On this page
- What Is a Checksum?
- How Do Checksums Work?
- 1. Calculate the original value
- 2. Store or share the expected value
- 3. Calculate the value again
- 4. Compare the values
- A Simple Checksum Example
- What Are the Main Types of Checksums?
- Parity bits
- Internet checksum
- Cyclic Redundancy Check (CRC)
- MD5 checksum
- SHA-256 checksum
- What Is a Checksum Used For?
- Downloaded files and software installers
- Data transmission
- Data storage and backups
- File systems and archives
- Software and security workflows
- How to Check a File Checksum on Windows
- Step 1: Obtain the expected checksum
- Step 2: Open Command Prompt
- Step 3: Run the SHA-256 command
- Step 4: Compare the result
- How to Verify a Checksum on macOS
- Step 1: Open Terminal
- Step 2: Calculate the SHA-256 hash
- Step 3: Compare the digest
- How to Verify a Checksum on Linux
- Step 1: Open a terminal
- Step 2: Calculate the checksum
- Step 3: Compare it with the official value
- What Is the Difference Between a Checksum and a Hash?
- Checksum vs. Hash vs. Digital Signature
- Are Checksums Secure?
- Can Two Files Have the Same Checksum?
- What Does a Checksum Mismatch Mean?
- What should you do if the checksum does not match?
- Frequently Asked Questions
- What is the main purpose of a checksum?
- What is a checksum in simple terms?
- How do checksums detect file corruption?
- What is an MD5 checksum?
- What is a SHA-256 checksum?
- Is a checksum the same as a digital signature?
- What happens if a checksum does not match?
- Are checksums used in networking?
- Can checksums prevent data corruption?
- Conclusion
A checksum is a calculated value used to help determine whether data has changed or become corrupted. Computers use checksums and related techniques to check downloaded files, stored information, and data transmitted across networks.
For example, when you download a software installer, the developer may publish its SHA-256 checksum. You can calculate the checksum of your downloaded file and compare it with the developer’s original value. If the values match, the file’s contents match the expected data with very high confidence against accidental corruption. However, a matching checksum does not automatically prove that the software is safe or that the publisher is trustworthy.
This guide explains what checksums mean, how they work, the common types, and how to verify a file’s checksum on Windows, macOS, and Linux.
What Is a Checksum?
A checksum is a value calculated from a block of data using a defined algorithm. It helps detect changes, transmission errors, or corruption by allowing the calculated value to be compared with an expected value.
The result depends on the algorithm. A simple checksum may use arithmetic operations on data bytes, while a cryptographic hash such as SHA-256 produces a fixed-length digest designed to provide stronger integrity checking.
Checksums are commonly used for:
- File verification: Checking whether a downloaded file matches an expected version.
- Data transmission: Detecting certain errors in data packets.
- Storage systems: Identifying changes or corruption in stored data.
- Software distribution: Comparing a downloaded installer with a published digest.
- Data processing: Checking whether data has changed between processing steps.
The term checksum is often used broadly in everyday computing. Strictly speaking, a traditional checksum, a cyclic redundancy check (CRC), and a cryptographic hash are different techniques, even though they can serve related integrity-checking purposes.
How Do Checksums Work?
Checksums work by applying the same algorithm to data and comparing the resulting value with a trusted expected value.
The general process has four steps.
1. Calculate the original value
A sender, software publisher, or storage system processes the original data using a selected algorithm. The result is the original checksum or digest.
2. Store or share the expected value
The calculated value may accompany the data, appear on a software download page, or be stored separately in an integrity-checking system.
3. Calculate the value again
After receiving or downloading the data, the recipient runs the same algorithm on the received file or data.
4. Compare the values
If the calculated and expected values differ, the data does not match the expected version. The cause might be corruption, an incomplete download, an accidental change, or deliberate modification.
If the values match, the data passes that particular integrity check. The strength of this conclusion depends on the algorithm and whether the expected value is trustworthy.
For example, imagine a software publisher provides this illustrative SHA-256 value:
abc123...
After downloading the installer, you calculate its SHA-256 digest. If your result differs from the publisher’s complete digest, you should not treat the file as verified.
The shortened value above is only an illustration, not a real checksum.
A Simple Checksum Example
Imagine you need to transmit the following three numbers:
12, 25, 33
For a deliberately simplified example, suppose the checksum algorithm adds the numbers together:
12 + 25 + 33 = 70
The checksum is 70.
If the received values become:
12, 26, 33
Their sum is 71, so the mismatch reveals that something changed.
