File signature reference (magic numbers)
The hex bytes that identify 111 file formats. Sortable, searchable, one page per signature.
Every file format has a fingerprint: a short run of bytes near the start that identifies it no matter what the filename says. Developers call these magic numbers or file signatures. This table lists 111 of them with the byte offset where each appears, every one cited on its own page so you can check the claim rather than take it on trust. Click any format to open a full breakdown of that signature, or drop a file into the in-browser identifier to check one instantly. The whole dataset is free to reuse under CC BY 4.0.
| Hex signature | ASCII | Used by | ||
|---|---|---|---|---|
| 3GP | 66 74 79 70 33 67 70 | ftyp3gp | 4 | .3gp |
| 7Z | 37 7A BC AF 27 1C | 7z¼¯'. | 0 | .7z, .cb7 |
| AAC (ADTS) | FF F1 | - | 0 | .aac |
| ACE | 2A 2A 41 43 45 2A 2A | **ACE** | 7 | .ace |
| AIFF | 46 4F 52 4D ?? ?? ?? ?? 41 49 46 46 | FORM....AIFF | 0 | .aiff |
| AMR speech | 23 21 41 4D 52 | #!AMR | 0 | .amr |
| Apache Arrow / Feather | 41 52 52 4F 57 31 | ARROW1 | 0 | .arrow |
| Apache Avro | 4F 62 6A 01 | Obj. | 0 | .avro |
| Apache Parquet | 50 41 52 31 | PAR1 | 0 | .parquet |
| Apple Disk Image | 6B 6F 6C 79 | koly | -512 | .dmg |
| ASF (WMV / WMA) | 30 26 B2 75 8E 66 CF 11 | 0&.u.f.. | 0 | .wmv, .wma, .asf |
| AutoCAD DWG | 41 43 31 30 | AC10 | 0 | .dwg |
| AVI | 52 49 46 46 ?? ?? ?? ?? 41 56 49 20 | RIFF....AVI | 0 | .avi |
| AVIF | 66 74 79 70 61 76 69 66 | ftypavif | 4 | .avif |
| Binary property list | 62 70 6C 69 73 74 30 30 | bplist00 | 0 | .plist |
| BitTorrent | 64 38 3A 61 6E 6E 6F 75 6E 63 65 | d8:announce | 0 | .torrent |
| Blender | 42 4C 45 4E 44 45 52 | BLENDER | 0 | .blend |
| BMP | 42 4D | BM | 0 | .bmp |
| Byte order mark (UTF-8 / UTF-16) | EF BB BF | - | 0 | .txt, CSV, XML, HTML, SRT, any Unicode text file |
| bzip2 | 42 5A 68 | BZh | 0 | BZ2, TBZ2 |
| Cabinet (CAB) | 4D 53 43 46 | MSCF | 0 | .cab |
| Core Audio Format | 63 61 66 66 | caff | 0 | .caf |
| DDS | 44 44 53 20 | DDS | 0 | .dds |
| Debian package | 21 3C 61 72 63 68 3E | !<arch> | 0 | .deb, AR, LIB |
| DjVu | 41 54 26 54 46 4F 52 4D | AT&TFORM | 0 | .djvu |
| Dolby Digital (AC-3) | 0B 77 | .w | 0 | .ac3 |
| DSF (DSD audio) | 44 53 44 20 | DSD | 0 | .dsf |
| DTS surround | 7F FE 80 01 | - | 0 | .dts |
| ELF | 7F 45 4C 46 | .ELF | 0 | SO, AXF, core |
| Enhanced Metafile | 20 45 4D 46 | EMF | 40 | .emf |
| FBX (binary) | 4B 61 79 64 61 72 61 20 46 42 58 20 42 69 6E 61 72 79 | Kaydara FBX Binary | 0 | .fbx |
| FITS (astronomy) | 53 49 4D 50 4C 45 | SIMPLE | 0 | .fits |
| FLAC | 66 4C 61 43 | fLaC | 0 | .flac |
| GGUF (local LLM) | 47 47 55 46 | GGUF | 0 | .gguf |
| GIF | 47 49 46 38 | GIF8 | 0 | .gif |
| GIMP XCF | 67 69 6D 70 20 78 63 66 20 | gimp xcf | 0 | .xcf |
| glTF (binary GLB) | 67 6C 54 46 | glTF | 0 | .gltf |
| gzip | 1F 8B | - | 0 | GZ, TGZ, SVGZ |
| HDF5 | 89 48 44 46 0D 0A 1A 0A | .HDF.... | 0 | .hdf5 |
| HEIC | 66 74 79 70 68 65 69 63 | ftypheic | 4 | .heic, HEIF, HEIX |
| ICNS | 69 63 6E 73 | icns | 0 | .icns |
| ICO | 00 00 01 00 | - | 0 | .ico |
| ISO 9660 | 43 44 30 30 31 | CD001 | 32769 | .iso |
