What this does
Turns text or a file into its MD5 digest: 128 bits, printed as 32 lowercase hex characters. Typing rehashes on every keystroke; picking a file checksums its bytes. Browsers deliberately leave MD5 out of the Web Crypto API, so this page carries a self-contained RFC 1321 implementation that runs in your tab — nothing is uploaded, files included.
What does an MD5 hash look like?
Always 32 hex characters, no matter how big the input, and a single changed character produces a completely unrelated digest:
(empty string) d41d8cd98f00b204e9800998ecf8427e
abc 900150983cd24fb0d6963f7d28e17f72
The quick brown fox jumps over the lazy dog 9e107d9d372bb6826bd81d3542a419d6
The quick brown fox jumps over the lazy dog. e4d909c290d0fb1ca068ffaddf22cbd0
Those are the canonical RFC 1321 test vectors, handy for checking that
another implementation agrees with this one. Text is UTF-8 encoded before
hashing, so 中文 gives
a7bac2239fcdcb3a067903d8077c4a07 — what md5sum
reports for a UTF-8 file of those two characters. A tool that treats the same
text as Latin-1 or UTF-16 gets a different answer, which is the usual reason
two hashes of "the same" string disagree.
How do I checksum a downloaded file with MD5?
- Choose the file with the file picker below the text box.
- Wait for the digest — large files take a moment, as the whole file is read into memory first.
- Compare it against the publisher's
.md5file or release page, character for character. - To do the same on the command line:
md5sum file.isoon Linux,md5 file.isoon macOS,certutil -hashfile file.iso MD5on Windows.
Why should I not use MD5 for passwords?
MD5 is extremely fast, so an attacker holding a stolen table of MD5 password hashes can test billions of candidates per second on commodity hardware — and unsalted hashes of common passwords are simply looked up in precomputed tables. MD5 has no work-factor knob to slow any of that down. Passwords belong in argon2id, scrypt or bcrypt: deliberately slow, salted per user. Swapping MD5 for SHA-256 does not fix it either, since SHA-256 is also fast by design.
What is an MD5 collision?
Two different inputs producing the same digest. For MD5 these are not theoretical: collisions have been generated on ordinary computers since 2004, and chosen-prefix collisions — where the attacker controls meaningful content on both sides — followed, which is how researchers produced a rogue certificate. The practical rule: MD5 tells you whether a file changed by accident, not whether someone changed it on purpose. If an adversary might be involved, use SHA-256.
What is MD5 still good for?
- Integrity checks against mirrors and flaky transfers, where you are guarding against a truncated download rather than an attacker.
- ETags and cache keys — many web servers and CDNs still derive them from MD5.
- Deduplication: grouping identical assets or rows where a rare collision is a cost, not a breach.
- Legacy interop: APIs that require a
Content-MD5header, database columns typedchar(32), and older vendor integrations that will not change.
Can I reverse an MD5 hash?
Not by inverting it — the function throws information away, and endless inputs map to any given digest. "MD5 decrypt" sites just look your hash up in a huge table of precomputed hashes of common strings. That works depressingly often for short passwords and dictionary words, which is the best argument against putting a secret through MD5, and never for a long random string. If you want something reversible you want encoding, not hashing: see Base64 or URL encode/decode.