Drop a file to hash it locally. Compute MD5, SHA-1, SHA-256, and SHA-512 checksums for integrity verification — no file is ever uploaded.
RookHash computes file checksums entirely in your browser using the File API and Web Crypto. Large files are hashed in chunks. The file never leaves your device.
SHA-256 is the modern standard for software distribution and download verification. MD5 is still used in some legacy systems but should not be considered secure for cryptographic purposes.
File Checksum Generator exists to hash a local file with MD5, SHA-256, or SHA-512 and compare the digest to the publisher. It is not a second copy of the tool homepage. The homepage introduces the whole product. This page stays on one job so a search for that job lands on instructions you can follow without hunting through other tabs. Read the result on this page against the input you actually used. A screenshot without the input is not evidence. If the result surprises you, change one thing and run it again before you change your VPN, browser, or server config.
Work through File Checksum Generator in order. 1. Drop the file. It stays on the machine. 2. Read the algorithm the publisher used, not the one you prefer. 3. Compare hex. 4. Delete the download if the digest does not match and fetch it again. Write down the input and the output together. When you ask someone for help, send both. Repeat the same input once. A stable tool returns the same answer. If it does not, the input changed or the page is talking to a different network path than you think.
A matching MD5 is weaker evidence than a matching SHA-256. The tool hashes the file you dropped, which might be a partial download. It does not scan for malware. Treat the output as a measurement, then decide. RookVPN does not log the contents of a client-side tool, and a measurement is not a promise that every other app on the device behaves the same way. Compare a second path when the decision matters: a terminal command, another browser, or the matching guide linked below.
Example: the release notes print SHA-256. You drop the file and compare that line, not the MD5 line that happens to be first on the page. A mismatch of one character means you do not install. A match means the bytes are the bytes they hashed, not that the publisher is trustworthy.
After you finish File Checksum Generator, open the SHA-256 page for a pasted string, or the MD5 page only if the publisher gave you MD5 if the next question is different from the one this page answers. Stay here if you are still on the same job. Extra pages help only when they answer a new question, such as a different algorithm, a different leak channel, or a different file type. The documentation link on this page is the long form of the same workflow, including the checks that do not fit in the tool UI.
A checksum is a short hash derived from a file's contents. Matching checksums confirm the file has not been modified or corrupted during transfer.
MD5 is adequate for detecting accidental corruption but is cryptographically broken — it should not be used for security-sensitive verification. Use SHA-256 instead.
On Windows: certutil -hashfile file.zip SHA256. On macOS: shasum -a 256 file.zip. Compare the output to the published hash.
The one printed next to the file you downloaded.
No.
The download did not finish. Hashing it will not match, and should not.