What is an MD5 hash?
MD5 (Message-Digest Algorithm 5) was designed by Ronald Rivest in 1991 and published as RFC 1321 in 1992. It reads its input in 512-bit blocks, runs each block through 64 steps of additions, bit rotations and logical functions, and produces a 128-bit digest, normally written as 32 hexadecimal characters. The same input always gives the same hash, and a tiny change gives a completely different one:
| Input | MD5 |
|---|---|
| (empty string) | d41d8cd98f00b204e9800998ecf8427e |
abc | 900150983cd24fb0d6963f7d28e17f72 |
The quick brown fox jumps over the lazy dog | 9e107d9d372bb6826bd81d3542a419d6 |
The quick brown fox jumps over the lazy dog. | e4d909c290d0fb1ca068ffaddf22cbd0 |
These are the standard test values, and the tool above reproduces them exactly, which is a quick way to check that any MD5 implementation is working.
How to use the MD5 generator
- Type or paste text in the Text tab. The MD5 updates as you type. If you have raw bytes, switch the input to hex or Base64.
- To hash a file, open the File tab and choose or drop the file. It is processed in 4 MB pieces, so large ISO images and videos work too.
- Pick lowercase hex (the usual format), uppercase hex (what Windows
certutilprints) or Base64 (used in HTTPContent-MD5headers). - To check a download, paste the checksum from the publisher into Compare with an expected hash. Case and surrounding text such as a file name are ignored.
- Need SHA-256 or several algorithms at once? Use the full hash generator.
MD5 checksums for downloads
The most common reason people need MD5 today is to confirm that a file arrived intact. Many software mirrors, firmware sites, academic data sets and backup tools still publish an MD5 next to each file. If the MD5 you calculate matches the published one, the file was not corrupted in transit. You can also calculate it with built-in commands:
| System | Command |
|---|---|
| Windows Command Prompt | certutil -hashfile file.zip MD5 |
| Windows PowerShell | Get-FileHash file.zip -Algorithm MD5 |
| macOS | md5 file.zip (or md5 -q for the hash only) |
| Linux | md5sum file.zip, or md5sum -c checksums.md5 to check a list |
One caution: a matching MD5 proves the file is not accidentally damaged, but it does not prove nobody tampered with it, because MD5 collisions can be manufactured. If the publisher also offers SHA-256 or a signature, use that for security.
A short history of MD5 collisions
A hash is “broken” when attackers can find two different inputs with the same digest faster than by brute force. For MD5, that happened in stages:
- 1996: Hans Dobbertin found collisions in MD5’s compression function, and cryptographers began recommending a move to other hashes.
- 2004: Xiaoyun Wang and colleagues published full MD5 collisions that could be computed in hours, later reduced to seconds on an ordinary computer.
- 2005: Researchers created two different X.509 certificates with the same MD5 signature.
- 2008: A team led by Alexander Sotirov and Marc Stevens used a chosen-prefix collision to create a rogue certificate authority certificate trusted by browsers. The same year, the U.S. CERT stated that MD5 should be considered cryptographically broken.
- 2012: The Flame espionage malware used an MD5 collision to forge a Microsoft code-signing certificate, showing the attack in real-world use.
What has not been broken is preimage resistance: there is still no practical way to take an MD5 hash and find an input that produces it. That is why MD5 remains acceptable for detecting accidental corruption while being unacceptable for signatures, certificates and anything an attacker controls.
Where MD5 is still used
- Checksums and deduplication: backup tools, file-sync services and storage systems use it to spot changed or duplicate files quickly.
- Cache keys and IDs: turning a long URL or query into a short, fixed-length key.
- Protocol fields: the HTTP
Content-MD5header and the ETag of many object-storage uploads are MD5 values. - Legacy systems: old databases and applications that stored MD5 values, which is why you may need to reproduce one exactly.
Never use MD5 for passwords
MD5 is extremely fast, and that is a flaw for password storage: a single graphics card can try tens of billions of MD5 guesses per second, and unsalted MD5 hashes of common passwords can be looked up instantly in public databases. If you are storing passwords, use bcrypt, Argon2 or scrypt; you can try bcrypt with the bcrypt generator. If you need a keyed checksum for an API, use the HMAC field above, or better, HMAC-SHA-256.
Why your MD5 might not match
MD5 works on bytes, so text must be byte-for-byte identical. The usual culprits are a trailing newline (echo "text" | md5sum adds one; use echo -n or printf), Windows CRLF line endings, extra spaces, and text encoding. This page hashes text as UTF-8. For files, make sure the download finished and you are comparing against the right file version.
Frequently asked questions
How long is an MD5 hash?
An MD5 hash is 128 bits, written as 32 hexadecimal characters or 24 Base64 characters.
Can an MD5 hash be decrypted?
No. MD5 is a one-way hash, not encryption. Short or common inputs can be found by guessing and comparing, which is why MD5 must never be used for passwords.
Is MD5 secure?
Not for security. Collisions can be created in seconds, so MD5 should not be used for signatures, certificates or passwords. It is still fine for spotting accidental file corruption.
How do I check the MD5 of a file?
Open the File tab, choose the file and compare the result with the published checksum. On Windows you can also run certutil -hashfile file MD5, on macOS md5 file, and on Linux md5sum file.
Are my files uploaded?
No. Files are read and hashed in your browser in 4 MB chunks. Nothing is sent to a server.
Why is my MD5 different from another tool?
Usually because the input bytes differ: a trailing newline, CRLF line endings, extra spaces or a different text encoding. This tool hashes text as UTF-8.