made from. If an attacker replaces both the file and the checksum on a compromised site, they will still match. So take the checksum from the official source, ideally a page served over HTTPS or a signed release note, and not from the same mirror you downloaded the file from. That is also why SHA-256 is preferred to MD5: with MD5, an attacker can prepare a harmful file that shares a checksum with the genuine one.