Before running a Windows installer, inspect its digital signature and compare the publisher with the official download source. PowerShell can read that information without starting the installer. A valid signature is one useful check; it is not a malware verdict.
This guide uses a read-only command checked on Windows 11. Keep the downloaded file unopened while you work through the checks below.
1. Start with the publisher’s download page
Find the software maker’s own website or the release repository linked from that website. Check the address before downloading. A familiar product name in a filename or an advertisement does not establish who supplied the file. Our guide to finding official download sources explains the common traps.
Write down which version and Windows architecture you chose. You will need the exact filename if the publisher provides a checksum.
2. Read the signature without running the installer
Open PowerShell on Windows and enter this command, replacing the example path with your downloaded file’s full path. Keep the quotation marks if the path contains spaces.
Get-AuthenticodeSignature -LiteralPath "C:\Downloads\installer.exe" |
Format-List Status, StatusMessage, SignatureType, SignerCertificate, TimeStamperCertificate
-LiteralPath uses the path exactly as written. This command reads signature information; it does not launch the file. The cmdlet is available on Windows. If a file has both an embedded signature and a Windows catalog signature, PowerShell uses the catalog signature. See Microsoft’s Get-AuthenticodeSignature documentation.
Look at Status, then inspect SignerCertificate for the certificate subject. Compare that organisation with the publisher identified by the official source. Do not treat any recognised company name as approval for an unrelated product.
3. Understand the result
| Status | Meaning and next step |
|---|---|
Valid |
The signature is syntactically valid. Confirm the expected publisher and source; this result alone does not establish trust or safety. |
NotSigned |
No signature was found. Check whether the official project distributes unsigned builds. Do not infer malware from this status alone. |
HashMismatch |
The file’s hash differs from the hash in its signature. Stop and obtain a fresh copy from the publisher before investigating further. |
NotTrusted |
Your system does not trust the signing certificate. Keep the file unopened and ask the publisher or your IT administrator to investigate. |
UnknownError, NotSupportedFileFormat or Incompatible |
The check did not produce a usable verification result. Read StatusMessage and consult the publisher; an incomplete check is not approval to run the file. |
The status definitions come from Microsoft’s SignatureStatus reference. A certificate’s display name, a file’s icon and a reassuring filename answer different questions; none substitutes for knowing where the download came from.
Our command check: signed and unsigned examples
On 30 September 2026 (UTC), we checked the command on Windows 11 Home, OS build 10.0.26300, using PowerShell 7.6.5. The existing Windows System32\notepad.exe returned Valid, SignatureType: Catalog and a signer subject beginning CN=Microsoft Windows, O=Microsoft Corporation.
A small unsigned PowerShell file created for this check returned NotSigned. We inspected the files with the command; we did not execute the unsigned file or install an application. These two observations demonstrate the output on that machine. They do not verify a different installer on your computer.
For an actual downloaded installer, our Raspberry Pi Imager entry records the exact Windows filename, matching SHA-256 and certificate subject we checked. Those observations apply to that file; use the same procedure to inspect your own copy.
Another measured example is our comparison of two official WinRAR installers. Both returned valid signatures on our machine but had different SHA-256 values. Match the expected checksum to the exact source and build instead of treating a signature and a hash as interchangeable.
4. Compare the publisher’s SHA-256 when available
A signature check and a checksum comparison are separate steps. Calculate the downloaded file’s SHA-256 with:
Get-FileHash -LiteralPath "C:\Downloads\installer.exe" -Algorithm SHA256
Compare the result with the publisher’s value for that exact version, platform and filename. A renamed file can have the same hash; changing its contents changes the hash. Microsoft documents this behaviour in Get-FileHash.
You can also use our local SHA-256 checker for files up to 128 MiB. A matching value establishes agreement with the expected bytes, provided you trust the source of that value. It does not prove that the program is harmless.
What if SmartScreen still warns about the file?
Keep the warning in place while you investigate. SmartScreen considers reported malicious downloads and reputation, including whether a file is widely recognised. Signature validity does not replace those checks. Microsoft explains the distinction in its SmartScreen overview.
If the source, publisher or checksum does not agree with what you expected, stop before running the installer. Share the version, official source URL and exact error with the software publisher. Avoid sending passwords, licence keys or private files as part of a support request.
See how Softwares Academy distinguishes source checks from hands-on testing for the limits of the information on our software pages.