Free File Hash Checker
Compute a file's cryptographic fingerprint in your browser and check it against our signature list. Upload an email file (.eml) and you get our full phishing analysis instead. Free, private, no account required.
Open the Hash Checker, FreeWhat This Tool Does, and What It Does Not
A file hash is a short fingerprint derived from a file's exact contents. Change one byte and the fingerprint changes completely. That makes hashes a reliable way to ask a narrow question: is this exact file already known to be bad?
That is the question this tool answers. Your browser computes the hash locally, sends only that hash, and we compare it against our signature list. If it matches, you get a clear warning. If it does not match, you get "no known match", which is genuinely different from "safe".
We want to be plain about the limits. This is not an antivirus product. We do not run commercial detection engines, we do not open files or watch what they do, and our signature list is small. Any file that is new, rare, targeted at you specifically, or simply not in our list will return no match no matter how dangerous it is. If you need broad malware detection, use a reputable antivirus product alongside this. Where ScanTotal genuinely adds something is the email analysis below and our URL scanner.
What File Types Can Be Checked?
Any file type up to 50MB can be hashed. These are the types people most often want to check, and the reasons they are risky are worth knowing whatever a hash check returns:
- Executables (.exe, .msi, .dmg): Software installers downloaded from the internet are one of the highest-risk file types. Always scan before installing, even if the source seems legitimate.
- Office documents (.docx, .xlsx, .pptx): Office files can contain macros, small programs embedded in the document. Malicious macros are a common delivery mechanism for ransomware.
- PDF files: PDFs can contain embedded JavaScript and exploits targeting PDF reader vulnerabilities. Fake invoices and shipping notifications are commonly used in phishing campaigns.
- Archive files (.zip, .rar, .7z): Archives frequently pack multiple malicious files together, or hide executables that would otherwise be flagged by email filters.
- Email files (.eml): These receive different and much deeper treatment, full phishing analysis including reported authentication results, link scanning through the URL scanner, and social engineering detection.
- Script files (.js, .vbs, .ps1, .bat): Script files can execute system commands directly and are often delivered as email attachments or hidden inside archives.
How the Hash Checker Works
Hashing happens in your browser. We calculate a SHA-256 hash of your file using your browser's built-in cryptography. The file itself is never uploaded, so nothing sensitive leaves your device.
Signature comparison. Only the hash is sent to us and compared against our signature list. A match returns an immediate warning naming what we hold for that hash.
Email files take a different path. Upload an .eml and we parse the message instead: we report the authentication results the receiving mail server recorded, run every link in the body through the full URL scanner, flag attachment filenames with risky extensions, and identify social engineering patterns such as manufactured urgency, impersonation, and fake verification requests. This is the most substantial analysis on this page.
Results are explicit about certainty. You get one of four outcomes: known malicious, no known match, result unavailable, or check failed. We never convert an absent match into a clean verdict.
How to Read Your Result
- Known malicious. The hash matched a signature we hold. Do not open the file. Delete it, and if it arrived by email or message, report the sender.
- No known match. The hash was not in our list. This is the most common result and it is not a clean bill of health. Judge the file on where it came from: an unexpected attachment, a download from a link in a message, or a file from someone you cannot verify all deserve suspicion regardless of what any scanner says.
- Result unavailable. The lookup did not reach us, so no check was performed. Treat the file as unverified and try again.
- Check failed. Something went wrong during the check. Same advice: nothing was verified.
If you want to understand what different scanners can and cannot tell you, our guide on how to read a security scan report covers this in more depth.
Your Privacy Is Protected
- Your file is never uploaded. Hashing happens inside your browser and only the resulting hash is sent.
- The hash cannot be used to reconstruct your file or reveal anything about its contents.
- We do not require an account, email address, or any personal information.
- We record an anonymous count of how many checks of each type are run, so we can publish our threat statistics. That count contains no file names, no hashes and nothing identifying you.
Because the file stays on your device, you can check sensitive documents, work files, and personal files without them leaving your machine. Our privacy policy sets out exactly what is stored.
Frequently Asked Questions
What is the maximum file size?
ScanTotal accepts files up to 50MB, covering the vast majority of files received by email or downloaded from the internet.
Is email file (.eml) checking different from a regular file check?
Yes, and it is the more thorough of the two. Email files get full phishing analysis: we report the authentication results the receiving server recorded, extract and scan every link through the URL scanner, flag risky attachment filenames, and look for social engineering patterns. A regular file check is only a hash comparison.
Does "no known match" mean my file is safe?
No, and this is the most important thing to understand about hash checking. It means the file's fingerprint was not in the limited signature list we check. We do not run commercial antivirus engines and we do not inspect what a file does when opened. Anything new, rare, or targeted specifically at you will not match a signature anywhere. Read it as "not yet known", never as "safe", and judge the file on where it came from.
Should I use this instead of antivirus software?
No. This is a narrow tool that answers one question: is this exact file already known to us. Keep using a reputable antivirus product for real-time protection and broad detection. This is a quick second opinion, not a replacement.
Do I need to install any software?
No. ScanTotal is entirely web-based. Open it in any browser and start scanning immediately, no installation, no plugins, no account required.
Related Articles
Check a File Hash, or Analyse an Email
Hashing happens in your browser, so the file never leaves your device. Free, private, no account needed.
Open the Hash Checker, Free