Hashes look simple until the first practical question: "if I move the file to another folder, does the hash change?", "why does the same contract have two different hashes?", "can someone recover the file from its hash?". These are exactly the questions that show up most in searches — and most articles on the topic answer none of them directly.
If you are not sure what a hash is yet, start with our guide SHA-256 hash: what it is and how to prove a file has not been altered. Here we go straight to the questions.
1. Does moving, copying or renaming a file change its hash?
No. The hash is calculated from the file's content — its exact sequence of bytes. The name, the folder, the modification date your operating system shows and the permissions live outside the file, in the file system. Move it to a USB drive, rename it, copy it to the cloud and download it again: if no byte changed, the hash is the same.
2. Does sending it by email or WhatsApp change the hash?
It depends on how you send it:
- As an email attachment or as a "document" in WhatsApp: the file arrives intact — same hash;
- As a photo or video in WhatsApp and other social apps: the app recompresses the media to save data. The file that arrives is a different one — different hash.
That is why an image that may serve as evidence should be sent as a document, not as a photo.
3. Why do two Word files with the same text have different hashes?
Because a .docx stores much more than the text: author, creation and last-saved dates, total editing time, internal revision identifiers and even the way the file was zipped. Save the same text twice, at different times, and that data changes — so the bytes change, and so does the hash.
A hash proves that two files are identical, not that two texts are the same. To find out whether the text changed between two versions, the right tool is a content comparison — for example, export both to PDF and use the PDF comparison tool, which highlights word by word what changed.
4. Does opening a file change its hash?
Opening it to read, no. Saving it, yes — even without any visible change. Many programs rewrite metadata when saving (Word updates dates and counters; PDF readers may add information if you click "save"). Rule of thumb: a file that serves as evidence is opened, read and closed — never saved over.
5. Can the content be recovered from the hash?
No. A hash is a one-way function: you go from the file to the hash, never back. That is why it is safe to publish the hash of a confidential document — it reveals nothing about its content.
6. Does a hash keep the file confidential?
No — and this is a common confusion. A hash guarantees integrity (the file has not changed), not confidentiality (nobody can read it). Anyone who has the file can still open it. Confidentiality needs another mechanism: encryption with a password. The difference is explained in our guide to document encryption.
7. Is SHA-256 symmetric or asymmetric encryption?
Neither. Symmetric and asymmetric cryptography use keys to encrypt and decrypt. SHA-256 uses no key and does not "decrypt" anything — it is a digest (hash) function. It does appear inside asymmetric systems such as digital signatures: the software calculates the document's hash, and it is that hash that gets signed with the certificate's private key.
8. Can SHA-256 be faked — another file with the same hash?
In practice, no. It would require a "collision" — two different files with the same SHA-256 — and nobody has ever found one; the computing effort is far beyond anything that exists today. That is why SHA-256 is the standard for banks, digital forensics and blockchains.
The same is not true of older algorithms: MD5 and SHA-1 have had collisions demonstrated and should not be used to prove integrity. If someone gives you a 32-character "hash" (MD5) or a 40-character one (SHA-1), ask for the SHA-256 (64 characters).
9. Where is the hash of a PDF? Is it inside the file?
It is not inside the file — and it could not be: anything written inside the PDF would change its own hash. The hash is calculated from the file by whoever needs to check it. That is why it appears in external places: a report, an email, a certificate, a forensic report.
What you often see printed in the footer of documents issued by courts, government systems or registries is a verification code, which you type into the issuer's website to check the document. It plays a similar role, but it is a system identifier, not necessarily the SHA-256 of the file.
And in digitally signed PDFs there is indeed a hash stored inside the signature — the hash of the signed content, which the PDF reader uses to validate the signature. We explain this in the guide on how to verify a signed PDF.
10. How do I check the integrity hash of a PDF?
You need the file and a tool that calculates the hash. The quickest way is to drop the PDF into the integrity checker: the SHA-256 appears instantly, without the file being sent anywhere. If you received a hash to compare, paste it into the check field — if it matches, the file is exactly the same. You can also calculate it on Windows, Mac and Linux from the command line (see the commands in this guide).
The same applies to Excel, Word, photos, videos and ZIP files: hashes work for any file type, not just PDF.
11. Can I look up the hash of someone else's file?
Only if you have a copy of the file. A hash is not a record stored in some public database — it is calculated from the file, on the spot. Without the file, there is no hash to look up. What you can do is ask the other person to calculate and send you the hash, then compare it with your copy.
12. What technique checks whether a file was altered in transit?
Hash verification (also called a checksum). The sender calculates the hash and shares it through a separate channel; the recipient calculates the hash of the received file and compares. If they match, nothing was lost or altered on the way. That is how reputable sites publish software downloads, and how forensic examiners ensure that the copy of a seized drive is identical to the original — see digital evidence and chain of custody.
Bonus: can hashes find duplicate files?
Yes — it is one of the most practical uses. Files with the same SHA-256 are identical, whatever their names. Drop the files into the checker and identical hashes reveal the duplicates, even if they are called contract_final.pdf and contract_final_v2_OK.pdf. More in how to check if two files are identical.
Summary table
| Question | Short answer |
|---|---|
| Does moving, copying or renaming change the hash? | No |
| Does sending as a photo on WhatsApp change it? | Yes (the app recompresses) |
| Same text in two Word files = same hash? | Almost never |
| Does opening the file change it? | No. Saving may |
| Does the hash reveal the content? | No |
| Does the hash protect confidentiality? | No — only integrity |
| Can SHA-256 be faked? | In practice, no (MD5 and SHA-1, yes) |
| Is the hash inside the PDF? | No (except the internal hash of a digital signature) |
Ready to put it into practice?
Free, no sign-up — and your files never leave your computer.
Calculate a file's hash now — free