Drop in a file — image, PDF, archive, installer, anything — or type some text, and get its MD5 straight away, with no limit on file size. You can paste the hash someone gave you and have it checked automatically, confirming the file has not been altered. 16- and 32-character output with an upper-case toggle; everything is computed locally in your browser and nothing is uploaded.
About MD5 “encryption” and decryption
Is MD5 really encryption?
Not strictly. Encryption is reversible — with the key you can recover the original. MD5 is a one-way hash function that compresses input of any length into a fixed 128-bit digest. Information is discarded along the way, so there is no “undo” step to perform. People routinely say “MD5 encryption”, and this page follows that habit — what it means in practice is computing an MD5 value.
One thing that often gets confused: Base64 is neither encryption nor hashing but encoding — fully reversible, decodable by anyone, and meant to let binary data travel through channels that only accept text. Anyone using it to "encrypt" a password has a security problem, not an encryption scheme.
Can MD5 be decrypted?
No. Every site that claims to “decrypt MD5” is really doing a rainbow-table lookup: it precomputes the MD5 of vast lists of common secrets (123456, admin, dictionary words, phone-number prefixes and so on) and stores them. You paste in a hash and it checks whether that hash is in the table. A hit means your input happened to be a common string; a miss means there is nothing more it can do.
The practical conclusion follows: a long random passphrase, or a password that has been salted, cannot be found by any "decryption" site. Turn it around, and if one of those sites looks your password up instantly, it was already sitting in a public dictionary and you should change it now. Replace it with a long one from the Random Password Generator, which never touches the network, so what it produces is known only to you.
So what is MD5 still good for?
It remains a reasonable choice for integrity checks: hash a file after downloading it and compare with the value the publisher gives, to confirm nothing was corrupted in transit — that is exactly what the “Checksum” box above is for, so paste their value in rather than comparing two strings of hex by eye. It is also common for cache keys and de-duplication identifiers, neither of which involves security.
It should not be used for anything security-related. Practical collision attacks have existed for years — producing two different files with the same MD5 takes an ordinary computer seconds — so MD5 cannot detect tampering or back a digital signature. To store user passwords, use a purpose-built slow hash such as bcrypt, scrypt or Argon2, which salt automatically and let you tune the work factor.
16 or 32 characters — which should I pick?
The 32-character form is the complete MD5 value — all 128 bits written in hexadecimal — and it is what you want whenever the result has to match someone else's. The 16-character form is a conventional middle slice of those same 32 characters: a substring, not a different algorithm. Fewer characters means a higher chance of collision, so it only suits display contexts with a length limit.