MD5 Hash Generator & Verifier

Generate MD5 hashes from text or files and verify them against an expected checksum. Streams large files in your browser, supports UTF-8/UTF-16/Latin-1/Windows-1252 and hex/base64 input, HMAC-MD5, and hex or base64 output. MD5 is collision-broken: use it for checksums and legacy compatibility only.

MD5 is cryptographically broken

Collisions have been practical since 2004 and now take seconds on a laptop; chosen-prefix collisions were used to forge a real CA certificate in 2008 and to sign the Flame malware in 2012. MD5 is still fine as a fast checksum against accidental corruption and for legacy compatibility (ETags, cache keys, rsync, deduplication) β€” but never for passwords, digital signatures, certificates, or integrity against an attacker. Use SHA-256 for integrity and signatures, and Argon2id for passwords.

Runs entirely in your browser. Browsers have no native MD5, so text and files are both hashed by a WebAssembly module served from this site β€” nothing is uploaded, nothing is logged. Verify it yourself: open DevTools β†’ Network, hash a 2 GB file, and watch zero requests appear after the one-time wasm fetch.

MD5 digest

0 bytes hashed β€” canonical empty-input digest

Fix the input above to see a digest.

Input

0 characters Β· 0 encoded bytes

UTF-8 is what md5sum and every modern web API use. Leave it selected unless you are reproducing a legacy system's hash.

Compare against an expected hash

Paste the publisher's checksum β€” bare hex, base64 (the Content-MD5 header format), an md5sum line (hash filename) or a BSD MD5 (file) = hash tag all work.

The verdict appears as soon as both a digest and an expected hash exist. Works for text and files β€” the browser equivalent of md5sum -c. A match proves the bytes were not corrupted in transit; it does not prove nobody tampered with them.

Other algorithms

Compute MD5, SHA-1, SHA-256 and SHA-512 of the same input to identify an unknown digest or to plan a migration away from MD5.

MD5 password hashes are cracked, not stored

A commodity GPU computes tens of billions of MD5 hashes per second, so an entire leaked table of MD5 password hashes falls in minutes β€” salted or not, and rainbow tables cover the unsalted ones instantly. If you have inherited MD5 password hashes, do not "add a salt": wrap or rehash them on next login with Argon2id, bcrypt (cost β‰₯ 12), scrypt or PBKDF2 with 600,000+ iterations, and treat every old hash as already public.

Why two tools disagree about "the" MD5 of your text

  • β€’ A trailing newline. echo "abc" | md5sum hashes 4 bytes, not 3. Use echo -n or this tool's trailing-newline toggle.
  • β€’ A BOM. UTF-16 (and sometimes UTF-8) files from Windows editors start with 2–3 extra bytes that most online tools silently add and CLIs never do.
  • β€’ The encoding itself. "cafΓ©" is 5 bytes in UTF-8, 4 in Latin-1, 8 in UTF-16 β€” three different digests for the same visible text.
  • β€’ Hex vs base64. HTTP's Content-MD5 and many S3 ETag workflows carry base64, not hex β€” the same 16 bytes in a different alphabet.
  • β€’ Multipart S3 ETags. An ETag containing a dash (-12) is the MD5 of concatenated part MD5s, not of the object, so it will never equal this digest.

Technical specifications

  • β€’ Algorithm: MD5 (RFC 1321, Rivest 1992), 128-bit output
  • β€’ Output: 128 bits = 16 bytes = 32 hex characters = 24 base64 characters
  • β€’ Block size: 512-bit blocks, 64 rounds, Merkle–DamgΓ₯rd construction
  • β€’ Empty input: MD5 of zero bytes is d41d8cd98f00b204e9800998ecf8427e
  • β€’ Security status: collisions practical since 2004 (seconds on a laptop), chosen-prefix collisions since 2009; preimage resistance is still unbroken, which is why HMAC-MD5 has not fallen
  • β€’ Length extension: vulnerable, like every Merkle–DamgΓ₯rd hash β€” never authenticate with md5(secret β€– message)
  • β€’ Engine: hash-wasm WebAssembly MD5 (no browser exposes MD5 through the Web Crypto API), 4 MiB streaming chunks for files
  • β€’ Verification: hex compared case-insensitively, base64 compared case-sensitively (base64 is a case-significant alphabet)

