DDateihafen Notes
Guides / Reference note

Verify a file after transfer

A file's name and size are useful checks, but they do not establish that its bytes survived a transfer unchanged. Compare a cryptographic digest produced before and after transfer.

Use SHA-256

# On the source machine
sha256sum archive.tar.gz > archive.tar.gz.sha256

# On the destination, with both files in this directory
sha256sum -c archive.tar.gz.sha256

An OK result means the downloaded bytes match the recorded digest. If the original is untrusted, a matching digest does not make it safe. Obtain the expected digest through a trusted channel or verify a signed release.

Keep a transfer record

Record the original filename, byte size, digest and source. Do not recompress or change line endings between digest generation and verification.

← Back to Guides