How to Check a Software Download Before Installing It

A download button is an invitation to trust someone with your computer. Before accepting it, you should know who supplied the file, whether it is the release you intended to get, and what access it will need.
You do not need to reverse-engineer every installer. A useful routine starts with a deliberate source, checks the available evidence, and pauses when something does not fit. No single check guarantees safety, but several checks can expose a bad download before you run it.
Here is a practical process for desktop software, whether you are installing a new tool or replacing something you already use.
Start With a Download Route You Chose
For a work computer, begin with your organization's software portal or IT team. An approved version may include settings, licensing, or security controls that a public download lacks. Ask before installing an alternative.
For a personal device, use the operating system's app store or reach the developer through an independently established route. A saved bookmark, existing product documentation, or the app's own update mechanism can help you avoid starting from an unsolicited message.
If you use search, examine the destination before downloading. An advertisement, familiar icon, or convincing product name is not evidence that the page belongs to the developer. Check the actual domain rather than relying on the title displayed above it.
Developers sometimes host releases on a separate service. Follow that destination from the developer's verified site instead of choosing an unrelated mirror with a similar filename. An encrypted connection protects traffic to a site; it does not establish that you chose the right site.
Match the File to the Release You Need
Before opening anything, compare the download with the release page. Check the product, version, operating system, processor architecture, and expected file type. A release for a different platform may simply be a mistake, but it still is not the file you meant to install.
Show full filenames and extensions in your file manager. An executable presented as a document deserves investigation. A familiar filename or icon can be copied, so neither proves identity.
Avoid download helpers that appear where the developer promised a direct installer. Stop if the process unexpectedly requires a browser extension, remote-support tool, password-protected archive, or command pasted into a terminal. Some legitimate tools use unusual packaging, but you need a clear explanation from the verified publisher before continuing.
If an extension really is part of the product, apply the same scrutiny to its access using the guide to auditing browser extensions for security and privacy.
Check the Publisher and Signature
A digital signature can help identify the signer and detect changes to signed content. It does not tell you whether the app is useful, respects your privacy, or is free from every malicious behavior. The publisher still needs to be someone you intended to trust.
On Windows, PowerShell can inspect supported files without launching the installer. Open PowerShell in the download folder and replace the example filename with the actual one:
Get-AuthenticodeSignature -LiteralPath '.\installer.exe' | Format-List
Review the reported status and signer certificate. Compare the signer with the developer's stated publishing identity. A company name can differ from the product name, so resolve a mismatch through the verified developer rather than guessing.
An unsigned file is not automatically malware, and some file types use other verification methods. However, an invalid signature or an unexplained publisher is a reason to stop. Do not run the installer just to find out more about it.
Use Checksums to Verify File Integrity
A checksum is a fingerprint calculated from a file's contents. When a developer publishes a SHA-256 checksum for a release, you can calculate your download's value and compare the two.
On Windows, from the folder containing the file, use:
Get-FileHash -LiteralPath '.\installer.exe' -Algorithm SHA256
This reads the file and calculates its hash; it does not install it. Compare the entire reported hash with the developer's value. Letter case does not matter for the hexadecimal digits, but every digit must match. Use the same algorithm and the checksum for the exact version and package you downloaded.

A mismatch means the file does not match that published value. Do not install it. Confirm you selected the right release, discard the suspect download, and obtain a fresh copy through the verified route. If the mismatch remains, contact the publisher.
A matching hash establishes consistency with the reference, not trust in whoever supplied it. Someone controlling both a malicious download and its checksum can make them match. Get the reference from a source you have already verified. If the publisher supplies no checksum, do not invent one or treat a random mirror's value as authoritative.
Understand Security Warnings Before Proceeding
Keep your operating system, browser, and approved security protection current. Their checks add information your own inspection cannot provide.
On macOS, Gatekeeper checks software downloaded outside the App Store, including developer signatures and notarization. Notarization means Apple checked for known malicious software and did not detect it; it is not a guarantee about every future action an app might take.
On Windows, Microsoft Defender SmartScreen uses reputation and other signals to warn about potentially unsafe downloads. A file without established reputation can trigger a warning even when it is legitimate. That possibility is a reason to investigate, not a reason to dismiss the warning automatically.
Read the actual alert. A notice that software is unfamiliar differs from a detection of malicious content. Check the verified publisher's support information or ask your administrator when the meaning is unclear. Do not follow instructions from a download page to disable protection or create a blanket exclusion.
A clean scan also has limits. Use it as one piece of evidence alongside the source and publisher checks, rather than permission to run an otherwise unexplained file.
Treat Unexpected Access as a New Decision
Passing the download checks does not mean accepting every request during setup. Read the installer screens and decline unrelated extras. Pause if the product changes your browser settings or asks for access unrelated to the job you chose it for.
Administrator privileges can be appropriate for some installers, but the request should be expected. Remote control, broad file access, accessibility permissions, or a new browser extension each deserves a separate explanation. Ask what feature requires the access and whether a narrower option exists.

For a managed device, let IT handle permissions outside your authority. Do not use personal administrator credentials or workarounds to bypass an organizational block. Installing and maintaining approved software belongs within the wider approach to endpoint security best practices.
Know When to Stop and Start Recovery
Cancel the process if you cannot explain the source, signer, checksum mismatch, or requested access. You can return after resolving the uncertainty. A deadline or a page insisting the warning is harmless does not supply the missing evidence.
If the file only downloaded, avoid opening it while you investigate. If you already ran it, granted permissions, or entered credentials, treat that as a different situation. Deleting the installer alone does not reverse what the program may have done.
On a work device, report the event promptly through your incident process. Record the filename, where it came from, when you ran it, and any permissions or information you supplied. Follow the team's instructions about preserving evidence and containing the device.
For personal accounts and devices, the guide on what to do after clicking a phishing link helps separate a suspicious visit from a download, an installation, or exposed credentials. Avoid signing into sensitive accounts on a device you suspect is compromised.
A Short Checklist Before Every Installation
Before you run a downloaded installer, confirm that:
- You deliberately reached the developer, app store, or approved software portal.
- The product, version, platform, and file type match your intention.
- Available signature information identifies an expected publisher without an unexplained failure.
- Any published checksum matches the exact downloaded package.
- Security warnings have been understood and resolved without disabling protection.
- Requested permissions and bundled components have a clear purpose.
Keep the product updated through its supported route after installation. Remove tools you no longer need rather than leaving forgotten software to accumulate.
The most useful habit is to pause before granting trust. If the evidence does not line up, stop while the decision is still easy to reverse.