How to Generate MD5, SHA-256 and SHA-512 Hashes

Published on April 5, 2026

Quick summary

Learn what a hash is, how MD5, SHA-1, SHA-256 and SHA-512 differ, when to use each algorithm, and why MD5 is broken for any security use.

Topic: Image tools

A hash is a fixed-length fingerprint produced by a one-way mathematical function: the same input always yields the same output, but the output cannot be reversed back to the input. SHA-256 and SHA-512 are the recommended algorithms for any security-related use, while MD5 and SHA-1 are broken and kept only for legacy checksums. The NeatForge Hash Generator computes all five at once in your browser.

What Is a Hash?

A cryptographic hash function takes arbitrary input (text, a file, a message) and returns a fixed-size string of hex characters. A good hash has three properties:

  • Deterministic — the same input always produces the same hash.
  • One-way — you cannot recover the input from the hash.
  • Avalanche — changing one bit of input completely changes the output.

Hashing is different from encryption: encryption is two-way and reversible with a key, while hashing is one-way. Use hashing for integrity checks and password storage; use encryption for confidentiality.

MD5 vs SHA-1 vs SHA-256 vs SHA-512

AlgorithmOutput lengthSecurity statusTypical use
MD5128 bitsBrokenLegacy checksums only
SHA-1160 bitsBrokenLegacy systems, old Git
SHA-256256 bitsSecureModern checksums, TLS, Git
SHA-512512 bitsSecureHigh-security applications

SHA-256 and SHA-512 belong to the SHA-2 family and are recommended for any new system.

When to Use Each Algorithm

  • Checksums and file integrity — SHA-256 is the modern default. Compare a downloaded file’s hash against the publisher’s value to confirm it was not altered.
  • Git and content addressing — Git historically uses SHA-1, and newer versions support SHA-256 for stronger integrity.
  • Password storage — never use plain MD5 or SHA-1. Use a slow, salted algorithm such as bcrypt, scrypt or Argon2 instead.
  • Legacy system integration — some older APIs still require MD5 or SHA-1; this tool provides them without installing extra software.

Why MD5 Is Broken

MD5 is cryptographically broken: researchers can produce two different inputs with the same MD5 hash (a collision) in seconds on ordinary hardware. For this reason MD5 must never be used for digital signatures, certificate authorities, or password storage. It remains useful only as a quick non-security checksum for legacy systems where collisions are not a threat.

How to Generate a Hash

  1. Open the Hash Generator.
  2. Type or paste the text you want to hash.
  3. Click Compute Hashes to generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at once.
  4. Use the Copy button next to any hash, and toggle uppercase output if your toolchain expects it.

SHA hashes are computed with the browser’s native Web Crypto API (crypto.subtle.digest), which is hardware-accelerated and audited. Your input is never uploaded.

Verifying a Download With SHA-256 in Under a Minute

Published checksums only protect you if you actually compare them. Here is the complete workflow:

  1. Copy the vendor hash. Reputable download pages, GitHub release notes and Linux distribution mirrors publish a SHA-256 string next to the file. Copy it into a text editor where you can see the full value.
  2. Hash your downloaded file locally. No extra software is needed:
    • Windows (PowerShell or Command Prompt): certutil -hashfile Downloads\app-setup.exe SHA256
    • macOS: shasum -a 256 ~/Downloads/app-setup.dmg
    • Linux: sha256sum ~/Downloads/app-setup.iso
  3. Compare character by character. Do not eyeball the first eight characters — check the entire string, since attackers can craft files that match a short prefix. Any decent editor with side-by-side view works, and the uppercase toggle in the Hash Generator helps when the vendor publishes uppercase and your terminal prints lowercase.
  4. Act on a mismatch. Even one differing character means the file is corrupt or tampered with. Delete it, re-download from the official mirror, and verify again before running anything.

One habit makes this painless: verify every executable, disk image and firmware file before you open it, and spot-check archives you received over email or chat. The whole ritual takes under a minute once the commands are familiar.

Reading Hash Lengths at a Glance

Every algorithm produces a fixed digest size, so the length of a hash identifies it on sight:

AlgorithmHex charactersBits
MD532128
SHA-140160
SHA-25664256
SHA-38496384
SHA-512128512

Two rules follow from this table. First, a valid hash contains only the characters 0–9 and a–f; anything else means the value was truncated, wrapped onto two lines, or mixed with a filename during copying. Second, a 64-character value is SHA-256, while a 32-character one is MD5 — if a vendor promises SHA-256 but hands you 32 characters, ask for the correct checksum before trusting the file.

The avalanche effect is easy to see with the word “hello”. Its MD5 is 5d41402abc4b2a76b9719d911017c592 (32 characters) and its SHA-256 is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824 (64 characters). Change the input to “hello!” and both digests change beyond recognition — roughly half of all digits flip. That sensitivity is exactly what makes hashes useful for integrity: any modification, however small, screams through the comparison.

For credential handling, remember the boundary: hashes on this page suit checksums and tokens, while human passwords belong in a slow salted function like bcrypt or Argon2, ideally paired with a secret from the Password Generator.

FAQ

Is MD5 still safe to use? No. MD5 is broken and should never be used for password storage, signatures or any security-sensitive purpose. Use it only for legacy checksum verification.

Which hash should I use? SHA-256 for general use, SHA-512 for high-security applications. Both are part of the SHA-2 family and considered secure.

What is the difference between hashing and encryption? Hashing is one-way and cannot be reversed. Encryption is two-way and can be decrypted with a key. Use hashing for integrity, encryption for confidentiality.

→ Open the free Hash Generator

Advertisement

Frequently asked questions

Which hash algorithm should I use?

SHA-256 is the right default for checksums, file integrity and most new systems. SHA-512 suits high-security contexts and 64-bit pipelines where its larger digest is welcome. Reach for MD5 or SHA-1 only when a legacy protocol forces you to, never by choice.

Is MD5 still safe to use?

No, MD5 is broken for every security purpose because researchers can craft two different inputs with the same hash in seconds. That breaks signatures, certificates and password storage all at once. Keep MD5 strictly for legacy checksum matching where an attacker gains nothing from a collision.

What is the difference between hashing and encryption?

Hashing is one-way, so no key can reverse a digest back into the original input. Encryption is two-way by design and returns the plaintext when you supply the right key. Choose hashing for integrity checks and encryption whenever data must stay confidential yet recoverable.

Can two different inputs produce the same hash?

In theory yes, because every hash has a fixed output size while possible inputs are unlimited, a fact known as the pigeonhole principle. In practice SHA-256 collisions are so unlikely that no one has ever found one. MD5 is the exception, since its collisions can now be manufactured on demand.

How do I verify a downloaded file with its published hash?

Copy the SHA-256 value from the vendor download page, compute the hash of your downloaded file, and compare the two strings character by character. Matching strings prove the file arrived intact, while any difference means a corrupt or tampered download you should delete. The step-by-step section below shows the exact commands for Windows, macOS and Linux.

Should I store passwords with SHA-256?

No, fast hashes like SHA-256 let attackers test billions of guesses per second on cheap graphics cards. Password storage needs a slow, salted function such as bcrypt, scrypt or Argon2 that makes each guess expensive. Use the generator on this page for checksums and tokens, and reach for a proper password-hashing library for credentials.

Explore this topic

Image tools

Read more guides in this cluster and move between related tools faster.

View topic guides

Useful tools

Related Guides