How to use a hash calculator on Mac
Three items down the left, a wall of hexadecimal on the right, and somebody waiting for “the SHA-256 of that file”. Ten minutes is genuinely enough to be competent here: this is which of the three tools in Rocket Hash answers the question you actually have, and how to read what comes back without guessing which line you were meant to be looking at.
You have the window open. There are three items in the sidebar, one of them is selected, and depending on which one that is you are looking at either a text field or a column of hexadecimal eight rows deep. Somewhere behind this is a real task — a download page listed a string you are supposed to compare something against, or a colleague asked for a checksum of the file you are about to send them.
This page is the orientation. Which of the three tools does the job you came for, what the digests on screen are telling you, and how to get one out of the window and into the place it needs to go. If the underlying idea is the gap, what a checksum actually proves is the companion read; if you want every button named rather than explained in context, the window panel by panel is the reference.
Text hashing is free, so you can confirm the arithmetic and decide whether the window suits you before anything is unlocked. Files & Folders and Verification are two separate one-time purchases — buy one, the other, or neither.
What a hash calculator actually does
It reads bytes and hands back a fixed-length fingerprint of them. Three letters or a 60 GB disk image: SHA-256 returns exactly 64 hexadecimal characters either way. The output length never varies with the input, which is what makes a digest usable as a name for a thing.
Two consequences are worth carrying around. The same input always produces the same digest — on any machine, in any year, under any operating system — so a digest you wrote down three years ago is still a valid test of whether that file is the same file. And one changed bit in the input moves about half the bits of the output, so the row in front of you will share almost no characters with the row it replaced. Digests are never nearly equal: they match, or they tell you nothing at all about how close you came.
What a calculator does not do is touch the file. Hashing is a read from beginning to end: nothing is written, no modification date moves, nothing is re-encoded or rewrapped. Whether hashing can damage a file answers that properly, and it is worth knowing before you point anything at a master copy.
Which of the three tools you want
The sidebar has exactly three entries, and they are three different questions rather than three views of the same one. Picking the right one first saves more time than anything else on this page.
Text, the cyan Aa icon, hashes what you type as you type it. Reach for it when the thing you want a digest of is something you can put in a text field: a string, a line out of a config file, a token somebody pasted into a chat, or a known test value you are using to check that a tool is honest. It never touches the disk, and it is the free one.
Files, the blue document icon, hashes things that live on disk. Drag in one file, or a folder with a hundred thousand files underneath it, and you get a digest per file — plus a status bar counting progress and an export button that turns the whole run into a text file. This is the tool for when the digest itself is the deliverable.
Verify, the green check badge, answers a yes-or-no question. Hand it a file and a checksum somebody published, or two files you suspect are the same, and it gives you a sentence rather than two strings to compare with your eyes. This is the tool for when the answer is the deliverable and you do not care what the digest was.
That last distinction is the one people get wrong on their first afternoon. If you find yourself copying a digest out of Files so you can paste it next to a published one and squint, you wanted Verify — and checking a file against a published checksum walks that route end to end.
-
Start in the Text tool
Click Text in the sidebar and type anything into the field. Eight digests appear underneath and every one of them recomputes on each keystroke, which is the quickest way to get a feel for how violently the output moves for a small change to the input. The small ⊗ at the top right of the field empties it again.
-
Check it against a known answer
Type the three letters
abc. The byte count under the field should read 3 bytes, and the SHA-256 row should holdba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad— a value published by NIST and identical in every correct implementation on earth. Thirty seconds of this tells you more about whether to trust a hashing tool than any amount of marketing copy. -
Find the row you were asked for
The digests sit under four group headings — SHA-2, SHA-3, CHECKSUM and LEGACY — with a colored chip at the start of each row naming the algorithm. You almost always want the SHA-256 row. The next section is about what the other seven are doing there.
-
Copy the digest out
Click anywhere on a row and that digest goes to the clipboard, which beats selecting 64 characters by hand and missing the last one. If you need several at once, Copy All takes every algorithm in one labeled block — useful in a ticket or a release note, excessive in a chat message. Copying one digest or all of them covers which form belongs where.
-
Point it at the real job
Now that you know the arithmetic is right and where the answer appears, switch to the tool that matches your actual task: Files if you need a digest of something on disk, Verify if you have a published checksum and want a verdict. Text and Files lay their digest rows out the same way; Verify replaces the row with a verdict, which is the one screen where you never read hex at all.
How to read a screen full of digests
Eight results for one input looks like generosity or noise, depending on your mood. It is neither: the eight are four different jobs, and the group headings tell you which job each row belongs to.
| Group | Rows | What it is for |
|---|---|---|
| SHA-2 | SHA-256, SHA-384, SHA-512 | The recommended family. Use SHA-256 unless something specifically asked for another. |
| SHA-3 | SHA3-256, SHA3-512 | Keccak — a completely different internal design, current alongside SHA-2 rather than replacing it. |
| CHECKSUM | CRC32 | Eight characters that catch a bad cable or a truncated copy. Easy to forge on purpose, because resisting anyone was never part of the design. |
| LEGACY | MD5, SHA-1 | Fast, still embedded in a great deal of tooling, and no longer collision-resistant. Fine for matching what an old system already published. |
The length of a digest usually identifies it on sight: 8 hexadecimal characters is CRC32, 32 is MD5, 40 is SHA-1, 96 is SHA-384. The two ambiguous lengths are 64, which is SHA-256 or SHA3-256, and 128, which is SHA-512 or SHA3-512 — and since the two families produce completely different values for the same input, guessing wrong gives you a mismatch with no clue as to why.
