Maybe you saw “SHA-256” printed at the bottom of an evidence export. Maybe the other parent’s lawyer said the “hash values don’t match.” Or maybe you’re worried the other side will claim you edited your photos and screenshots, and someone told you a SHA-256 hash is how digital evidence is protected in family court. It sounds like computer-science homework, but the idea is simple once someone explains it without jargon.

This guide explains what a hash is, what a hash value can and can’t prove about evidence, why two copies of the same photo can have different hashes, how to calculate one yourself for free, and how to keep a simple hash log. None of it requires special software or a technical background.

What is a SHA-256 hash, in plain English?

A SHA-256 hash is a fingerprint of a file. A math formula reads every bit of the file and produces a 64-character code made of the numbers 0 to 9 and the letters a to f. The same file always produces the same code, on any computer, today or years from now.

Change anything in the file, even one character, and the fingerprint changes completely. Here’s a real example. A tiny text file containing exactly “Pickup moved to 6 p.m.” and one containing “Pickup moved to 7 p.m.” produce these hashes (shown in groups of eight characters to make them easier to read):

Example: one character changed

“Pickup moved to 6 p.m.” → f6c87e98 6f0eceaf 9809fbb5 35359ea2 2091e887 a7919e8a 60462bbc c8c24580

“Pickup moved to 7 p.m.” → fefc446c 468353db 65d92a85 dcb5b9e8 bc53e2a3 d420e1de 6cf10d9a 9564ce14

Two more things to know. A hash is one-way: nobody can rebuild your photo or video from its hash, so sharing a hash value doesn’t hand over the file itself. And SHA-256 belongs to a published family of hash standards that is widely used to verify software downloads, secure websites and check copies in digital forensics.

What does a hash value prove about evidence, and what doesn’t it?

A matching hash shows a file is bit-for-bit identical to the file that was hashed earlier. That’s all hash value evidence shows, and it’s both more useful and more limited than many people think.

A matching hash can showA hash cannot show
A copy is identical to the original fileWho created the content or sent the message
A file hasn’t changed since the hash was recordedThat a screenshot wasn’t edited before it was hashed
Your export matches the one you gave the other sideWhen the file was created, unless a dated record shows it
Nothing was added to or removed from a log afterwardThat the content is true, or what it means

The key idea is that a hash protects a file only from the moment it was taken. If you hash a photo the day you take it and record that hash in a dated log, you can later show the photo hasn’t changed since that day. If you hash a screenshot six months later, the hash says nothing about those six months.

Why do two copies of the same photo have different hashes?

Because they aren’t actually the same file. Anything that rewrites the bytes changes the hash, and lots of ordinary actions do that without changing what you see on the screen.

  • Sending it through an app. Many texting apps, email services and social media sites compress photos and videos.
  • Converting the format. Turning an iPhone HEIC photo into a JPEG creates a new file with a new hash.
  • Editing at all. Cropping, rotating, brightening or marking up a picture, then saving it.
  • Screenshotting a photo. A screenshot is a brand-new image, not a copy.

Some things don’t change the hash: renaming a file, moving it to another folder, or copying it exactly to a USB drive or cloud storage that doesn’t alter files. The hash is calculated from the contents, not the file name.

So if someone says “the hashes don’t match,” it means the two files are different, not necessarily that anyone faked anything. The useful question is which file is the original and what happened between the two.

How do you check a SHA-256 hash yourself?

Every Mac and Windows computer can do it for free with tools that are already installed. You type one short command, point it at the file, and it prints the 64-character hash.

  1. On a Mac: open Terminal (search for it with Spotlight), type “shasum -a 256” followed by a space, drag the file into the window, and press Return.
  2. On Windows: open PowerShell, type “Get-FileHash” followed by a space and the file’s path in quotes, and press Enter. SHA-256 is the default. In Command Prompt, “certutil -hashfile” followed by the path and “SHA256” does the same.
  3. On Linux: run “sha256sum” followed by the file name.
  4. Compare carefully. Check all 64 characters, not just the first few. The easiest way is to paste both values into one document and use Find to search for one of them.

Calculating a hash only reads the file; it doesn’t change it. Still, run it on a copy if you’re nervous, since an exact copy has the same hash anyway.

How do you keep a hash log for your evidence?

A hash log is a simple table that records each original file, where it came from and its hash, on the day you saved it. It turns “trust me, I didn’t change it” into something anyone can check.

  • File name and a short description of what it is
  • Where it came from (your phone, your email account, a school portal)
  • The date it was captured or downloaded
  • The date you calculated the hash
  • The full SHA-256 value
  • Where the original is stored (phone, external drive, cloud folder)

Sample hash log entry

IMG_4021.HEIC · Photo of the exchange parking lot · From my phone · Taken 5/2/2026 · Hashed 5/2/2026 · SHA-256: [all 64 characters] · Original on phone and backup drive

Save dated copies of the log as you add to it, and keep it with your capture notes. Our guide to preserving digital evidence before it disappears covers the capture side, and how to prove digital evidence hasn’t been altered shows how hashes fit with metadata and testimony.

How do family courts treat SHA-256 hashes on digital evidence?

As supporting information, not a replacement for testimony. In most courts, whoever offers evidence must show it is what they claim it is, usually through testimony from someone with knowledge, like the person who took the photo or received the message.

A hash can back that testimony up: “This is the photo I took on May 2. I recorded its hash that day, and the copy in front of you has the same hash.” The federal rules of evidence and some states’ rules also allow certain electronic records and copied data to be authenticated with a written certification from a qualified person, and hash values are the usual way to show a copy matches the original. Whether and how that applies in your family court varies, and many family judges rarely see hash values, so be ready to explain yours in one or two plain sentences. Our guide to authenticating a screenshot for court covers the testimony side.

How Custody Commander helps

Keeping a hash log by hand works, but it means running commands file by file and copying 64-character strings into a spreadsheet without a typo. Evidence Helper does the fingerprinting as part of organizing. Your uploaded originals are preserved untouched and hashed, and you set the date each item happened, tag it and map it to the issues in your case. When you export, you get a court-ready PDF that is exhibit-numbered, case-captioned and SHA-256-hashed, generated the same way every time with no AI involved, plus an Evidence Index.

For text messages, Message Extractor adds a SHA-256 digest that fingerprints the finished message log, along with an authentication declaration template you complete yourself. Neither tool makes evidence admissible or proves what it means; they give you clean, checkable records. Every account starts with a 14-day free trial of everything, no credit card.

Try Evidence Helper free for 14 days14 days of everything free · no credit card