FF D8

File signature reference (magic numbers)

The hex bytes that identify 111 file formats. Sortable, searchable, one page per signature.

Every file format has a fingerprint: a short run of bytes near the start that identifies it no matter what the filename says. Developers call these magic numbers or file signatures. This table lists 111 of them with the byte offset where each appears, every one cited on its own page so you can check the claim rather than take it on trust. Click any format to open a full breakdown of that signature, or drop a file into the in-browser identifier to check one instantly. The whole dataset is free to reuse under CC BY 4.0.

111 signatures
Hex signatureASCIIUsed by
3GP66 74 79 70 33 67 70ftyp3gp4.3gp
7Z37 7A BC AF 27 1C7z¼¯'.0.7z, .cb7
AAC (ADTS)FF F1-0.aac
ACE2A 2A 41 43 45 2A 2A**ACE**7.ace
AIFF46 4F 52 4D ?? ?? ?? ?? 41 49 46 46FORM....AIFF0.aiff
AMR speech23 21 41 4D 52#!AMR0.amr
Apache Arrow / Feather41 52 52 4F 57 31ARROW10.arrow
Apache Avro4F 62 6A 01Obj.0.avro
Apache Parquet50 41 52 31PAR10.parquet
Apple Disk Image6B 6F 6C 79koly-512.dmg
ASF (WMV / WMA)30 26 B2 75 8E 66 CF 110&.u.f..0.wmv, .wma, .asf
AutoCAD DWG41 43 31 30AC100.dwg
AVI52 49 46 46 ?? ?? ?? ?? 41 56 49 20RIFF....AVI 0.avi
AVIF66 74 79 70 61 76 69 66ftypavif4.avif
Binary property list62 70 6C 69 73 74 30 30bplist000.plist
BitTorrent64 38 3A 61 6E 6E 6F 75 6E 63 65d8:announce0.torrent
Blender42 4C 45 4E 44 45 52BLENDER0.blend
BMP42 4DBM0.bmp
Byte order mark (UTF-8 / UTF-16)EF BB BF-0.txt, CSV, XML, HTML, SRT, any Unicode text file
bzip242 5A 68BZh0BZ2, TBZ2
Cabinet (CAB)4D 53 43 46MSCF0.cab
Core Audio Format63 61 66 66caff0.caf
DDS44 44 53 20DDS 0.dds
Debian package21 3C 61 72 63 68 3E!<arch>0.deb, AR, LIB
DjVu41 54 26 54 46 4F 52 4DAT&TFORM0.djvu
Dolby Digital (AC-3)0B 77.w0.ac3
DSF (DSD audio)44 53 44 20DSD 0.dsf
DTS surround7F FE 80 01-0.dts
ELF7F 45 4C 46.ELF0SO, AXF, core
Enhanced Metafile20 45 4D 46 EMF40.emf
FBX (binary)4B 61 79 64 61 72 61 20 46 42 58 20 42 69 6E 61 72 79Kaydara FBX Binary0.fbx
FITS (astronomy)53 49 4D 50 4C 45SIMPLE0.fits
FLAC66 4C 61 43fLaC0.flac
GGUF (local LLM)47 47 55 46GGUF0.gguf
GIF47 49 46 38GIF80.gif
GIMP XCF67 69 6D 70 20 78 63 66 20gimp xcf 0.xcf
glTF (binary GLB)67 6C 54 46glTF0.gltf
gzip1F 8B-0GZ, TGZ, SVGZ
HDF589 48 44 46 0D 0A 1A 0A.HDF....0.hdf5
HEIC66 74 79 70 68 65 69 63ftypheic4.heic, HEIF, HEIX
ICNS69 63 6E 73icns0.icns
ICO00 00 01 00-0.ico
ISO 966043 44 30 30 31CD00132769.iso
Java class / Mach-O fatCA FE BA BE-0CLASS, Mach-O universal binary
JPEGFF D8 FFÿØÿ0.jpg, .jfif
JPEG 200000 00 00 0C 6A 50 20 20 0D 0A 87 0A....jP ....0.jp2
JPEG XL00 00 00 0C 4A 58 4C 20 0D 0A 87 0A....JXL ....0.jxl
Mach-OCF FA ED FE-0dylib, bundle
MATLAB MAT-file4D 41 54 4C 41 42 20 35 2E 30MATLAB 5.00.mat
Matroska / WebM1A 45 DF A3-0.mkv, .webm, .mka
MIDI4D 54 68 64MThd0.mid