This example illustrates the basic principle, but it is not a secure or robust checksum algorithm. Different data can produce the same sum. For instance, 12, 25, 33 and 13, 24, 33 both produce 70.
Real checksum algorithms use defined mathematical procedures appropriate to their intended purpose. Cryptographic hash functions are designed with additional security properties, including resistance to finding different inputs that produce the same digest.
What Are the Main Types of Checksums?
Different algorithms detect different kinds of errors and provide different levels of protection.
| Type | How it works | Common use | Main limitation |
|---|---|---|---|
| Parity bit | Adds a bit to represent even or odd parity | Basic error detection | Some multiple-bit errors remain undetected |
| Simple arithmetic checksum | Combines data values using arithmetic | Basic integrity checks | Different inputs can produce the same result easily |
| Internet checksum | Uses one’s-complement arithmetic on 16-bit words | Network protocols, including TCP and UDP | Not designed to provide cryptographic security |
| CRC (Cyclic Redundancy Check) | Uses polynomial-based calculations over data bits | Storage, communication, and file formats | Not suitable for cryptographic authentication |
| MD5 | Produces a 128-bit message digest | Legacy identification and compatibility | Cryptographic collision resistance is broken |
| SHA-256 | Produces a 256-bit cryptographic digest | File verification and security-related integrity checks | Does not authenticate a file by itself |
These techniques are not interchangeable. Choose the algorithm that matches the purpose of the check. The NIST Secure Hash Standard documents the SHA family, while RFC 1071 describes the Internet checksum used in networking.
Parity bits
A parity bit adds one bit to a group of bits so that the total number of set bits follows an even-parity or odd-parity rule.
For example, a parity scheme can detect a single-bit change. However, if two bits change, the overall parity may remain unchanged. Parity is therefore a basic error-detection method, not a comprehensive integrity mechanism.
Internet checksum
The Internet checksum uses one’s-complement arithmetic to calculate a value from 16-bit words. It is used in network protocol checks, including TCP and UDP.
It is designed to detect certain transmission errors efficiently. .It is not a cryptographic hash and does not provide protection against a malicious party deliberately modifying data.
Cyclic Redundancy Check (CRC)
A cyclic redundancy check treats the data as a sequence of bits and calculates a remainder using a specified polynomial.
CRC algorithms are widely used to detect common accidental errors in communication and storage. Different CRC variants use different parameters, so a CRC-32 value, for example, must be calculated using the correct CRC-32 variant to be meaningfully compared.
A CRC can be excellent for detecting accidental corruption, but it should not be used as a security mechanism against intentional tampering.
MD5 checksum
MD5 produces a 128-bit digest, commonly represented by 32 hexadecimal characters.
Although MD5 remains present in older software and legacy workflows, practical collision attacks make it unsuitable where cryptographic collision resistance is required. A collision occurs when two different inputs produce the same digest.
For modern security-sensitive file verification, prefer SHA-256 or another currently appropriate cryptographic hash rather than MD5.
SHA-256 checksum
SHA-256 belongs to the SHA-2 family of cryptographic hash functions and produces a 256-bit digest, usually represented by 64 hexadecimal characters.
It is commonly used to verify downloaded files and detect changes to data. If a file changes, its SHA-256 digest will ordinarily change as well.
SHA-256 is a strong general-purpose choice for file-integrity checks, provided that you obtain the expected digest from a trustworthy source. A hash alone does not prove who created the file.
What Is a Checksum Used For?
Checksums and related integrity mechanisms are used in several areas of computing.
Downloaded files and software installers
A software publisher may provide a checksum beside a download. Comparing the downloaded file’s digest with the published digest can reveal whether the file differs from the expected release.
Data transmission
Network protocols use integrity checks to identify certain errors that can occur as data moves between devices. Depending on the protocol, detected errors may lead to a discarded packet, retransmission, or another recovery action.
Data storage and backups
Storage systems and backup tools may calculate checksums to identify changes or corruption. Some systems also retain redundant copies or use additional recovery mechanisms to repair damaged data.
A checksum can help detect a problem, but it cannot reconstruct missing or corrupted data on its own.
File systems and archives
Some file systems, archive formats, and data-management systems use integrity metadata to detect inconsistencies. The exact protection depends on the implementation and whether checks are performed during ordinary reads, background scrubbing, or verification operations.
Software and security workflows
Cryptographic hashes are also used in digital signatures, software manifests, and other security systems. In those cases, the hash is usually one part of a larger process that establishes integrity and, where required, authenticity.
