A few quick checks tell you whether the file you downloaded is the one the developer published. None of them can tell you that an app is harmless, but they do catch tampered or swapped files.
1. Compare the SHA-256 hash
A SHA-256 hash is a 64-character fingerprint of a file. Change a single byte and the hash changes completely. If the developer, or the download page here, lists a hash, compare it with your file.
- On Windows: open PowerShell and run
Get-FileHash .\file.apk -Algorithm SHA256. - On macOS or Linux: run
shasum -a 256 file.apkin Terminal. - On Android: several file manager and hash checker apps can show a file's SHA-256. Check the developer of any such app before you install it.
If the hashes match, the file is identical to the one the hash came from. If they don't, don't install it.
2. Check the package name
The package name, such as org.thoughtcrime.securesms for Signal, is the app's unique ID. It appears in the Google Play URL. Fake apps often use a similar-looking name. Each app page here lists the package name where we have confirmed it.
3. Check the signing certificate
Some developers publish the fingerprint of the certificate they sign their APKs with. Signal does this on its APK download page. With the Android SDK's apksigner verify --print-certs file.apk command you can compare it. This is the strongest check, because only the developer has the signing key.
4. Look at the file size
A file that is much smaller or larger than the size listed by the source is a warning sign, though sizes vary between builds for different processors.
What these checks don't tell you
A matching hash only proves the file wasn't changed after the hash was published. It doesn't show what the app does. That still depends on trusting the developer. Our download policy explains which checks we run on any file we host, and we label files "Not scanned" when no malware scan has been done.