Where MD5 is still legitimately used

Transfer integrity: mirrors that publish an MD5SUMS file, S3's Content-MD5 header, rsync block checks β€” detecting accidental corruption, not tampering.
Cache keys and ETags: a fast, fixed-length fingerprint for content you control and nobody is attacking.
Deduplication: finding identical files in your own storage, where a crafted collision would only hurt the person crafting it.
Database change detection: row-level fingerprints to spot rows that changed between syncs.
Legacy protocols: CRAM-MD5 SMTP authentication, RADIUS, HTTP Digest auth β€” replace when you can, interoperate meanwhile.
Identifying an unknown digest: 32 hex characters could be MD5, MD4, NTLM or RIPEMD-128 β€” Hash Identifier ranks the candidates and shows the Hashcat mode.

About MD5 Hash Generator & Verifier

The MD5 Hash Generator & Verifier computes MD5 digests of text or files and checks them against a hash you already have. Text is hashed live as you type; files are streamed through a WebAssembly MD5 in 4 MiB chunks, so a multi-gigabyte ISO is hashed without ever being loaded into memory. Input can be interpreted as UTF-8, UTF-16LE, UTF-16BE, ISO-8859-1, Windows-1252, raw hex or base64 bytes, and the 128-bit digest can be read as lower-case hex, upper-case hex or base64 β€” the last being the format HTTP's Content-MD5 header and S3 ETags use.

Why use a MD5 Hash Generator & Verifier?

Most online MD5 tools quietly make one of three mistakes: they prepend a byte-order mark to UTF-16 input, they refuse empty input (so you can never see the canonical d41d8cd9… digest), or they lowercase both sides when verifying β€” which breaks base64 comparison, because base64 is case-significant. This tool does none of those. It hashes exactly the bytes you asked for, allows empty input, streams real files instead of pretending text is enough, and tells you which format it compared and why the verdict came out the way it did. It is also honest about what MD5 is for: checksums and legacy interop, never security.

Who is it for?

Developers reproducing an MD5 from a legacy system or a database column, engineers debugging Content-MD5 and S3 ETag mismatches, sysadmins verifying a download against an MD5SUMS file, and anyone migrating old MD5 fingerprints to SHA-256 who needs both digests of the same bytes side by side.

How to use the tool

1

Choose Hash Text to hash typed input, or Hash File to checksum a file from disk.

2

In text mode, type or paste your input β€” the 32-character MD5 digest updates live above the input box, and an empty box shows the canonical empty-input digest d41d8cd98f00b204e9800998ecf8427e.

3

Pick the input encoding: UTF-8 (the default, and what md5sum uses), UTF-16LE/BE, ISO-8859-1, Windows-1252, or raw hex/base64 bytes.

4

If you are reproducing a hash from a file that starts with a byte-order mark, tick 'Prepend a BOM'; leave it off to match command-line tools.

5

Tick 'Append a trailing newline' when reproducing echo "text" | md5sum, which hashes an extra LF byte that echo -n does not add.

6

Copy the digest in lower-case hex, upper-case hex or base64 β€” base64 is what Content-MD5 headers and S3 ETag comparisons expect.

7

In file mode, drop a file onto the drop zone β€” the progress bar shows percentage and MB/s while the file is streamed through MD5 in chunks.

8

Paste the publisher's checksum into 'Compare against an expected hash' for a green match / red mismatch verdict; bare hex, base64, an md5sum line or a BSD MD5 (file) = hash tag are all accepted.

Frequently Asked Questions

How do I generate an MD5 hash of text or a file?

In text mode, type into the input box β€” the 32-character hex digest appears immediately and updates on every keystroke; there is no Generate button. Choose an input encoding first if your source is not UTF-8, because the digest is taken over bytes, not characters. In file mode, drop a file onto the drop zone: it is read in 4 MiB chunks and fed through a streaming MD5, so nothing is uploaded and nothing is held in memory in one piece. Both modes produce results identical to md5sum, md5 -q on macOS and Get-FileHash -Algorithm MD5 on the same bytes.