How to Check a File Checksum on Windows
Windows includes the certutil command, which can calculate a file’s cryptographic hash.
Step 1: Obtain the expected checksum
Download the file and find its official SHA-256 value on the software publisher’s website, release page, or authenticated manifest.
Make sure the published value belongs to the exact file and version you downloaded.
Step 2: Open Command Prompt
Open the Start menu, search for Command Prompt, and launch it. Administrator privileges are not normally required just to calculate a hash for a readable file.
Step 3: Run the SHA-256 command
Enter the following command, replacing the example path with the location of your file:
certutil -hashfile "C:\Users\YourName\Downloads\installer.exe" SHA256
The command calculates and displays the file’s SHA-256 hash. Microsoft documents this syntax in its certutil command reference.
Step 4: Compare the result
Compare the entire calculated value with the official expected SHA-256 value.
- Values match: The file matches the expected digest.
- Values differ: The file has not passed verification. Check the filename, version, algorithm, and download source before using it.
Do not compare a SHA-256 result with an MD5 checksum or a checksum for another software version.
How to Verify a Checksum on macOS
macOS provides the shasum utility on many standard installations.
Step 1: Open Terminal
Open Finder, navigate to Applications, open Utilities, and launch Terminal.
Step 2: Calculate the SHA-256 hash
Run:
shasum -a 256 "/path/to/your/file.zip"
Replace /path/to/your/file.zip with the actual file path. You can often drag the file into the Terminal window to insert its path.
Step 3: Compare the digest
Compare the displayed hash with the expected SHA-256 value from the software publisher.
If the values differ, confirm that you selected the correct file and algorithm. If the mismatch remains, download a fresh copy from the official source and investigate before opening or installing it.
How to Verify a Checksum on Linux
Many Linux distributions provide the sha256sum utility.
Step 1: Open a terminal
Navigate to the directory containing the downloaded file, or use its full path.
Step 2: Calculate the checksum
Run:
sha256sum file.iso
Replace file.iso with your downloaded filename.
The output includes the SHA-256 digest and the filename.
Step 3: Compare it with the official value
Check every character of the digest against the value published by the distribution or software provider.
Some projects also provide checksum files that can be checked with commands such as:
sha256sum -c SHA256SUMS
This command works when SHA256SUMS contains correctly formatted checksum entries and the referenced files are accessible at the expected paths. Verify the checksum list’s authenticity as well; a manipulated checksum list cannot establish that a file is genuine.
What Is the Difference Between a Checksum and a Hash?
The terms overlap in everyday use, but they are not always technically equivalent.
A checksum is a value used to help detect errors or changes. A hash is an output produced by a hash function. Cryptographic hashes are designed to provide security properties that ordinary checksums generally do not provide.
| Feature | Traditional checksum | Cryptographic hash |
|---|---|---|
| Main purpose | Detect certain accidental errors | Represent data with a security-oriented digest |
| Calculation | Often arithmetic or error-detection operations | A defined hash algorithm |
| Collision resistance | Generally not a security property | A key design property |
| Examples | Internet checksum, CRC | SHA-256, SHA-3 |
| Security against deliberate manipulation | Usually inadequate | Depends on the algorithm and how the digest is authenticated |
A checksum can be a useful integrity check without being a secure cryptographic hash. The distinction matters when verifying software or protecting important data.
Checksum vs. Hash vs. Digital Signature
These terms describe related but different parts of an integrity and authenticity workflow.
- Checksum: Helps detect certain errors or changes.
- Cryptographic hash: Produces a fixed-length digest of data, with security properties depending on the algorithm.
- Digital signature: Uses a cryptographic signing process to help verify that signed data is associated with a particular signing key and has not been altered since signing.
A digital signature can establish stronger evidence of authenticity when the signing key and identity are appropriately verified. It is not simply another name for a checksum.
For example, if a publisher posts a checksum on the same compromised website as a malicious replacement file, both values could be changed together. Comparing them would not establish that the file came from the legitimate publisher. A verified digital signature or an independently authenticated digest can provide stronger assurance.
Are Checksums Secure?
The answer depends on the algorithm and what you are trying to protect against.
For accidental corruption, many traditional checksums and CRCs are useful. For security-sensitive integrity verification, a modern cryptographic hash such as SHA-256 is generally a more appropriate choice.
However, three important limitations remain:
- A matching digest does not prove that a file is safe. A file may match its published checksum and still contain malicious code if the publisher or distribution process has been compromised.