Mobipocket42 4F 4F 4B 4D 4F 42 49BOOKMOBI60.mobi, .azw
Monkey's Audio4D 41 43 20MAC 0.ape
MOV66 74 79 70 71 74 20 20ftypqt 4.mov
MP349 44 33ID30.mp3
MP466 74 79 70ftyp4.mp4, .m4v, .m4b, .m4r, .f4v, M4A
MPEG-1/200 00 01 BA-0.mpg, .vob
MXF06 0E 2B 34 02 05 01 01 0D 01 02 01 01 02..+4..........0.mxf
NetCDF (classic)43 44 46 01CDF.0.nc
Netpbm (PPM/PGM/PBM)50 36P60.ppm
NumPy array93 4E 55 4D 50 59.NUMPY0.npy
OGG4F 67 67 53OggS0.ogg, .opus, .ogv
OLE2 Compound FileD0 CF 11 E0 A1 B1 1A E1-0.doc, .xls, .ppt, .msi, .msg, .pub
OneNoteE4 52 5C 7B 8C D8 A7 4D AE B1 53 78 D0 29 96 D3.R\{...M..Sx.)..0.one
OpenEXR76 2F 31 01v/1.0.exr
OpenType4F 54 54 4FOTTO0.otf
PCAP captureD4 C3 B2 A1-0.pcap
PCX0A-0.pcx
PDF25 50 44 46 2D%PDF-0.pdf, .ai
PE (EXE / DLL)4D 5AMZ0.exe, .dll, SYS, SCR, OCX
PLY (Stanford)70 6C 79 0Aply.0.ply
PNG89 50 4E 47 0D 0A 1A 0A.PNG....0.png, .apng
PostScript / EPS25 21 50 53%!PS0.eps, PS (PostScript)
PSD38 42 50 538BPS0.psd
QCOW2 (QEMU disk)51 46 49 FBQFIû0.qcow2
Radiance HDR23 3F 52 41 44 49 41 4E 43 45#?RADIANCE0.hdr
RAR52 61 72 21 1A 07 00Rar!...0.rar, .cbr
RealMedia2E 52 4D 46.RMF0.rm
RPM packageED AB EE DB-0.rpm
RTF7B 5C 72 74 66 31{\rtf10.rtf
Shapefile00 00 27 0A-0.shp
SPSS data file24 46 4C 32$FL20.sav
SQLite53 51 4C 69 74 65 20 66 6F 72 6D 61 74 20 33 00SQLite format 3\00.sqlite, .db, .mbtiles
StuffIt53 49 54 21 00SIT!.0.sit
Sun audio (.snd)2E 73 6E 64.snd0.au
SVG3C 3F 78 6D 6C<?xml0.svg
TAR (ustar)75 73 74 61 72ustar257.tar, .cbt, .ova
TIFF49 49 2A 00II*.0.tiff, .dng, CR2, NEF, ARW
TrueType00 01 00 00-0.ttf
TrueType Collection74 74 63 66ttcf0.ttc
TTA (True Audio)54 54 41 31TTA10.tta
Unix compress (.Z)1F 9D-0.z
VHD (virtual disk)63 6F 6E 65 63 74 69 78conectix0.vhd
VHDX (Hyper-V disk)76 68 64 78 66 69 6C 65vhdxfile0.vhdx
VMDK (VMware disk)4B 44 4D 56KDMV0.vmdk
VRML23 56 52 4D 4C#VRML0.wrl
WAV52 49 46 46 ?? ?? ?? ?? 57 41 56 45RIFF....WAVE0.wav
WavPack77 76 70 6Bwvpk0.wv
WebAssembly00 61 73 6D.asm0WASM
WebP52 49 46 46 ?? ?? ?? ?? 57 45 42 50RIFF....WEBP0.webp
WebVTT57 45 42 56 54 54WEBVTT0.vtt
WIM4D 53 57 49 4D 00 00 00MSWIM...0.wim, .esd
Windows cursor00 00 02 00-0.cur
Windows MetafileD7 CD C6 9A-0.wmf
WOFF277 4F 46 32wOF20.woff2
WordPerfectFF 57 50 43ÿWPC0.wpd
xar (macOS .pkg)78 61 72 21xar!0.pkg, XAR, SafariExtz
XML3C 3F 78 6D 6C 20<?xml 0.xml, .gpx, .kml, .dae, .fb2, .opf
xzFD 37 7A 58 5A 00ý7zXZ.0.xz, TXZ
ZIP50 4B 03 04PK..0.zip, .docx, .xlsx, .pptx, .apk, .epub
Zstandard28 B5 2F FD-0.zst, TZST

How to read this table

The hex signature is the sequence of bytes to look for. A pair of question marks (??) means any byte can appear in that position, which is common for RIFF formats like WebP and WAV that embed a size field early on. The offset is how many bytes from the start of the file the signature begins, so an offset of 0 means the very first byte. A few formats, like tar and ISO images, place their marker well into the file.

