Know what the comparison proves
A cryptographic hash is a fingerprint of file contents. If the SHA-256 digest of your download matches an independently trusted publisher checksum, the contents match the file represented by that checksum. This helps detect corruption or substitution. It does not prove the software is harmless.
The trust source matters. A malicious site can provide both a malicious file and a matching hash. Prefer the vendor's official release page and, where supplied, its documented signature-verification process.
Calculate the local digest
Keep the file unopened. In Windows PowerShell:
Get-FileHash -Algorithm SHA256 -LiteralPath 'C:\Mina\Downloads\installer.exe'Replace the path with the actual existing file. LiteralPath avoids treating special wildcard characters in a filename as a pattern. The command reads the file; it does not execute it.
Compare the right values
- Obtain the SHA-256 value for the exact release, platform and filename from the genuine publisher.
- Confirm both sides use SHA-256. Comparing SHA-256 with MD5 will never give a meaningful match.
- Compare every hexadecimal character. Letter case does not change the represented value.
- If it differs, stop. Recheck the version and download source before trying another download.
For a scripted comparison, use a real expected value copied from the trusted source, not a tutorial sample:
$expectedHash = Read-Host 'Paste trusted SHA-256'
if ($expectedHash -notmatch '^[a-fA-F0-9]{64}$') {
throw 'Expected exactly 64 hexadecimal characters'
}
$actualHash = (Get-FileHash -Algorithm SHA256 -LiteralPath 'C:\Mina\Downloads\installer.exe').Hash
$actualHash -eq $expectedHashVerify the decision
True indicates equality; False means the file and expected digest differ. Preserve the release URL and digest in your change record when appropriate. If the command cannot read the file, resolve the path or permissions instead of reporting a match.
Common mistakes
Do not hash a similarly named file or an extracted component when the published digest is for the whole archive. Antivirus results and checksums answer different questions. Avoid using MD5 or SHA-1 as the primary integrity choice for new security-sensitive workflows when a modern digest is available.
Privacy
This local calculation does not upload the file. That makes it useful for large or confidential downloads, while still requiring a trustworthy source for the expected value.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.