A checksum or cryptographic hash is a fingerprint calculated from a file. If the file changes, its hash usually changes. A digital signature uses cryptography to associate a file with a signer and detect later modification. Neither check, alone, proves that the program is safe to run.
A useful example
A developer publishes a SHA-256 value on its official site. You calculate the downloaded file's SHA-256 value and compare them exactly. A match supports that you obtained the same bytes the developer described, provided the site itself is authentic. Separately, Windows may show a valid signature from the expected publisher. A scam site can publish its own matching hash, and malicious software can have a valid signature.
Use both in context
Start with the real download source. Then compare any official hash and inspect the signer when provided. Microsoft's
Get-FileHash documentation explains local hash calculation. If either check fails, stop and obtain the file afresh; do not bypass a warning because the filename looks right.
Practical distinction
A matching hash from an untrusted mirror says only that the mirror and file agree. Obtain the expected value independently from the developer's verified channel.