What MD5 is
MD5 is a hashing algorithm that turns any data (text, a file) into a string of 32 hexadecimal characters, for example 5d41402abc4b2a76b9719d911017c592 for the word “hello”. The same data always gives the same hash, and the smallest change (even one letter) changes it completely.
MD5 is not encryption
People often search for “MD5 encryption”, but technically it is hashing. Encryption can be decrypted back with a key, while a hash cannot: it is one-way, so the original text cannot be “recovered” from MD5. Still, simple words and short passwords are guessed using ready tables (rainbow tables), so MD5 should not be relied on where security matters.
What MD5 is used for
- Checking file integrity — compare the hash of a downloaded file with the one the author gave and make sure the file is not damaged.
- Finding duplicates — identical files or texts have the same hash.
- Cache keys and identifiers — a short stable string for an address, a request or content.
- Compatibility with old systems — some APIs and CMSs still require an MD5 signature.
Can passwords be stored as MD5
No. MD5 is too fast and has long been considered broken for security: collisions (two different inputs with the same hash) are generated in seconds, and passwords are guessed at billions of attempts per second. For passwords use dedicated algorithms: bcrypt, scrypt or Argon2 with a salt. For signatures and integrity checks choose SHA-256.
MD5, SHA-1, SHA-256 and SHA-512: what is the difference
How to verify a file checksum
Choose a file in the “file hash” block (up to 25 MB): we will calculate all four hashes. Paste the hash given on the author’s site into the “Check a match” field, and we will highlight the algorithm it matches. If there is no match, the file was changed or damaged, or the hash of another algorithm was given.
Limitations of the tool
Text is hashed in UTF-8 encoding, so the hash of Cyrillic will match services that also use UTF-8, but may differ from systems in Windows-1251. We do not process files over 25 MB so as not to overload the browser. Also, the tool cannot decrypt an MD5 hash back, because this is impossible by the very nature of a hash.
What else StayIndexed can do
This page is a free tool from the StayIndexed service. In your account you can save a list of sites and track their indexing, speed, links and technical state, while the service’s main job is to track how your pages do in Google.
How much it costs
The check is free, both on this page and in your account. Tokens are used to pay for the other services: indexing, speed and backlinks cost 3 tokens per check. 30 tokens are credited at sign-up, no card required.
Frequently asked questions
How do I get the MD5 hash of a text online?
Enter or paste the text in the field above: MD5 and three more hashes (SHA-1, SHA-256, SHA-512) are calculated at once. Each can be copied in one click.
Can MD5 be decrypted?
No: a hash is one-way, the original text cannot be recovered from it. Simple words are sometimes found using ready tables, but that is guessing, not decryption.
Why is MD5 called encryption?
Out of habit: people write “MD5 encryption” in queries, although technically it is hashing. In practice users look for a way to turn a string into a hash, and that is exactly what the tool does.
Is it safe to store passwords in MD5?
No. MD5 is too fast and has known collisions. Passwords need bcrypt, scrypt or Argon2 with a salt, and for integrity and signatures SHA-256.
Why does the hash differ from another service?
Most often because of the encoding or an extra space or line break at the end. We use UTF-8; if needed, turn on the “Trim spaces and line breaks at the edges” option.
How much does the online MD5 generator cost?
Nothing: the tool is free both on this page and in your StayIndexed account, and your data does not leave the browser.