| Java class / Mach-O fat | CA FE BA BE | - | 0 | CLASS, Mach-O universal binary |
| JPEG | FF D8 FF | ÿØÿ | 0 | .jpg, .jfif |
| JPEG 2000 | 00 00 00 0C 6A 50 20 20 0D 0A 87 0A | ....jP .... | 0 | .jp2 |
| JPEG XL | 00 00 00 0C 4A 58 4C 20 0D 0A 87 0A | ....JXL .... | 0 | .jxl |
| Mach-O | CF FA ED FE | - | 0 | dylib, bundle |
| MATLAB MAT-file | 4D 41 54 4C 41 42 20 35 2E 30 | MATLAB 5.0 | 0 | .mat |
| Matroska / WebM | 1A 45 DF A3 | - | 0 | .mkv, .webm, .mka |
| MIDI | 4D 54 68 64 | MThd | 0 | .mid |
| Mobipocket | 42 4F 4F 4B 4D 4F 42 49 | BOOKMOBI | 60 | .mobi, .azw |
| Monkey's Audio | 4D 41 43 20 | MAC | 0 | .ape |
| MOV | 66 74 79 70 71 74 20 20 | ftypqt | 4 | .mov |
| MP3 | 49 44 33 | ID3 | 0 | .mp3 |
| MP4 | 66 74 79 70 | ftyp | 4 | .mp4, .m4v, .m4b, .m4r, .f4v, M4A |
| MPEG-1/2 | 00 00 01 BA | - | 0 | .mpg, .vob |
| MXF | 06 0E 2B 34 02 05 01 01 0D 01 02 01 01 02 | ..+4.......... | 0 | .mxf |
| NetCDF (classic) | 43 44 46 01 | CDF. | 0 | .nc |
| Netpbm (PPM/PGM/PBM) | 50 36 | P6 | 0 | .ppm |
| NumPy array | 93 4E 55 4D 50 59 | .NUMPY | 0 | .npy |
| OGG | 4F 67 67 53 | OggS | 0 | .ogg, .opus, .ogv |
| OLE2 Compound File | D0 CF 11 E0 A1 B1 1A E1 | - | 0 | .doc, .xls, .ppt, .msi, .msg, .pub |
| OneNote | E4 52 5C 7B 8C D8 A7 4D AE B1 53 78 D0 29 96 D3 | .R\{...M..Sx.).. | 0 | .one |
| OpenEXR | 76 2F 31 01 | v/1. | 0 | .exr |
| OpenType | 4F 54 54 4F | OTTO | 0 | .otf |
| PCAP capture | D4 C3 B2 A1 | - | 0 | .pcap |
| PCX | 0A | - | 0 | .pcx |
| 25 50 44 46 2D | %PDF- | 0 | .pdf, .ai | |
| PE (EXE / DLL) | 4D 5A | MZ | 0 | .exe, .dll, SYS, SCR, OCX |
| PLY (Stanford) | 70 6C 79 0A | ply. | 0 | .ply |
| PNG | 89 50 4E 47 0D 0A 1A 0A | .PNG.... | 0 | .png, .apng |
| PostScript / EPS | 25 21 50 53 | %!PS | 0 | .eps, PS (PostScript) |
| PSD | 38 42 50 53 | 8BPS | 0 | .psd |
| QCOW2 (QEMU disk) | 51 46 49 FB | QFIû | 0 | .qcow2 |
| Radiance HDR | 23 3F 52 41 44 49 41 4E 43 45 | #?RADIANCE | 0 | .hdr |
| RAR | 52 61 72 21 1A 07 00 | Rar!... | 0 | .rar, .cbr |
| RealMedia | 2E 52 4D 46 | .RMF | 0 | .rm |
| RPM package | ED AB EE DB | - | 0 | .rpm |
| RTF | 7B 5C 72 74 66 31 | {\rtf1 | 0 | .rtf |
| Shapefile | 00 00 27 0A | - | 0 | .shp |
| SPSS data file | 24 46 4C 32 | $FL2 | 0 | .sav |
| SQLite | 53 51 4C 69 74 65 20 66 6F 72 6D 61 74 20 33 00 | SQLite format 3\0 | 0 | .sqlite, .db, .mbtiles |
| StuffIt | 53 49 54 21 00 | SIT!. | 0 | .sit |
| Sun audio (.snd) | 2E 73 6E 64 | .snd | 0 | .au |
| SVG | 3C 3F 78 6D 6C | <?xml | 0 | .svg |
| TAR (ustar) | 75 73 74 61 72 | ustar | 257 | .tar, .cbt, .ova |
| TIFF | 49 49 2A 00 | II*. | 0 | .tiff, .dng, CR2, NEF, ARW |
| TrueType | 00 01 00 00 | - | 0 | .ttf |
| TrueType Collection | 74 74 63 66 | ttcf | 0 | .ttc |
| TTA (True Audio) | 54 54 41 31 | TTA1 | 0 | .tta |
| Unix compress (.Z) | 1F 9D | - | 0 | .z |
| VHD (virtual disk) | 63 6F 6E 65 63 74 69 78 | conectix | 0 | .vhd |
| VHDX (Hyper-V disk) | 76 68 64 78 66 69 6C 65 | vhdxfile | 0 | .vhdx |
| VMDK (VMware disk) | 4B 44 4D 56 | KDMV | 0 | .vmdk |
| VRML | 23 56 52 4D 4C | #VRML | 0 | .wrl |
| WAV | 52 49 46 46 ?? ?? ?? ?? 57 41 56 45 | RIFF....WAVE | 0 | .wav |
| WavPack | 77 76 70 6B | wvpk | 0 | .wv |
| WebAssembly | 00 61 73 6D | .asm | 0 | WASM |
