How to Check a File's SHA256 Hash on Windows
On Windows, you can check a file's SHA256 hash with the PowerShell Get-FileHash command. No additional software is required. Compare the result with the SHA256 published by the official distributor to check whether your downloaded file matches the original. You can also use certutil in Command Prompt.
What is a SHA256 hash?
SHA256 (Secure Hash Algorithm, 256-bit) takes data, such as a file's contents, and produces a 256-bit hash. It is normally displayed as 64 hexadecimal characters using 0–9 and A–F. A hash is a calculated result; it is not necessarily a property stored inside the file.
The same contents processed with the same algorithm produce the same hash. Renaming or moving a file without changing its contents leaves its SHA256 unchanged. Modifying the contents generally changes the hash. This makes hashes useful for checking whether a file changed during downloading or copying.
SHA256 belongs to the SHA-2 family. For background on the algorithms and their security uses, see the National Institute of Standards and Technology (NIST) hash functions overview.
Check SHA256 with PowerShell
Wait until the download or copy finishes before checking the file. Avoid modifying it while the hash is being calculated. You can normally run the command without administrator privileges if your account has permission to read the file.
- Find the file in File Explorer. On Windows 11, you can right-click it and select Copy as path. You need the full path, including the file name and extension, rather than just the folder address.
- Search for Windows PowerShell in the Start menu and open it. If you use Windows Terminal, select a PowerShell tab. A Command Prompt tab does not directly support
Get-FileHash. - Run the following command after replacing the example path with your file's path. Keep only one pair of quotation marks around the path.
Get-FileHash -LiteralPath 'C:\Users\YourName\Downloads\file.iso' -Algorithm SHA256
-LiteralPath uses the path exactly as entered, so characters such as square brackets in a file name are not treated as wildcards. Single quotation marks also help keep spaces and characters such as dollar signs in the path as literal text.
The result contains these fields:
- Algorithm: the algorithm used. It should be SHA256 in this example.
- Hash: the file's SHA256 value. Compare this field with the distributor's published hash.
- Path: the file that was checked. Confirm that it is the intended file.
If the table output is difficult to read, display the result as a list:
Get-FileHash -LiteralPath 'C:\Users\YourName\Downloads\file.iso' -Algorithm SHA256 | Format-List
SHA256 is the default algorithm for Get-FileHash, so you can omit -Algorithm SHA256. The examples specify it explicitly to avoid confusion with other algorithms. See Microsoft's Get-FileHash documentation for parameters and defaults.
Display or copy only the hash value
To display the hash without the algorithm name or file path, select the result's Hash property. Include the parentheses and the final .Hash.
(Get-FileHash -LiteralPath 'C:\Users\YourName\Downloads\file.iso' -Algorithm SHA256).Hash
Copy all 64 characters. A narrow terminal window may wrap the displayed value onto another line, but that does not split the hash into separate values. Check that you have not omitted characters or copied surrounding labels.
Compare SHA256 with the official checksum
Find the SHA256 for the exact file you downloaded on the official download page or in the official checksum file. Different versions, languages, operating systems, or CPU architectures can have different files and hashes. Do not compare an MD5 or SHA-1 checksum with a SHA256 result.
If you compare the values visually, check the entire hash rather than just its first few characters. Hexadecimal letter case does not affect the value. PowerShell can compare the strings for you:
$expectedHash = 'REPLACE WITH THE OFFICIAL 64-CHARACTER SHA256' $actualHash = (Get-FileHash -LiteralPath 'C:\Users\YourName\Downloads\file.iso' -Algorithm SHA256 -ErrorAction Stop).Hash $actualHash -eq $expectedHash.Trim()
Replace the placeholder on the first line with the published SHA256, then run all three lines. Put only the hash inside the quotation marks, without a file name or a label such as SHA256:. Trim() removes leading and trailing whitespace; it does not remove spaces or line breaks within the value.
- True: the strings match. If the reference hash is trustworthy, this provides strong evidence that the file matches the original.
- False: the values differ. Check the file version, path, algorithm, and copied checksum. If they still differ, hold off on using the file and download it again from the official source.
PowerShell's -eq operator compares strings without distinguishing uppercase and lowercase by default. See Microsoft's comparison operators documentation for details.
The reference hash must also come from a trusted source. If someone alters both a file and its checksum, the values can still match. Prefer the official distributor's checksum over a value in an unverified post. A matching hash does not establish that a file is free of malware or safe to run.
Check SHA256 in Command Prompt
Open Command Prompt from the Start menu and run the following command. In CMD, use double quotation marks around the file path.
certutil -hashfile "C:\Users\YourName\Downloads\file.iso" SHA256
Replace the path with your own. The output includes the hash and a completion message. Compare the 64-character hash, not the completion message. Microsoft's certutil documentation describes the -hashfile option.
Troubleshoot common errors
- File not found: check the folder path, file name, and extension. Make sure you are not using a temporary download file or an old path from before the file was moved.
- Get-FileHash is not recognized: if you entered it in Command Prompt, open PowerShell and try again. Windows Terminal hosts different shells, so check the active tab.
- Access denied or unable to open the file: check whether you have read permission and whether another program has locked the file. Identify the access problem before changing ownership or security settings.
- The calculation takes a long time: hashing reads the entire file. Large ISO images, slow storage, and network locations can take longer. Wait for the current command rather than repeatedly starting it again.
Frequently asked questions
Does calculating SHA256 change the file?
The commands above read the file to calculate its hash. They do not modify its contents or add the hash to the file.
Does a ZIP file have the same hash as its extracted files?
They contain different data, so their hashes generally differ. If the distributor publishes the SHA256 of a ZIP archive, calculate the hash of the ZIP file itself, not an executable extracted from it.
Is it normal for SHA256 to stay the same after renaming a file?
Yes. These commands calculate the hash from the file's contents. Changing only its name or location does not change the hash when the contents remain the same.





