How to Verify 7-Zip Backups Match Source Hashes
Verifying that a 7-Zip compressed backup perfectly matches your
source data requires comparing individual file checksums rather than
comparing the final .7z file hash to the original folder.
Because compression, archive headers, and metadata alter the overall
container hash, verification relies on generating cryptographic
checksums (such as SHA-256) of your source files and checking them
against the contents stored within the archive. This guide covers how to
extract and match these hashes using 7-Zip's built-in hashing features
and command-line checksum tools.
Why Direct File-to-Archive Hashing Fails
A .7z archive is a container that compresses data and
adds structural metadata, timestamps, and headers. Calculating a SHA-256
hash of backup.7z will never match the hash of the original
directory or files. To confirm that the backup is an exact duplicate,
you must verify the integrity of the uncompressed data streams contained
inside the archive.
Method 1: Using 7-Zip's Built-in Hash Command
7-Zip includes a native hashing command (h) that can
calculate checksums for files on your drive as well as the uncompressed
files stored inside an archive, without needing to extract the archive
to disk.
Step 1: Calculate Hashes for the Source Files
Open your terminal (Command Prompt, PowerShell, or Linux terminal) and run:
7z h -scrcSHA256 "C:\Path\To\Source\*"This command outputs the individual SHA-256 hashes of every file in the directory, followed by a cumulative hash for the entire data stream.
Step 2: Calculate Hashes for the Archive Contents
Run the hash command directly against the .7z
archive:
7z h -scrcSHA256 "C:\Path\To\backup.7z"7-Zip will decompress the archive in memory and calculate the SHA-256 hashes of the files inside.
Step 3: Compare the Outputs
Compare the individual file hashes and the final summary hash from both operations. If the cumulative data stream hashes match, the files stored in the archive are identical to the source files.
Method 2: Generating a Checksum Manifest
For automated or mission-critical backups, generating an independent checksum manifest file prior to compression is the standard practice.
Step 1: Create a Checksum File of Source Data
Generate a manifest containing the relative paths and hashes of all source files.
On Linux / macOS:
cd /path/to/source find . -type f -exec sha256sum {} + > manifest.sha256On Windows (PowerShell):
Get-ChildItem -Recurse -File | Get-FileHash -Algorithm SHA256 | Select-Object Hash, Path | Export-Csv -NoTypeInformation manifest.csv
Step 2: Test Integrity via Extraction or Pipe
You can include manifest.sha256 directly inside your
.7z backup. To verify the backup later:
- Extract the backup to a temporary directory:
7z x backup.7z -o/tmp/restore_test/ - Run the checksum verification tool against the manifest:
cd /tmp/restore_test sha256sum -c manifest.sha256
If all files report OK, the restored data exactly
matches the state of the files when the manifest was generated.
Method 3: Internal Archive Integrity Test
If the archive was created without external corruption during the process, 7-Zip records CRC-32 or CRC-64 checksums for every file directly inside the archive headers.
To verify that the archive has not suffered bit rot or corruption since creation, run:
7z t backup.7zThe t (test) command decompresses all files in memory
and compares the calculated CRC values against the stored header values.
While this does not compare against the live source directory, it
guarantees that the files inside the archive match the exact condition
they were in when 7-Zip read and compressed them.