If nobody specified an algorithm, the answer is SHA-256. It is what a download page means when it says only “the checksum”, and the cases where the answer is something else are narrow: a legacy system that already published an MD5, a compliance requirement naming SHA-3, or a ZIP file whose own internal check is a CRC32.
The mistake everyone makes in the first hour
Hashing a file and hashing text are different operations, and the Text tool only does the second one. Typing a file's name into the field gives you the digest of that name — the 16 bytes of ubuntu-24.04.iso, not the 6 GB the name points at. Dropping the file itself onto that screen is not how the file gets hashed either; files belong in Files or Verify.
The subtler version catches people who type a line out of a file into the field and expect it to match the digest of the file itself. A one-line text file nearly always ends in a newline you cannot see, and that newline is a byte, and the byte changes the digest — so the file and the line typed into the field legitimately disagree. Why two tools give different hashes runs through that and the five other causes, roughly in the order they actually happen.
What a digest will not tell you
Nothing on that screen carries an opinion about the file. A digest measures bytes, so it cannot tell you who produced them, cannot separate a clean installer from a malicious one that arrived intact, and cannot say where two files differ when their digests disagree — it is a fingerprint, not a diff. Those are limits of the arithmetic rather than of this window, and no tool on any platform gets around them.
The practical version, for the ten minutes you are in: a matching digest closes the question you pointed it at and no other. Turning “these are the same bytes” into “these bytes came from the publisher” needs a signature underneath the checksum, which what a digest proves about tampering takes apart.
Troubleshooting
The digest is cut off in the middle
The row is narrower than the value, so its middle is elided — on screen only. Click the row and the clipboard gets all 64 or 128 characters; paste it somewhere and count them if you want the reassurance.
Nothing happens when I drop a file on the Text screen
Correct, and by design. Text hashes the characters in its field and nothing else. Files and folders go to the Files tool, which takes a drag-and-drop or the add button in its toolbar, and a single file you want checked against a published value goes to Verify instead.
The app cannot read the folder I picked
Nothing is broken. An App Store app starts out fenced off from almost everything, and macOS releases Desktop, Documents, Downloads and external volumes one approval at a time. Anything you hand over yourself counts as that approval, whether you drag it in or pick it through the add button — so select the file or folder rather than expecting the window to go looking for it. Permission denied when hashing a folder has the System Settings route for granting a directory once and for all.
I do not know whether the calculator itself is correct
Then test it, rather than trusting it. NIST publishes digests for a handful of fixed inputs, every implementation worth using agrees with them exactly, and a wrong implementation is obvious within seconds. Checking that a hashing tool is telling the truth has three values and a method that takes about half a minute.
The numbers change while I am still reading them
In the Text tool that is the live recompute doing its job — every keystroke, including the one where your cursor brushed the trackpad, produces an entirely new set of digests. If you need the screen to hold still, stop typing before you copy, and check the byte count matches the input you meant to give it.
Frequently asked questions
What is a hash calculator used for?
Proving that two sets of bytes are the same bytes, when you cannot put them side by side. That covers checking a download against the checksum its publisher listed, confirming a file survived a copy to a USB disk or a server, spotting duplicate files that have different names, and recording what a file looked like today so you can tell in a year whether anything has touched it.
Does macOS show a file’s checksum anywhere?
Nothing in the Finder does. Get Info hands you a name, a size, a kind and a list of dates, and never a digest — which is the gap the three items in the sidebar fill. Drag a file into Files and its digest appears in the row beside the name, with a chevron that opens every algorithm for it; drop it into Verify instead when you already have a published value to hold it against.
Do I have to pay to hash something on my Mac?
No. Hashing text is free — the Text tool gives you all eight algorithms live, with nothing unlocked, no account and no time limit. The two paid parts are independent one-time purchases, Files & Folders and Verification, so you can buy one without the other and neither is a subscription. If you want to watch the arithmetic before you unlock anything, the SHA-256 generator on this site hashes text in a browser tab and uploads nothing — a file still needs the app.
Which algorithm should I choose if nobody told me?
SHA-256. It is what “the checksum” means on a download page, it is what almost every publisher lists, and it has no known weakness. Choose something else only when you are matching a value somebody else already produced, or when a standard you have to comply with names a specific function — see which hash algorithm to use.
Can a checksum tell me whether a file contains malware?
No. A checksum tells you whether a file is the file somebody measured, and malware is perfectly capable of being intact. It is a useful sanity check before you run an installer — a mismatch is a reason to stop — but a match only rules out damage and interference in transit, not bad intent at the source.
Why does it show eight results when I only wanted one?
Because producing all eight costs almost nothing once the input has been read, and because you often do not know in advance which one you will be asked for. Read the row whose chip matches the algorithm you need and ignore the rest; clicking a single row copies only that digest.