Security · THE NO-PANIC PLAN
Verify a software download against its published SHA-256
Use this procedure when a software publisher provides a SHA-256 checksum for a specific installer or archive. A match shows that the bytes you checked equal the bytes represented by that reference; it does not prove the reference itself is authentic, that the publisher's account was uncompromised, or that the software is safe. First obtain the expected value from the publisher's authenticated release page or a separately trusted distribution channel. Nirmion Checksum Verifier compares a local file against a supplied digest in the browser; it accepts files up to 100 MB and SHA-256, SHA-384 or SHA-512 values. For larger packages or controlled environments, use the operating system's local hashing command and compare the values yourself.
MISSION Compare the exact software package you downloaded with its publisher's SHA-256 reference, resolve mismatches safely, and record what the check does and does not prove.
Open Checksum VerifierTHE REAL-WORLD BIT
What happens outside this browser tab?
Match the release and package identity; obtain its SHA-256 from an authenticated publisher source; calculate the downloaded file's digest locally or with the browser-based verifier; compare the complete values; stop on mismatch; and record the source, artifact and result before installation.
YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES
One step at a time.
Follow the order below. If a step names a Nirmion tool, its link is right there with it.
- 01
Match the package to the exact release
Identify the publisher, product, version, operating system, CPU architecture, package format and exact filename you intend to install. Open the publisher's release page by navigating to its known official domain or through an independently trusted distribution channel; avoid search ads, unsolicited links and random checksum sites. Confirm the checksum is listed for this exact artifact, not just another installer, mirror, architecture or release. If the publisher does not provide a SHA-256 value, do not invent one by hashing the download and calling it verification: a locally generated digest has no independent reference for comparison. Keep the downloaded file unchanged while you perform the check.
- 02
Capture the publisher's complete SHA-256 reference
On the authenticated release page, locate the SHA-256 value associated with the exact filename and version. Copy all 64 hexadecimal characters and note the page URL, product version, filename, algorithm and date checked. Check whether the publisher publishes a signed checksum manifest or signature and follow its verification instructions when available; a checksum hosted beside a download can be replaced if that same publishing account or channel is compromised. Do not use a value from a forum post, an unrelated mirror or a second page you cannot authenticate. If the publisher lists several algorithms, explicitly choose SHA-256 and keep the expected value tied to its artifact.
- 03
Calculate the digest of the downloaded file
For a local Windows check, open PowerShell and run Get-FileHash -LiteralPath 'C:\path\to\package.exe' -Algorithm SHA256, replacing the example path with the exact downloaded file. Compare the Hash field, not the filename or file size. Alternatively, open Nirmion Checksum Verifier, select the same package and paste the publisher's expected SHA-256 value; the browser calculates the selected file's digest and reports whether it matches. The verifier supports files up to 100 MB and leaves file processing in the browser. If policy forbids browser processing or the package exceeds the limit, use an approved local utility. Do not install or edit the package before hashing it.
- 04
Compare every character and handle a mismatch
Compare the full computed digest with the publisher's full SHA-256 reference. Hexadecimal letter case does not change the value, but a missing character, wrong algorithm, wrong release, wrong architecture or wrong file does. A MATCH means the checked bytes agree with the supplied reference; a NO MATCH means the package is not verified. On mismatch, do not launch, install or redistribute it. Recheck the artifact identity and SHA-256 selection, obtain the reference again from the authenticated publisher source, and download a fresh copy over HTTPS from the official channel. Recalculate once. If it still differs, stop and report the release URL, filename, version and mismatch through the publisher's security/support process; preserve or quarantine the file according to your organization's incident policy.
- 05
Record the result and decide whether installation is appropriate
Record the product/version, exact filename, SHA-256 algorithm, computed digest, reference URL, check time and result in the change, deployment or software intake record. Avoid exposing private filesystem paths in a public report. A passing checksum establishes equality with the particular reference you obtained; it does not identify the author, prove the reference is trustworthy, detect malware, validate a software license or guarantee safe behavior. When offered, also verify the publisher's digital signature or signed checksum manifest using the publisher's documented trust chain, and follow your organization's allowlisting and review controls. Install only after the source, reference and result satisfy your normal software approval process. If the artifact changes or is downloaded again, repeat the check on the new bytes.
THE HELPER CREW
Tools for the fiddly bits.
These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.
RECEIPTS, PLEASE
Sources & review notes
Each source is linked to the steps it supports. Open it to check its scope and current guidance.
Source checked 2026-10-05