PowerShell Get-FileHash: verify a download’s SHA256 checksum

  • Published: 2026.10.07
  • Updated: 2026.10.07
  • Windows

A download page may list a long SHA256 checksum beside an ISO or ZIP file. The filename and size look right, but comparing that long value by eye is easy to get wrong.

PowerShell’s Get-FileHash can calculate the checksum of your local file. Comparing it with the value published by the official distributor helps you check whether the downloaded bytes match.

Find the checksum for your download

Use the official download page to find the SHA256 value for the exact file you downloaded. A different version, CPU architecture, language or file format can have a different checksum. Match the algorithm too: a SHA512 value cannot be compared directly with SHA256.

The commands below work in Windows PowerShell 5.1 and PowerShell 7. Open PowerShell in the folder containing the file and replace .\sample[1].txt with its path. The example uses a small UTF-8 file containing only hello, with no BOM or trailing newline. Your ZIP or ISO will have its own value.

Calculate the file’s SHA256 checksum

$file = '.\sample[1].txt'
$result = Get-FileHash -LiteralPath $file -Algorithm SHA256
$result | Select-Object Algorithm, Hash

-LiteralPath treats the path as a literal filename, so square brackets such as [1] are not interpreted as wildcards. Single quotes also make it convenient to enter a path containing spaces.

SHA256 is the default algorithm, but specifying it explicitly makes the comparison clear. For the sample file, the result is:

Algorithm Hash
--------- ----
SHA256    2CF24DBA5FB0A30E26E83B2AC5B9E29E1B161E5C1FA7425E73043362938B9824

Algorithm identifies the method and Hash contains the calculated value. The command reads the file without changing its contents.

Compare it with the published value

Put the distributor’s SHA256 value in $expected. The value below belongs to the small sample file; replace it when checking a real download.

$expected = '2CF24DBA5FB0A30E26E83B2AC5B9E29E1B161E5C1FA7425E73043362938B9824'
$actual = (Get-FileHash -LiteralPath $file -Algorithm SHA256 -ErrorAction Stop).Hash
$actual -eq $expected.Trim()
True

True means the two checksum strings match; False means they do not. PowerShell’s string comparison with -eq ignores letter case. Trim() removes surrounding whitespace, but leaves spaces inside the value and labels such as SHA256:. Paste just the 64-character checksum.

-ErrorAction Stop stops this calculation if the file cannot be read. If an error appears, resolve the path or access problem before interpreting a comparison result.

Check the file and algorithm when values differ

A mismatch is a reason to revisit the filename, version and algorithm on the download page. If the copied value is correct, try downloading the file again from the official source. A different checksum alone does not identify whether corruption, tampering or a file mix-up caused the difference.

Renaming a file leaves its checksum unchanged when its bytes stay the same. In a text file, a newline, encoding change or BOM can change those bytes. An editor that adds a newline to the sample will produce a different value.

Keep the source of the checksum trustworthy

A matching SHA256 checksum helps compare the download with a trusted published value. It does not, by itself, prove who provided the file or guarantee that it is safe to run. Obtain the checksum from the official distributor and follow its signature-verification advice where available. Avoid substituting MD5 or SHA1 when protection against deliberate tampering matters.

References: Microsoft Learn: Get-FileHash and PowerShell comparison operators.