Verify a download

Every file on this site lists a SHA-256 checksum, and says whether it is code-signed. Checking both takes under a minute.

1. Check the SHA-256 checksum

Open PowerShell in the folder where you saved the file and run:

Get-FileHash .\FileName.exe -Algorithm SHA256

Compare the Hash value with the SHA-256 shown next to the download. They must match exactly (upper or lower case does not matter). To have PowerShell compare them for you:

(Get-FileHash .\FileName.exe -Algorithm SHA256).Hash -eq "PASTE-THE-HASH-FROM-THIS-SITE"

True means the file is identical to the one we published. From Command Prompt you can use certutil -hashfile FileName.exe SHA256 instead.

2. Check the code signature (signed files only)

Files marked Signed carry an Authenticode signature. Right-click the file, choose Properties, then the Digital Signatures tab. Or run:

Get-AuthenticodeSignature .\FileName.exe

Status should be Valid. If a file marked Signed shows no signature or an invalid one, do not run it, and tell us.

What each check proves

  • A matching checksum proves the file was not corrupted or swapped on the way to you. It does not help if this website itself were compromised, because the checksum comes from the same place as the file.
  • A valid signature proves the file was signed by the holder of our signing certificate, independently of this website.

Windows warnings

Windows marks downloaded files as coming from the internet.

  • New or unsigned programs may show "Windows protected your PC" (SmartScreen). This is common for new releases and does not by itself mean a file is unsafe. Verify the checksum first.
  • PowerShell may refuse to run a downloaded, unsigned script. After you have verified its checksum, you can clear the internet mark with Unblock-File .\ScriptName.ps1.

Only unblock files you downloaded from this site and verified.