Compare a Windows Download With the Publisher’s SHA256 Checksum
Some software publishers provide a SHA256 checksum alongside a download. Comparing it with the local file helps establish whether you obtained the exact content described by that reference.
Begin on the publisher’s official page. Match the product version, operating system, architecture and package type. A checksum for a different installer cannot validate the file you actually downloaded, even if their names look similar.
Calculate the value without opening the download
Open Windows PowerShell. Use Get-FileHash with the file’s full path and the SHA256 algorithm. For example: Get-FileHash -LiteralPath 'C:\Downloads\example-installer.exe' -Algorithm SHA256 | Format-List
Replace the example path with your real file location; it is not an instruction to download or run a program with that name. LiteralPath treats the supplied path exactly rather than interpreting wildcard characters. Keep the quotes around a path that includes spaces.
Check the output’s Path and Algorithm before comparing its Hash value. Microsoft documents that hashing follows file content, so renaming a file does not make its contents match another file.
Compare the complete value and keep its context
Compare every character with the publisher’s SHA256 value. Do not accept a match based only on the first and last few characters, and do not compare a SHA256 result with a reference using another algorithm.
If the values differ, stop before running the file. Recheck the selected version and download source, then obtain a fresh copy through the official route if appropriate. Keep the mismatch information if support needs to investigate it.
A matching checksum establishes agreement with the reference you used. It does not independently prove that the reference is trustworthy, that the program suits your computer or that security software should ignore a warning.
For a retained installer, save the official source address, version and verified checksum with your records. This makes a later comparison meaningful rather than leaving an unexplained hexadecimal string beside an ambiguously named file.
Sources: Microsoft Get-FileHash reference.