| WebP | 52 49 46 46 ?? ?? ?? ?? 57 45 42 50 | RIFF....WEBP | 0 | .webp |
| WebVTT | 57 45 42 56 54 54 | WEBVTT | 0 | .vtt |
| WIM | 4D 53 57 49 4D 00 00 00 | MSWIM... | 0 | .wim, .esd |
| Windows cursor | 00 00 02 00 | - | 0 | .cur |
| Windows Metafile | D7 CD C6 9A | - | 0 | .wmf |
| WOFF2 | 77 4F 46 32 | wOF2 | 0 | .woff2 |
| WordPerfect | FF 57 50 43 | ÿWPC | 0 | .wpd |
| xar (macOS .pkg) | 78 61 72 21 | xar! | 0 | .pkg, XAR, SafariExtz |
| XML | 3C 3F 78 6D 6C 20 | <?xml | 0 | .xml, .gpx, .kml, .dae, .fb2, .opf |
| xz | FD 37 7A 58 5A 00 | ý7zXZ. | 0 | .xz, TXZ |
| ZIP | 50 4B 03 04 | PK.. | 0 | .zip, .docx, .xlsx, .pptx, .apk, .epub |
| Zstandard | 28 B5 2F FD | - | 0 | .zst, TZST |
How to read this table
The hex signature is the sequence of bytes to look for. A pair of question marks (??) means any byte can appear in that position, which is common for RIFF formats like WebP and WAV that embed a size field early on. The offset is how many bytes from the start of the file the signature begins, so an offset of 0 means the very first byte. A few formats, like tar and ISO images, place their marker well into the file.
The ASCII column shows what those same bytes look like as text, which is what you see in the right-hand pane of a hex editor. Many signatures are deliberately readable: 50 4B is PK for Phil Katz of PKZIP, 25 50 44 46 2D is %PDF-, and 66 74 79 70 is ftyp in every MP4-family file. A dot stands for a byte that has no printable character, and a question mark for a wildcard.
Many modern formats are actually ZIP archives underneath, including DOCX, XLSX, PPTX, EPUB, APK and JAR. They all share the ZIP signature 50 4B 03 04, so the extension and internal structure decide which one it is.
Reuse this dataset
The table, the JSON export and the per-signature breakdowns are published under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. You may copy it, adapt it and republish it, including commercially, provided you credit WhatFileType, https://whatfiletype.com and link back to this page. No permission request, no key, no fee.
There are three ways to take it, depending on what you are building.
- Embed the live table. One iframe, self-contained, with its own filter box and the attribution built in. It stays current as signatures are added.
- Download the JSON. /api/signatures returns every signature with its hex, offset, ASCII rendering, trailer where one exists, the formats that share it and a link to its page, plus the licence and attribution string in the payload itself.
- Copy the table. Republishing the rows in your own layout is fine under the same licence, as long as the credit and the link are there.
Copy the embed code
<iframe src="https://whatfiletype.com/widget/signatures" title="File signatures (magic numbers) reference by WhatFileType" width="100%" height="560" style="border:0;" loading="lazy" ></iframe> <p><a href="https://whatfiletype.com/magic-numbers">File signature reference</a> by WhatFileType, CC BY 4.0</p>
The credit line under the frame is the part that matters. The frame itself carries a visible link too, but a link outside the iframe is what a reader can follow and what a crawler can see. More embed options are on the embed page.
