Whenever you download a critical software installer, a firmware update, or receive a sensitive document, you must ensure it hasn’t been tampered with or corrupted during transit. Software developers provide SHA-256 checksums—unique 64-character cryptographic hashes—for precisely this reason.

Here is how to verify a SHA-256 checksum on Windows, Mac, and Linux using built-in command-line tools, as well as how to perform automated comparisons to avoid manually checking 64 characters.

How to Verify SHA-256 on the Command Line

Native command-line interface (CLI) tools stream the file directly from your disk, reading it in chunks with roughly constant memory overhead. This allows them to process files of any size, including multi-gigabyte ISOs.

1. Windows (PowerShell and cmd)

Windows provides built-in tools for hashing files. Open PowerShell and use the Get-FileHash cmdlet:

Get-FileHash .\hello.txt -Algorithm SHA256

To compare the hash automatically against an expected value (case-insensitive), you can run:

(Get-FileHash .\hello.txt -Algorithm SHA256).Hash -eq "<EXPECTED-HASH>"

This will print True if it matches, or False if it does not.

If you are using the older Command Prompt (cmd) instead of PowerShell, you can use:

certutil -hashfile hello.txt SHA256

2. macOS (shasum)

macOS ships with the shasum utility. Open the Terminal application:

printf 'hello world\n' > hello.txt
shasum -a 256 hello.txt

Output:

a948904f2f0f479b8f8197694b30184b0d2ed1c1cd2a1ec0fb85d299a192a447  hello.txt

To automatically verify an expected hash, use the -c flag. Note the two spaces between the hash and the filename:

echo "<expected-hash>  hello.txt" | shasum -a 256 -c

Output:

hello.txt: OK

3. Linux (sha256sum)

Most Linux distributions include sha256sum as part of coreutils. Open your terminal:

sha256sum hello.txt

To automatically verify an expected hash:

echo "<expected-hash>  hello.txt" | sha256sum -c -

Note: Recent macOS versions also include a BSD sha256sum; this trailing-dash form works there too, as does shasum -a 256 -c.

If a project provides a SHA256SUMS file with multiple hashes, place it in the same directory as your downloads and run:

sha256sum -c SHA256SUMS --ignore-missing

Checksums vs. Signatures: Why a Matching Hash is Not Enough

A matching SHA-256 hash confirms that your file exactly matches the hash you downloaded. However, if an attacker compromises the server hosting the download, they can replace both the file and the expected hash on the website.

This is why a checksum is not a digital signature. To verify authenticity, projects like Ubuntu publish SHA256SUMS together with a GPG signature (SHA256SUMS.gpg) and Debian publishes SHA256SUMS.sign.

To properly verify authenticity:

  1. Import the project’s public key from their official documentation.
  2. Verify the signature of the checksum file:
    gpg --verify SHA256SUMS.gpg SHA256SUMS
  3. Only after the signature is verified as “Good”, check the file against the verified hash list:
    sha256sum -c SHA256SUMS --ignore-missing

Common Verification Mistakes

  • Comparing only the first or last few characters: Matching only the first and last 4 hex characters checks just 32 bits, so an attacker needs only about 4 billion (2^32) attempts to craft a file that passes that glance — trivial on a GPU. Verify the full 64 characters (or let the -c / -eq commands compare for you).
  • Using a single space in piped checks: When using echo "<hash> filename" | shasum -c, using a single space between the hash and filename makes shasum fail with “no properly formatted SHA checksum lines found”. Always use two spaces.
  • Copying trailing spaces or newlines: Ensure you do not include hidden spaces when copying the expected hash into a comparison tool, which will cause a false mismatch.
  • Worrying about uppercase vs. lowercase: Hexadecimal case does not matter. A948... is identical to a948....
  • Hashing a partially downloaded file: Ensure your download is completely finished before checking its hash, otherwise it will not match.
  • Using the wrong algorithm: You must use the exact algorithm the publisher used. For SHA-1, SHA-384, or SHA-512, the Checksum Calculator computes all four SHA variants at once (or use shasum -a 512, sha512sum, or Get-FileHash -Algorithm SHA512). For legacy MD5 checksums, use md5 (macOS), md5sum (Linux), or Get-FileHash -Algorithm MD5, and note that MD5 and SHA-1 only detect accidental corruption, not deliberate tampering.

In-Browser Hashing (For Smaller Files)

For users who prefer a graphical interface, modern browsers provide a native, typically optimized Web Crypto API (window.crypto.subtle).

Using an offline-capable browser tool like the SHA256 File Checksum Calculator allows you to calculate the hash locally without uploading anything to a server. You can drag and drop your file into the secure dropzone, paste the expected checksum into the verification field, and see a MATCH VERIFIED or MISMATCH WARNING banner.

Because this method reads the entire file into browser memory, it is fine for files up to a few hundred MB. For multi-GB ISOs, use the command line tools mentioned above.

Comparison Table

EnvironmentToolMax File SizeBest For
Terminal (macOS)shasumUnlimited (Disk Stream)Large files, automated verification
Terminal (Linux)sha256sumUnlimited (Disk Stream)Large files, automated verification
Windows PowerShellGet-FileHashUnlimited (Disk Stream)Large files on Windows
Windows Command PromptcertutilUnlimited (Disk Stream)Command Prompt users
Browser (Utiliome)Web Crypto APIA few hundred MBQuick checks, UI-driven verification

Pre-Flight Verification Checklist

  1. Source the Expected Hash Securely: Get the hash from the official site over HTTPS AND, when the project publishes a signed checksum file (SHA256SUMS.gpg or .sign), verify the signature first with gpg.
  2. Compute Locally: Generate the hash using a local CLI tool or an in-browser Web Crypto API tool.
  3. Verify the Match: The computed hash must match the expected hash exactly. A single changed bit will result in a completely different SHA-256 digest (an avalanche effect). If they differ, delete the downloaded file immediately.