Hashing and verifying files on a Mac
Practical answers to the things people actually need checksums for — every one of them written against the shipping app, and every algorithm checked against the official NIST test vectors. The same engine powers the free calculators on this site, so you can see a digest resolve before you read a word.
Start Here
How to check a file’s checksum on Mac
The whole job end to end: get the digest, compare it with the published one, and know what to do when the two disagree.
How to use a hash calculator on Mac
The three tools in the sidebar, what each is for, and how to read a screen full of digests without guessing.
What is a checksum, and when do you actually need one?
What the fingerprint actually proves, what it does not, and the four moments in a normal week when it earns its keep.
How to hash a file on Mac without using Terminal
Drag, read, copy. The same answer the command line gives you, without a single flag to remember.
The Rocket Hash window, panel by panel
Every control in the window, what it does, and the quickest route to each one.
Hashing Text
How to hash text on Mac
Type a string, get eight digests live. The free tool, and the details that decide what the answer is.
How to generate a SHA-256 hash on Mac
The algorithm almost everything asks for — how to produce it for a string or a file, and how to read the result.
How to generate a SHA-512 hash on Mac
128 characters instead of 64 — how to produce one, and whether you gain anything by choosing it.
How to generate a SHA-384 hash on Mac
The digest certificate authorities favour — what it is under the hood, and how to produce one.
How to generate a SHA-3 hash on Mac
Keccak, not SHA-2 with a bigger number. How to compute it, and the mistake that wastes an afternoon.
How to generate an MD5 hash on Mac
Still everywhere, still useful for one narrow job, and genuinely unsafe for the other. Both halves explained.
How to generate a SHA-1 hash on Mac
Broken for signatures, alive in Git and in a hundred legacy systems. How to produce one and how far to trust it.
How to calculate a CRC32 checksum on Mac
Eight characters that catch a bad cable and nothing else. How to compute one, and what it is really for.
How to copy every hash at once on Mac
One digest, or all eight in a labelled block, in a single click — and where each form belongs.
How to hash Unicode and emoji text on Mac
Accented letters, emoji and invisible characters all change the bytes. How to see it happen, live.
Files & Folders
How to hash a file on Mac
One read of the disk, every digest you asked for. The route, and what every part of the file row means.
How to hash a folder on Mac
A digest per file, not one digest for the folder — why that distinction matters and how to work with it.
How to hash multiple files at once on Mac
Selecting, queueing and exporting a batch — and what the status bar counts while it runs.
How to hash a large file on Mac
Why file size stops mattering once the read is streamed — and how to plan for a job that runs for an hour.
How to hash an ISO file on Mac
The single most common reason anyone hashes anything — done properly, including where to get the real checksum.
How to hash a DMG file on Mac
What the checksum adds on top of Gatekeeper, and the order to do the two checks in.
How to pause and resume hashing on Mac
Stop mid-file, come back, carry on from the same byte. What survives a pause and what does not.
How to see hashing speed and time remaining on Mac
Read the live rate, work out the wait, and learn which part of the machine is the bottleneck.
How to hash files on an external drive on Mac
USB, SD cards and network shares — what changes, what slows down, and what to check first.
How to hash a ZIP archive on Mac
Two different checks live inside a ZIP. Which one you are running, and which one you actually wanted.
How to hash a photo or video file on Mac
Proving a master file survived a copy intact, and why an export never matches its source.
Verifying Downloads
How to verify a download on Mac
Paste the published checksum, drop the file, read the verdict. Plus where the real checksum lives.
How to verify a SHA-256 checksum on Mac
The specific, common case: one file, one SHA-256 string, one unambiguous answer.
How to compare two files on Mac
Same name, different folders. Same folder, different names. One answer either way.
What to do when a checksum does not match
Nine causes in order of likelihood, and the two-minute route through all of them.
How to tell which hash algorithm a checksum uses
Count the characters and the algorithm usually names itself. The table, plus the three ambiguous lengths.
How to verify a Linux ISO on Mac
Where the checksums really live, how to read a SHA256SUMS file, and what the signature beside it is for.
How to verify a file after transferring it on Mac
The progress bar said it finished. This says it arrived intact — which is a different claim.
How to verify a backup on Mac
Fingerprint once, re-check later, and catch the file that rotted while nobody was looking.
How to check a file has not been tampered with on Mac
What a digest proves about tampering, and the one condition without which it proves nothing.
How to find duplicate files by hash on Mac
Names lie, dates lie, sizes collide. The digest is the only field that settles it.
Manifests & Sharing
How to export a checksum manifest on Mac
From a window full of digests to a file anyone’s tooling can read.
What is a SHA256SUMS file, and how do you read one?
Two columns, one asterisk, and a format that has not changed in thirty years. Line by line.
How to share a checksum with someone
Sending a file and its fingerprint down the same pipe proves nothing. Here is what does.
How to check files against a manifest on Mac
Old list, new folder, one diff. How to line the two up and read the result.
How to checksum a release before you publish it
What to publish, where to put it, and the sentence to write next to it so people use it.
Choosing an Algorithm
Which hash algorithm should I use?
A decision tree, not a ranking. Four questions and you have your answer.
SHA-256 vs SHA-512: which should you pick?
Bigger number, different arithmetic, surprising speed result. When the extra 64 characters buy you anything.
MD5 vs SHA-256: what actually changed
One promise broke, the other did not. Knowing which is which tells you when MD5 is still fine.
SHA-2 vs SHA-3: two different machines
Not a replacement — a spare. What a sponge does that a Merkle–Damgård chain does not.
Is MD5 still safe to use?
Yes for one job, firmly no for the other. The distinction is collision resistance.
Is SHA-1 still safe to use?
Broken in 2017, still in Git, still in your tooling. What that combination actually means.
Should you hash a password with SHA-256?
The right answer is no, and the reason is the same property that makes SHA-256 good at everything else.
How long is a SHA-256 hash?
64 characters, and the table that gives you the length of every other algorithm at a glance.
What is CRC32 actually used for?
Built into ZIP, PNG and Ethernet. Excellent at its job, and its job is not security.
Privacy & Troubleshooting
Why do two tools give different hashes for the same thing?
Six causes, in the order they actually happen. The first one accounts for half of them.
Is it safe to hash files on a website?
How to tell whether a page is uploading your file, and why the answer matters more than it sounds.
How to hash files completely offline on Mac
For anything under an NDA. Compute it with the Wi-Fi off — and check that claim yourself.
Why is hashing slow on my Mac?
Six bottlenecks, and the one-minute test that tells you which of them you are hitting.
What happens if a file changes while it is being hashed?
A digest of a moving target describes a file that never existed. How to spot it and what to do instead.
Permission denied when hashing a folder on Mac
What the sandbox lets through, what it does not, and the three System Settings switches that matter.
Does hashing change or damage a file?
A read-only operation, start to finish. Worth knowing before you point it at a master copy.
How to check that a hashing tool is telling the truth
Three known answers and thirty seconds tells you whether to trust the thing doing the counting.