What an MD5 hash is
MD5 is a hash function. It takes any input, from one letter to a large file, and produces a fixed-size fingerprint of 128 bits, usually written as 32 hex characters. The same input always gives the same hash. A tiny change, even one character, gives a completely different hash.
Ron Rivest published MD5 in 1992. It is still common for checksums on download pages, for spotting duplicate files, for cache keys and for quick change detection. It is no longer considered secure, which this page covers below.
How to use the MD5 generator
Hash text. Under Hash a, keep Text selected and type or paste into the box. The hashes update as you type. Text is hashed as UTF-8, exactly as entered, including spaces and line breaks.
Hash a file. Press File and choose a file of up to 500 MB. The file is read on your device. The file name and its size in bytes are shown when the hashes are ready.
Read the results. The Hashes panel shows four results:
- MD5, highlighted, 32 hex characters
- SHA-1, 40 characters
- SHA-256, 64 characters
- SHA-512, 128 characters
Each has its own Copy button. Press Uppercase if you need capital letters.
Compare with a known hash. Paste a checksum from a download page into this field. The tool checks it against all four results and tells you which one matches. If nothing matches, it uses the length of your hash to tell you which algorithm it looks like.
How MD5 works
MD5 pads the input to a multiple of 512 bits and processes it in blocks. Each block passes through 64 rounds of bit mixing that combine additions, rotations and logical operations. The final state of four 32-bit words is the hash. Because so much mixing happens, the output looks random and changes completely when any input bit changes. This is called the avalanche effect.
Examples
| Input | MD5 |
|---|---|
| (empty) | d41d8cd98f00b204e9800998ecf8427e |
abc |
900150983cd24fb0d6963f7d28e17f72 |
hello |
5d41402abc4b2a76b9719d911017c592 |
Hello |
8b1a9953c4611296a827abf8c47804d7 |
Hello, World! |
65a8e27d8879283831b664bd8b7f0ad4 |
The quick brown fox jumps over the lazy dog |
9e107d9d372bb6826bd81d3542a419d6 |
The quick brown fox jumps over the lazy dog. |
e4d909c290d0fb1ca068ffaddf22cbd0 |
The last two rows differ by one full stop, yet the hashes share nothing.
The same input, abc, with the other algorithms:
| Algorithm | Hash of abc |
|---|---|
| SHA-1 | a9993e364706816aba3e25717850c26c9cd0d89d |
| SHA-256 | ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad |
Security: what MD5 is and is not good for
Fine: checking that a file arrived without corruption, finding duplicate files, building cache keys, and non-security IDs.
Not fine: passwords, digital signatures, certificates, or proving that a file has not been changed by someone trying to fool you. Practical collision attacks against MD5 have been public since 2004. Attackers can craft two different files with the same MD5.
Passwords need a slow hash. Even SHA-256 is too fast for passwords. Use bcrypt, scrypt or Argon2, which are designed to slow down guessing. A plain MD5 password hash such as 5f4dcc3b5aa765d61d8327deb882cf99 (the word “password”) is recognised at once by any lookup site.
Other ways to get an MD5 hash
Linux. md5sum file.zip prints the hash and file name. echo -n hello | md5sum hashes text. Leave out -n and the new line is hashed too.
macOS. md5 file.zip, or md5 -s hello for text.
Windows. certutil -hashfile file.zip MD5 in Command Prompt, or Get-FileHash file.zip -Algorithm MD5 in PowerShell.
Python. hashlib.md5(b'hello').hexdigest() returns 5d41402abc4b2a76b9719d911017c592.
Node.js. require('crypto').createHash('md5').update('hello').digest('hex') gives the same value.
Related tools
Need a password rather than a hash? Use the strong password generator. For unique IDs, the UUID generator is a better fit than hashing random data. To encode binary data as text, see Base64 encode and decode.