Verify a file after transfer
A file's name and size are useful checks, but they do not establish that its bytes survived a transfer unchanged. Compare a cryptographic digest produced before and after transfer.
Use SHA-256
# On the source machine
sha256sum archive.tar.gz > archive.tar.gz.sha256
# On the destination, with both files in this directory
sha256sum -c archive.tar.gz.sha256An OK result means the downloaded bytes match the recorded digest. If the original is untrusted, a matching digest does not make it safe. Obtain the expected digest through a trusted channel or verify a signed release.
Keep a transfer record
Record the original filename, byte size, digest and source. Do not recompress or change line endings between digest generation and verification.