- The expected digest must be trustworthy. Obtain it from an authenticated source, not an untrusted copy that could have been altered alongside the file.
- Not every hash algorithm is suitable for every security purpose. MD5 and SHA-1 should not be chosen for new applications that require collision resistance.
For cryptographic algorithm guidance, consult NIST’s hash-function policy.
Can Two Files Have the Same Checksum?
Yes. Different files can produce the same checksum or hash value. This is called a collision when the same hash function produces an identical digest for different inputs.
For simple checksums, collisions can be easy to construct because the algorithm may preserve very little information about the original data.
Cryptographic hashes such as SHA-256 are designed to make finding collisions computationally infeasible with currently understood practical methods. Nevertheless, the output is finite, while the set of possible input files is vastly larger, so collisions necessarily exist in principle.
For ordinary file verification, a matching SHA-256 digest provides strong evidence that the file matches the expected data, assuming the expected digest is authentic. It is not a mathematical proof of identity.
What Does a Checksum Mismatch Mean?
A checksum mismatch means the calculated value does not match the expected value. It indicates that the data has failed the selected integrity check.
Possible causes include:
- An incomplete or corrupted download.
- A file that changed after the checksum was published.
- A checksum copied incorrectly.
- A mismatch between software versions.
- An incorrect algorithm or command.
- A damaged file or storage medium.
- Deliberate modification of the file or expected value.
What should you do if the checksum does not match?
- Confirm that the checksum algorithm is correct.
- Verify that the expected value belongs to the exact file and version.
- Check that you calculated the digest for the intended file.
- Download a fresh copy from the official source.
- Calculate the checksum again.
- If the mismatch persists, do not rely on the file until you have resolved the discrepancy.
For important software, verify the publisher’s signature or another available authenticity mechanism where appropriate.
Frequently Asked Questions
What is the main purpose of a checksum?
The main purpose of a checksum is to help detect errors or changes in data. A system calculates a value from the original data and compares it with a value calculated later. A mismatch indicates that the data does not match the expected version. The reliability of the check depends on the algorithm and how the expected value is obtained.
What is a checksum in simple terms?
A checksum is a calculated value that acts like a compact fingerprint for a piece of data. You calculate it before or after transferring a file and compare it with an expected value. If the values differ, something changed or the wrong file or algorithm may have been used.
How do checksums detect file corruption?
A checksum algorithm processes the file’s contents to produce a value. If the file changes, the new calculation may produce a different value. Comparing the new value with a trusted original helps identify corruption or modification, although weak algorithms may fail to detect some changes.
What is an MD5 checksum?
An MD5 checksum is the 128-bit digest produced by the MD5 algorithm, usually displayed as 32 hexadecimal characters. MD5 remains in some legacy workflows, but its collision resistance is broken. Use SHA-256 or another suitable modern cryptographic hash for new security-sensitive verification.
What is a SHA-256 checksum?
A SHA-256 checksum is the 256-bit digest produced by the SHA-256 cryptographic hash algorithm. It is commonly used to compare downloaded files with expected values. Its digest is usually written as 64 hexadecimal characters. SHA-256 helps verify file integrity, but it does not independently authenticate the file’s publisher.
Is a checksum the same as a digital signature?
No. A checksum or hash is a calculated value, while a digital signature is created through a cryptographic signing process. A properly verified digital signature can provide evidence of authenticity and integrity tied to a signing key. A checksum alone does not establish who created a file.
What happens if a checksum does not match?
A mismatch means the file has failed the comparison. Check that you used the correct algorithm, file, version, and expected value. If the mismatch persists, obtain a fresh copy from the official source and investigate before using the file.
Are checksums used in networking?
Yes. Network protocols use checksums or related integrity mechanisms to detect certain errors in transmitted data. Different protocols use different methods, and ordinary network checksums are not a replacement for cryptographic authentication.
Can checksums prevent data corruption?
Checksums can help detect certain forms of corruption, but calculating a checksum does not prevent data from becoming corrupted. Prevention and recovery require additional measures, such as reliable storage, redundancy, backups, retransmission, or error-correcting techniques.
Conclusion
Checksums provide a practical way to detect changes and identify potential data corruption. They are used in downloaded files, software distribution, storage systems, backups, and network communication.
For basic error detection, a simple checksum or CRC may be appropriate. For modern file verification, SHA-256 is a strong general-purpose choice. Always compare the calculated value with a trustworthy expected digest, and remember that integrity checking alone does not guarantee that a file is safe or authentic.