The ASCII column shows what those same bytes look like as text, which is what you see in the right-hand pane of a hex editor. Many signatures are deliberately readable: 50 4B is PK for Phil Katz of PKZIP, 25 50 44 46 2D is %PDF-, and 66 74 79 70 is ftyp in every MP4-family file. A dot stands for a byte that has no printable character, and a question mark for a wildcard.

Many modern formats are actually ZIP archives underneath, including DOCX, XLSX, PPTX, EPUB, APK and JAR. They all share the ZIP signature 50 4B 03 04, so the extension and internal structure decide which one it is.

Reuse this dataset

The table, the JSON export and the per-signature breakdowns are published under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. You may copy it, adapt it and republish it, including commercially, provided you credit WhatFileType, https://whatfiletype.com and link back to this page. No permission request, no key, no fee.

There are three ways to take it, depending on what you are building.

Copy the embed code

<iframe
  src="https://whatfiletype.com/widget/signatures"
  title="File signatures (magic numbers) reference by WhatFileType"
  width="100%"
  height="560"
  style="border:0;"
  loading="lazy"
></iframe>
<p><a href="https://whatfiletype.com/magic-numbers">File signature reference</a> by WhatFileType, CC BY 4.0</p>

The credit line under the frame is the part that matters. The frame itself carries a visible link too, but a link outside the iframe is what a reader can follow and what a crawler can see. More embed options are on the embed page.

Where the data comes from

Each of the 111 signatures was checked against a published source before it went in, and every signature page lists the sources for that entry. Across the corpus that comes to 33 distinct sources: format specifications where the format has one, and the cross-format signature lists for the many older and abandoned formats that never had a public specification, or whose specification is no longer reachable. Most of the corpus rests on the latter, so check the source line on the individual page before you quote a figure. 11 of the signatures sit at a non-zero offset and 3 carry a fixed marker at the end of the file, both taken from the same sources rather than assumed. Of those 3, only 1 has no header magic at all and is genuinely identified by its trailer: the Apple disk image. PDF and Parquet open with a header and close with an end marker as well, which is a different thing, and this reference says so on each page rather than calling all three trailer formats.

Formats with no reliable fixed signature are deliberately absent. Plain-text formats and headerless binaries whose meaning depends entirely on the producing program are logged as having no signature instead of being given a plausible-looking one, which is the main thing that separates this list from the copies of copies that circulate online. Here is that log in full, 63 extensions this reference will not give you a magic number for, because there is not an honest one to give.

Three kinds of thing end up here. Plain text is the largest: a .json, .csv, .md or .sh file is just characters, so there is nothing fixed to match beyond an optional byte order mark. Then come headerless binaries and catch-all names such as .dat, .bin and .tmp, where the bytes mean whatever the program that wrote them decided. Last are closed formats such as .fig and .afdesign, which certainly have a fixed header but no published one we were willing to cite. If you have seen a citable specification for any of these, the table should carry it.

Frequently asked questions

What are magic numbers in a file?

Magic numbers are a short, fixed sequence of bytes at a known position, usually the very start, that identifies a file's format regardless of its name. Programs read them to know what a file really is.

How do I check a file's signature?

Open the file in a hex editor and read the first bytes, run xxd -l 16 file on Linux or macOS, run Format-Hex -Path file -Count 16 in Windows PowerShell, or drop the file into the WhatFileType identifier, which reads the signature in your browser without uploading anything.

Can a file's extension lie about its format?

Yes. The extension is just part of the name and can be changed freely. The magic bytes are the reliable signal, which is why security tools inspect them.

What does the ASCII column mean?

It is the same bytes shown as text, the way a hex editor displays them side by side. Printable bytes appear as characters, a dot stands for a byte with no printable character, and a question mark marks a wildcard byte that varies from file to file.

Can I reuse this file signature table on my own site?

Yes. The dataset is published under Creative Commons Attribution 4.0 International (CC BY 4.0), so you may copy, adapt and republish it, commercial use included, as long as you credit WhatFileType, https://whatfiletype.com. There is a copy-paste embed on this page and a JSON download at /api/signatures if you would rather hold the data yourself.

Where does the data in this table come from?

Every signature cites its source on its own page, 33 distinct ones across the corpus. Where a format has a published specification, that is what the entry cites: the PNG spec, PKWARE's APPNOTE for ZIP, RFC 1952 for gzip, RFC 8794 for Matroska and so on. The majority of the corpus rests on the cross-format signature list maintained by Wikipedia, which is the only public source for many older or abandoned formats. Check the source line on an individual page before quoting it, and treat a Wikipedia-only entry as exactly that. Formats with no reliable fixed signature are left out rather than guessed.