MD5 Hash Online (Files / Images)

Drop in a file — image, PDF, archive, installer, anything — or type some text, and get its MD5 straight away, with no limit on file size. You can paste the hash someone gave you and have it checked automatically, confirming the file has not been altered. 16- and 32-character output with an upper-case toggle; everything is computed locally in your browser and nothing is uploaded.
Text input
File upload
Drop a file here, or click to choose one

Images, PDFs, archives, installers — any file, any size

Output options
Checksum
Notes:
1. Use either text input or a file upload — if both are given, the file wins.
2. When the text box is empty, the current timestamp is used as the input.
3. No size limit. The file is read in chunks and hashed block by block, so files of several GB work too; progress is shown on the button.
4. The checksum box accepts a whole md5sum line — “hash + spaces + filename” — and keeps only the hash; it also recognises the 16-character short form.
5. MD5 is a one-way hash function (Chinese usage calls it “encryption”). It cannot be decrypted, and it should no longer be used for anything security-related.

About MD5 “encryption” and decryption

Is MD5 really encryption?

Not strictly. Encryption is reversible — with the key you can recover the original. MD5 is a one-way hash function that compresses input of any length into a fixed 128-bit digest. Information is discarded along the way, so there is no “undo” step to perform. People routinely say “MD5 encryption”, and this page follows that habit — what it means in practice is computing an MD5 value.

One thing that often gets confused: Base64 is neither encryption nor hashing but encoding — fully reversible, decodable by anyone, and meant to let binary data travel through channels that only accept text. Anyone using it to "encrypt" a password has a security problem, not an encryption scheme.

Can MD5 be decrypted?

No. Every site that claims to “decrypt MD5” is really doing a rainbow-table lookup: it precomputes the MD5 of vast lists of common secrets (123456, admin, dictionary words, phone-number prefixes and so on) and stores them. You paste in a hash and it checks whether that hash is in the table. A hit means your input happened to be a common string; a miss means there is nothing more it can do.

The practical conclusion follows: a long random passphrase, or a password that has been salted, cannot be found by any "decryption" site. Turn it around, and if one of those sites looks your password up instantly, it was already sitting in a public dictionary and you should change it now. Replace it with a long one from the Random Password Generator, which never touches the network, so what it produces is known only to you.

So what is MD5 still good for?

It remains a reasonable choice for integrity checks: hash a file after downloading it and compare with the value the publisher gives, to confirm nothing was corrupted in transit — that is exactly what the “Checksum” box above is for, so paste their value in rather than comparing two strings of hex by eye. It is also common for cache keys and de-duplication identifiers, neither of which involves security.

It should not be used for anything security-related. Practical collision attacks have existed for years — producing two different files with the same MD5 takes an ordinary computer seconds — so MD5 cannot detect tampering or back a digital signature. To store user passwords, use a purpose-built slow hash such as bcrypt, scrypt or Argon2, which salt automatically and let you tune the work factor.

16 or 32 characters — which should I pick?

The 32-character form is the complete MD5 value — all 128 bits written in hexadecimal — and it is what you want whenever the result has to match someone else's. The 16-character form is a conventional middle slice of those same 32 characters: a substring, not a different algorithm. Fewer characters means a higher chance of collision, so it only suits display contexts with a length limit.

FAQ

How does MD5 differ from SHA and SHA-256?

MD5 produces a 128-bit (16-byte) hash, SHA-1 produces 160 bits and SHA-256 produces 256 bits. More bits means more theoretical collision resistance. MD5 and SHA-1 have both been broken and are unfit for security use; SHA-256 remains the mainstream secure hash today, and you can compute it with our SHA256 hash generator.

Can an MD5 hash be decrypted?

No. MD5 is a one-way hash function and is irreversible by design. Sites advertising “MD5 decryption” perform rainbow-table lookups, which only succeed for strings already in their table — a long random passphrase or a salted password will not be found. See “About MD5 encryption and decryption” above for the full explanation.

How do I get the MD5 of an image?

Drop the image straight into the upload box above and press “Compute MD5”. JPG, PNG, GIF, WebP and HEIC all behave the same way, because MD5 hashes the bytes of the file and knows nothing about what is inside it — so there is nothing to configure per format. For the same reason, two images that look identical can have completely different MD5s: re-saving once, changing the compression quality, or even just being forwarded through WeChat or QQ (which re-encode and compress) changes the bytes, and the MD5 changes with them. Comparing MD5s is the right way to tell whether two files are the same file; it cannot tell you whether two pictures look the same.

How do I hash a large file such as a PDF or an installer?

Exactly like an image — just drop it in, with no size limit. This page cuts the file into 4 MB slices and feeds them to the hash one at a time, so only one slice is ever in memory and multi-gigabyte PDFs, ISOs and installers all work; progress appears on the button. A large file takes a few seconds to a minute, so leave the page open while it runs.

As long as the bytes are identical, the MD5 must come out the same on any machine and from any tool. If it does not match the value you were given, what that tells you is that the two files differ — usually the download did not finish, you downloaded a web page instead of the file, or the publisher replaced the file without updating the checksum.

How do I use MD5 to check whether a download is intact?

Drop the file into the upload box, paste the publisher's MD5 into the “Checksum” box and press compute: a match shows in green, a mismatch in red. That box takes a whole md5sum line — “hash + spaces + filename” — as well as an md5: prefix and the 16-character short form, so there is nothing to clean up by hand. If what you paste is the wrong length for an MD5 (64 characters, say), the page tells you outright that it is almost certainly SHA-256 and that you want the SHA-256 hash tool page instead.

Is my file uploaded to a server?

No. The whole computation runs in your browser in local JavaScript; the file is neither uploaded nor cached on any server, and this site has no backend that could receive it. That matters most for large files — hashing a 3 GB installer does not require sending 3 GB anywhere first. Disconnect from the network and this page still works; feel free to try it.

What is the difference between 16- and 32-character MD5?

The 32-character form is the complete MD5 hash (128 bits written in hexadecimal). The 16-character form is simply its middle 16 characters (positions 9 through 24). It is not a separate algorithm — just a substring of the 32-character value.