What is the MD5 hash of an empty string?

d41d8cd98f00b204e9800998ecf8427e, or 1B2M2Y8AsgTpgAmY7PhCfg== in base64. It is the digest of zero bytes, so it is also the checksum of every empty file β€” md5sum /dev/null prints exactly that value, and it is the ETag S3 returns for a zero-byte object and the Content-MD5 of an empty request body. You will meet it constantly as the tell-tale sign that a pipeline hashed nothing at all: an unread stream, a failed download, an empty buffer. Many hash tools refuse empty input, so this tool deliberately allows it and labels the result.

Is it safe to hash sensitive data in this tool?

Yes, in the privacy sense. The tool runs entirely in your browser: browsers expose no native MD5, so text and files are both hashed by a WebAssembly module served from this site. Your input never reaches a server, is never logged and is never stored. Verify it without trusting us: open DevTools, switch to the Network tab, hash a large file and watch zero requests appear after the one-time wasm fetch. Note the separate question of algorithm safety β€” MD5 itself is broken, so never treat an MD5 as proof that data was not tampered with.

Is MD5 broken, and what should I use instead?

MD5's collision resistance has been broken since 2004, and finding a collision now takes seconds on a laptop. Chosen-prefix collisions forged a real CA certificate in 2008 and signed the Flame malware in 2012. MD5 is still acceptable as a fast checksum against accidental corruption, as a cache key or ETag, and for legacy interop β€” but never for passwords, signatures, certificates, or integrity against an adversary. Use [SHA-256](/tools/sha256-hash-generator-verifier/) for integrity and signatures, and [Argon2id](/tools/argon2-hash-generator-verifier/) or [bcrypt](/tools/bcrypt-hash-generator-verifier/) with cost 12+ for passwords.

Why doesn't my UTF-16 MD5 match another tool's?

Almost always a byte-order mark. Many online tools silently prepend FF FE (UTF-16LE) or FE FF (UTF-16BE) before hashing, which adds two bytes and produces a completely different digest. MD5 of "abc" as UTF-16LE without a BOM is ce1473cf80c6b3fda8e3dfc006adc315; with the BOM it is c627105fad747457b7e88ed1016e065f. This tool never adds a BOM unless you tick the checkbox. The second suspect is endianness β€” UTF-16LE and UTF-16BE hold the same characters in opposite byte order, so they never agree (UTF-16BE "abc" is fc48464a2559ee604be70382c39c6687).

Why does echo "abc" | md5sum differ from hashing abc here?

echo appends a newline. "abc" is 900150983cd24fb0d6963f7d28e17f72, but "abc\n" β€” what echo actually pipes β€” is 0bee89b07a248e27c83fc3d5951213c1. Use printf '%s' abc | md5sum or echo -n abc | md5sum to hash three bytes, or tick this tool's 'Append a trailing newline' toggle to reproduce the four-byte version. The same class of bug bites text files: an editor that adds a final newline, or a Windows checkout storing CRLF instead of LF, changes the file's checksum without changing a single visible character.

How do I verify a downloaded file's MD5 checksum?

Switch to Hash File, drop the download in, then paste the publisher's checksum into the compare box β€” an md5sum line (hash, two spaces, filename) or a BSD MD5 (file) = hash tag can be pasted whole. A green verdict means the bytes are identical to what the publisher hashed. One caveat matters more than the checksum itself: with MD5 an attacker who can replace the download can also craft a colliding file, and can usually replace the published hash too. Treat an MD5 match as proof against corruption only, and prefer a GPG signature or a SHA-256 checksum.

Can MD5 be used with a secret key (HMAC-MD5)?

Yes β€” switch on 'Keyed mode: HMAC-MD5'. HMAC (RFC 2104) nests the key with the message, and because it does not rely on collision resistance, HMAC-MD5 has not fallen the way plain MD5 has; that is why CRAM-MD5 SMTP authentication, RADIUS and HTTP Digest still use it. It is nonetheless deprecated for new designs: use HMAC-SHA256. Never authenticate with md5(secret β€– message) β€” MD5 is a Merkle–DamgΓ₯rd hash and is vulnerable to length extension. For more key formats and output encodings, see the [HMAC Generator & Verifier](/tools/hmac-generator-verifier/).

Share This Tool

Found this tool helpful? Share it with others who might benefit from it!

πŸ’‘ Help others discover useful tools! Sharing helps us keep these tools free and accessible to everyone.

Support This Project

Buy Me a Coffee