MD5 Hash Generator

Calculate the MD5 hash of any text or file instantly. Files are read in chunks on your own device, so even multi-gigabyte downloads can be checked without uploading anything. Paste a published checksum below the result to confirm a match.

What is an MD5 hash?

MD5 (Message-Digest Algorithm 5) was designed by Ronald Rivest in 1991 and published as RFC 1321 in 1992. It reads its input in 512-bit blocks, runs each block through 64 steps of additions, bit rotations and logical functions, and produces a 128-bit digest, normally written as 32 hexadecimal characters. The same input always gives the same hash, and a tiny change gives a completely different one:

InputMD5
(empty string)d41d8cd98f00b204e9800998ecf8427e
abc900150983cd24fb0d6963f7d28e17f72
The quick brown fox jumps over the lazy dog9e107d9d372bb6826bd81d3542a419d6
The quick brown fox jumps over the lazy dog.e4d909c290d0fb1ca068ffaddf22cbd0

These are the standard test values, and the tool above reproduces them exactly, which is a quick way to check that any MD5 implementation is working.

How to use the MD5 generator

  1. Type or paste text in the Text tab. The MD5 updates as you type. If you have raw bytes, switch the input to hex or Base64.
  2. To hash a file, open the File tab and choose or drop the file. It is processed in 4 MB pieces, so large ISO images and videos work too.
  3. Pick lowercase hex (the usual format), uppercase hex (what Windows certutil prints) or Base64 (used in HTTP Content-MD5 headers).
  4. To check a download, paste the checksum from the publisher into Compare with an expected hash. Case and surrounding text such as a file name are ignored.
  5. Need SHA-256 or several algorithms at once? Use the full hash generator.

MD5 checksums for downloads

The most common reason people need MD5 today is to confirm that a file arrived intact. Many software mirrors, firmware sites, academic data sets and backup tools still publish an MD5 next to each file. If the MD5 you calculate matches the published one, the file was not corrupted in transit. You can also calculate it with built-in commands:

SystemCommand
Windows Command Promptcertutil -hashfile file.zip MD5
Windows PowerShellGet-FileHash file.zip -Algorithm MD5
macOSmd5 file.zip (or md5 -q for the hash only)
Linuxmd5sum file.zip, or md5sum -c checksums.md5 to check a list

One caution: a matching MD5 proves the file is not accidentally damaged, but it does not prove nobody tampered with it, because MD5 collisions can be manufactured. If the publisher also offers SHA-256 or a signature, use that for security.

A short history of MD5 collisions

A hash is “broken” when attackers can find two different inputs with the same digest faster than by brute force. For MD5, that happened in stages:

What has not been broken is preimage resistance: there is still no practical way to take an MD5 hash and find an input that produces it. That is why MD5 remains acceptable for detecting accidental corruption while being unacceptable for signatures, certificates and anything an attacker controls.

Where MD5 is still used

Never use MD5 for passwords

MD5 is extremely fast, and that is a flaw for password storage: a single graphics card can try tens of billions of MD5 guesses per second, and unsalted MD5 hashes of common passwords can be looked up instantly in public databases. If you are storing passwords, use bcrypt, Argon2 or scrypt; you can try bcrypt with the bcrypt generator. If you need a keyed checksum for an API, use the HMAC field above, or better, HMAC-SHA-256.

Why your MD5 might not match

MD5 works on bytes, so text must be byte-for-byte identical. The usual culprits are a trailing newline (echo "text" | md5sum adds one; use echo -n or printf), Windows CRLF line endings, extra spaces, and text encoding. This page hashes text as UTF-8. For files, make sure the download finished and you are comparing against the right file version.

Frequently asked questions

How long is an MD5 hash?

An MD5 hash is 128 bits, written as 32 hexadecimal characters or 24 Base64 characters.

Can an MD5 hash be decrypted?

No. MD5 is a one-way hash, not encryption. Short or common inputs can be found by guessing and comparing, which is why MD5 must never be used for passwords.

Is MD5 secure?

Not for security. Collisions can be created in seconds, so MD5 should not be used for signatures, certificates or passwords. It is still fine for spotting accidental file corruption.

How do I check the MD5 of a file?

Open the File tab, choose the file and compare the result with the published checksum. On Windows you can also run certutil -hashfile file MD5, on macOS md5 file, and on Linux md5sum file.

Are my files uploaded?

No. Files are read and hashed in your browser in 4 MB chunks. Nothing is sent to a server.

Why is my MD5 different from another tool?

Usually because the input bytes differ: a trailing newline, CRLF line endings, extra spaces or a different text encoding. This tool hashes text as UTF-8.