How to Check a File's SHA256 Hash on Windows

On Windows, you can check a file's SHA256 hash with the PowerShell Get-FileHash command. No additional software is required. Compare the result with the SHA256 published by the official distributor to check whether your downloaded file matches the original. You can also use certutil in Command Prompt.

What is a SHA256 hash?

SHA256 (Secure Hash Algorithm, 256-bit) takes data, such as a file's contents, and produces a 256-bit hash. It is normally displayed as 64 hexadecimal characters using 0–9 and A–F. A hash is a calculated result; it is not necessarily a property stored inside the file.

The same contents processed with the same algorithm produce the same hash. Renaming or moving a file without changing its contents leaves its SHA256 unchanged. Modifying the contents generally changes the hash. This makes hashes useful for checking whether a file changed during downloading or copying.

SHA256 belongs to the SHA-2 family. For background on the algorithms and their security uses, see the National Institute of Standards and Technology (NIST) hash functions overview.

Check SHA256 with PowerShell

Wait until the download or copy finishes before checking the file. Avoid modifying it while the hash is being calculated. You can normally run the command without administrator privileges if your account has permission to read the file.

  1. Find the file in File Explorer. On Windows 11, you can right-click it and select Copy as path. You need the full path, including the file name and extension, rather than just the folder address.
  2. Search for Windows PowerShell in the Start menu and open it. If you use Windows Terminal, select a PowerShell tab. A Command Prompt tab does not directly support Get-FileHash.
  3. Run the following command after replacing the example path with your file's path. Keep only one pair of quotation marks around the path.
Get-FileHash -LiteralPath 'C:\Users\YourName\Downloads\file.iso' -Algorithm SHA256

-LiteralPath uses the path exactly as entered, so characters such as square brackets in a file name are not treated as wildcards. Single quotation marks also help keep spaces and characters such as dollar signs in the path as literal text.

The result contains these fields:

  • Algorithm: the algorithm used. It should be SHA256 in this example.
  • Hash: the file's SHA256 value. Compare this field with the distributor's published hash.
  • Path: the file that was checked. Confirm that it is the intended file.

If the table output is difficult to read, display the result as a list:

Get-FileHash -LiteralPath 'C:\Users\YourName\Downloads\file.iso' -Algorithm SHA256 | Format-List

SHA256 is the default algorithm for Get-FileHash, so you can omit -Algorithm SHA256. The examples specify it explicitly to avoid confusion with other algorithms. See Microsoft's Get-FileHash documentation for parameters and defaults.

Display or copy only the hash value

To display the hash without the algorithm name or file path, select the result's Hash property. Include the parentheses and the final .Hash.

(Get-FileHash -LiteralPath 'C:\Users\YourName\Downloads\file.iso' -Algorithm SHA256).Hash

Copy all 64 characters. A narrow terminal window may wrap the displayed value onto another line, but that does not split the hash into separate values. Check that you have not omitted characters or copied surrounding labels.

Compare SHA256 with the official checksum

Find the SHA256 for the exact file you downloaded on the official download page or in the official checksum file. Different versions, languages, operating systems, or CPU architectures can have different files and hashes. Do not compare an MD5 or SHA-1 checksum with a SHA256 result.

If you compare the values visually, check the entire hash rather than just its first few characters. Hexadecimal letter case does not affect the value. PowerShell can compare the strings for you:

$expectedHash = 'REPLACE WITH THE OFFICIAL 64-CHARACTER SHA256'
$actualHash = (Get-FileHash -LiteralPath 'C:\Users\YourName\Downloads\file.iso' -Algorithm SHA256 -ErrorAction Stop).Hash
$actualHash -eq $expectedHash.Trim()

Replace the placeholder on the first line with the published SHA256, then run all three lines. Put only the hash inside the quotation marks, without a file name or a label such as SHA256:. Trim() removes leading and trailing whitespace; it does not remove spaces or line breaks within the value.

  • True: the strings match. If the reference hash is trustworthy, this provides strong evidence that the file matches the original.
  • False: the values differ. Check the file version, path, algorithm, and copied checksum. If they still differ, hold off on using the file and download it again from the official source.

PowerShell's -eq operator compares strings without distinguishing uppercase and lowercase by default. See Microsoft's comparison operators documentation for details.

The reference hash must also come from a trusted source. If someone alters both a file and its checksum, the values can still match. Prefer the official distributor's checksum over a value in an unverified post. A matching hash does not establish that a file is free of malware or safe to run.

Check SHA256 in Command Prompt

Open Command Prompt from the Start menu and run the following command. In CMD, use double quotation marks around the file path.

certutil -hashfile "C:\Users\YourName\Downloads\file.iso" SHA256

Replace the path with your own. The output includes the hash and a completion message. Compare the 64-character hash, not the completion message. Microsoft's certutil documentation describes the -hashfile option.

Troubleshoot common errors

  • File not found: check the folder path, file name, and extension. Make sure you are not using a temporary download file or an old path from before the file was moved.
  • Get-FileHash is not recognized: if you entered it in Command Prompt, open PowerShell and try again. Windows Terminal hosts different shells, so check the active tab.
  • Access denied or unable to open the file: check whether you have read permission and whether another program has locked the file. Identify the access problem before changing ownership or security settings.
  • The calculation takes a long time: hashing reads the entire file. Large ISO images, slow storage, and network locations can take longer. Wait for the current command rather than repeatedly starting it again.

Frequently asked questions

Does calculating SHA256 change the file?

The commands above read the file to calculate its hash. They do not modify its contents or add the hash to the file.

Does a ZIP file have the same hash as its extracted files?

They contain different data, so their hashes generally differ. If the distributor publishes the SHA256 of a ZIP archive, calculate the hash of the ZIP file itself, not an executable extracted from it.

Is it normal for SHA256 to stay the same after renaming a file?

Yes. These commands calculate the hash from the file's contents. Changing only its name or location does not change the hash when the contents remain the same.

More in This Category
How to Check a File's SHA256 Hash on Windows

How to Check a File's SHA256 Hash on Windows

Calculate a file's SHA256 hash using PowerShell or Command Prompt, compare it with the official checksum, and troubleshoot common errors.

What Is a Windows Prefetch PF File? Contents, Analysis, and Deletion

What Is a Windows Prefetch PF File? Contents, Analysis, and Deletion

Learn what Windows Prefetch PF files record, how to inspect them, and why run counts, timestamps, and file paths need careful interpretation before you delete or investigate a record.

Windows 11 / Notepad Keyboard Shortcuts for Files, Tabs, and Editing

Windows 11 / Notepad Keyboard Shortcuts for Files, Tabs, and Editing

A practical reference to Windows 11 Notepad shortcuts for files, tabs, editing, search, and zoom. It also explains the difference between closing a tab and a window and what to check when a shortcut does not work.

Windows 11 / Three Ways to Open Notepad

Windows 11 / Three Ways to Open Notepad

Open Notepad in Windows 11 from the Start menu, Windows Search, or the Run dialog. Follow the illustrated steps and learn what to check if the app does not appear.

Windows 11 / What Is Windows.old, and Can You Delete It?

Windows 11 / What Is Windows.old, and Can You Delete It?

You can remove Windows.old to free space in Windows 11, but doing so ends the option to return to the previous installation. Learn what to check first, when Windows removes it automatically, and how to delete it through Storage settings.

How to Enable Remote Desktop on Windows 11

How to Enable Remote Desktop on Windows 11

Learn how to enable Remote Desktop on a Windows 11 PC, allow users, and test a connection. This guide also explains the Windows Home limitation and security considerations for access from another network.