Hash & Checksum Verifier
Check downloads against their published checksum — and verify the checksum file’s own OpenPGP or minisign signature, so you know who published it.
How to use
- Single file: drop it and paste the published checksum.
- Signed release: add the publisher’s key, the checksum list and its signature, then your downloads.
- Compare the key fingerprint shown with the one on the publisher’s website.
Drop a file here, or
Read in 4 MB pieces straight from your disk. Files over 1 GB work with MD5, SHA-1 and SHA-256.
Common questions
How do I verify a file’s SHA-256 checksum?
Drop the file and paste the checksum from the download page. The algorithm is detected from its length, and you get a clear match or mismatch. Large files are read in pieces, so multi-gigabyte ISOs work.
Is a matching checksum enough?
It proves the file matches the list, not that the list is genuine — an attacker who changes the download can change the checksum too. Verifying the list’s signature with the publisher’s key closes that gap.
Is my file uploaded?
No. Your browser reads the file from your disk, and the page cannot open any connection to send it.
Known limitations
- Keys are never fetched: you supply the publisher’s public key, and must check its fingerprint against an official source.
- OpenPGP: v4 signatures with RSA or Ed25519 keys (what Linux distributions and most vendors use). Key expiry and revocation are not checked.
- MD5 and SHA-1 catch accidental corruption but not deliberate tampering. SHA-384/512 are limited to files up to 1 GB.
- Large files are read in pieces to stay light on memory, so files over 256 MB hash more slowly than native tools.
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- FIPS 180-4 — SHA-1 and SHA-2 (opens in a new tab)
- RFC 9580 — OpenPGP (opens in a new tab)
- minisign signature format (opens in a new tab)
- RFC 7693 — BLAKE2 (opens in a new tab)
- RFC 2104 — HMAC (opens in a new tab)