Verify the source and file before installing
Check that the file you received is the app you intended to install, then review Android’s installer information.
Check the complete destination
Read the address shown after opening a download page. A familiar app name in a search result does not establish who controls the destination. Look for the expected app identity and compare it with the publisher’s information.
Check shortened and redirected links at their final destination. If the file or publisher differs from what you expected, pause before installing.
Check the completed file
- Confirm that the browser marks the download as complete.
- Check the filename and file type in your Downloads list.
- Read the app name and permissions displayed by Android.
- Keep device security checks enabled.
A file extension ending in .apk identifies a format; it does not prove the file’s origin or safety.
Understand package identity and signatures
An Android package has an internal application ID and a signing certificate. Android uses these identifiers when deciding whether a file can update an existing installation.
A matching icon or filename is not sufficient. A signature mismatch can explain why a file will not update your installed copy. Refer to update help before removing any existing app data.
What a SHA-256 checksum tells you
A checksum is a fingerprint of a particular file. Two identical SHA-256 values indicate that the compared files have the same bytes. The comparison is useful only when the expected checksum comes from a trusted source.
A checksum calculated from an unknown file does not establish who published it or certify that it is safe.
Ask about a source you cannot confirm
Use the support contact listed on our About page and include the source URL, filename and installer message. Do not install merely because a page claims “verified”, “official” or “virus-free”.
