Five digests for one string, in one pass
This page is for checking that a download did not get corrupted, or comparing a digest written down somewhere against the string you have now. The text you enter is encoded as UTF-8 bytes, then MD5, SHA-1, SHA-256, SHA-384 and SHA-512 are computed together and shown as lowercase hex, uppercase hex or Base64.
The SHA family is computed with Web Crypto, which is built into the browser. Web Crypto has no MD5, so MD5 alone is computed in the page, and its output was checked against the test vectors published in RFC 1321. A request counter keeps a slow earlier response from overwriting the result of your latest input, so only the newest digest stays on screen.
MD5 and SHA-1 have broken collision resistance: methods are known for producing two different inputs with the same digest. Do not use them for signatures, integrity verification or password storage. Checksums, where no attacker is assumed, are the exception. This page does not reverse a digest and does not rate password strength. Written as of October 2026.
Frequently asked questions
No. MD5 is designed to be fast, which favors bulk guessing, and its collision resistance is broken. Password storage needs a dedicated algorithm with a tunable cost factor.
They should not be used for signatures or integrity verification. They are still used as checksums, for example confirming a downloaded file matches the published build, where no attacker is assumed to be involved.
The input bytes are probably different. Line endings, a trailing space or a UTF-8 BOM all change the digest. This page encodes UTF-8 without a BOM.