← Back to Blog
GuideOctober 5, 2026• 5 min read

How to Check a Downloaded File Isn't Corrupted (SHA-256 in 30 Seconds)

A checksum tells you whether the file you received is exactly the file that was sent. It sounds technical, but it's one command on any computer.

Large downloads occasionally go wrong. A connection hiccups, a disk has a bad sector, a sync tool grabs a file before it finished writing. Usually you find out when an archive refuses to open or a video freezes halfway through.

There's a simple way to check up front: compare checksums.

What a checksum is

A checksum (or hash) is a short string calculated from every byte of a file. Change a single bit anywhere and the checksum changes completely. If the sender's checksum and your checksum match, the files are identical.

The most common one today is SHA-256. It produces a 64-character string like this:

9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08

You don't need to understand how it works. You just need to compare two of them.

Getting the checksum

Windows (PowerShell)

Open PowerShell and run:

Get-FileHash "C:\path\to\file.zip"

SHA-256 is the default. Tip: type Get-FileHash with a trailing space, then drag the file into the window to paste its path.

Windows (Command Prompt)

certutil -hashfile "C:\path\to\file.zip" SHA256

Mac

Open Terminal and run:

shasum -a 256 /path/to/file.zip

Again, you can drag the file into Terminal instead of typing the path.

Linux

sha256sum /path/to/file.zip

Comparing

The sender runs the same command on their copy and sends you the result. You compare. You don't have to read all 64 characters; checking the first and last six or so is plenty for catching corruption.

If they match, the file arrived intact. If they don't, download it again.

When this is worth doing

  • Very large files, like multi-gigabyte archives, disk images or raw footage. More data means more chances for something to go wrong.
  • Files you'll delete the original of. If you're moving the only copy of something, verify before removing the source.
  • Software installers and disk images. Many projects publish official SHA-256 values on their download pages. Comparing confirms you got the real file, not a modified one from a mirror.
  • Backups. A backup you never verified is a backup you're hoping works.

For everyday documents and photos, it's overkill. If the file opens and looks right, it's fine.

MD5 and SHA-1

You'll still see MD5 and SHA-1 checksums around. They're fine for catching accidental corruption, but both are considered broken for security purposes, because it's possible to deliberately create two different files with the same hash. If you're verifying that a file hasn't been tampered with, use SHA-256.

Checksums for a whole folder

If you're sending many files, zip them first and checksum the archive. One check covers everything. Alternatively, some tools can produce a checksum list for every file in a folder, which the recipient can verify in one go. On Linux and Mac, sha256sum and shasum both support a check mode with the -c flag.

A short note on what a checksum doesn't do

A matching checksum proves the file is identical to the one the checksum was made from. It doesn't prove that original file is safe. If the checksum comes from the same place as the file, an attacker who swapped the file could swap the checksum too. For security checks, get the checksum from a separate trusted source, like the project's official website.

Summary

  • Windows: Get-FileHash file
  • Mac: shasum -a 256 file
  • Linux: sha256sum file
  • Same string on both ends means the same file.

It takes half a minute, and it settles the question for good.

Try InstantFile Today

Simple, fast, and secure file sharing. No account needed.

Start Sharing Files