Where the data comes from
Each of the 111 signatures was checked against a published source before it went in, and every signature page lists the sources for that entry. Across the corpus that comes to 33 distinct sources: format specifications where the format has one, and the cross-format signature lists for the many older and abandoned formats that never had a public specification, or whose specification is no longer reachable. Most of the corpus rests on the latter, so check the source line on the individual page before you quote a figure. 11 of the signatures sit at a non-zero offset and 3 carry a fixed marker at the end of the file, both taken from the same sources rather than assumed. Of those 3, only 1 has no header magic at all and is genuinely identified by its trailer: the Apple disk image. PDF and Parquet open with a header and close with an end marker as well, which is a different thing, and this reference says so on each page rather than calling all three trailer formats.
Formats with no reliable fixed signature are deliberately absent. Plain-text formats and headerless binaries whose meaning depends entirely on the producing program are logged as having no signature instead of being given a plausible-looking one, which is the main thing that separates this list from the copies of copies that circulate online. Here is that log in full, 63 extensions this reference will not give you a magic number for, because there is not an honest one to give.
Three kinds of thing end up here. Plain text is the largest: a .json, .csv, .md or .sh file is just characters, so there is nothing fixed to match beyond an optional byte order mark. Then come headerless binaries and catch-all names such as .dat, .bin and .tmp, where the bytes mean whatever the program that wrote them decided. Last are closed formats such as .fig and .afdesign, which certainly have a fixed header but no published one we were willing to cite. If you have seen a citable specification for any of these, the table should carry it.
- Wikipedia: List of file signatures (94 signatures)
- GCK file signature table (Gary Kessler, hosted by SEARCH) (5 signatures)
- 7z archive format notes (py7zr, a third-party Python implementation) (1 signature)
- Apache Arrow IPC format (1 signature)
- Apache Avro specification (1 signature)
- Apache Parquet file format (1 signature)
- Apple property list format (1 signature)
- DSF File Format Specification (Sony Corporation, PDF rehosted by dsd-guide.com) (1 signature)
- Esri Shapefile Technical Description (1 signature)
- FBX binary file format, reverse-engineered notes (code.blender.org developer blog, 2013) (1 signature)
- FITS standard (NASA) (1 signature)
- GGUF specification (ggml) (1 signature)
- HDF5 File Format Specification Version 3.0 (The HDF Group) (1 signature)
- Hydrogenaudio Knowledgebase (community wiki): TTA (1 signature)
- ISO 32000-1:2008, PDF 1.7 (Adobe published copy) (1 signature)
- JPEG XL (jpeg.org) (1 signature)
- Library of Congress: WordPerfect document (1 signature)
- MAT-file versions (MathWorks) (1 signature)
- Microsoft [MS-ONESTORE]: OneNote file format, file-type GUID (1 signature)
- NetCDF file format (1 signature)
- NumPy .npy format (1 signature)
- PCX format (Encyclopedia of Graphics File Formats) (1 signature)
- PKWARE .ZIP APPNOTE (format spec) (1 signature)
- PNG Specification (W3C), file signature (1 signature)
- RFC 1952: GZIP file format specification 4.3 (1 signature)
- SQLite database file format (1 signature)
- True Audio codec project (SourceForge) (1 signature)
- Unicode FAQ: UTF-8, UTF-16, UTF-32 and BOM (1 signature)
- W3C: Extensible Markup Language (XML) 1.0, prolog (1 signature)
- W3C: Scalable Vector Graphics (SVG) 2, conforming documents (1 signature)
- Wikipedia: Shapefile (1 signature)
- Wikipedia: StuffIt (1 signature)
- xar project (archive format) (1 signature)
Frequently asked questions
What are magic numbers in a file?
Magic numbers are a short, fixed sequence of bytes at a known position, usually the very start, that identifies a file's format regardless of its name. Programs read them to know what a file really is.
How do I check a file's signature?
Open the file in a hex editor and read the first bytes, run xxd -l 16 file on Linux or macOS, run Format-Hex -Path file -Count 16 in Windows PowerShell, or drop the file into the WhatFileType identifier, which reads the signature in your browser without uploading anything.
Can a file's extension lie about its format?
Yes. The extension is just part of the name and can be changed freely. The magic bytes are the reliable signal, which is why security tools inspect them.
What does the ASCII column mean?
It is the same bytes shown as text, the way a hex editor displays them side by side. Printable bytes appear as characters, a dot stands for a byte with no printable character, and a question mark marks a wildcard byte that varies from file to file.
Can I reuse this file signature table on my own site?
Yes. The dataset is published under Creative Commons Attribution 4.0 International (CC BY 4.0), so you may copy, adapt and republish it, commercial use included, as long as you credit WhatFileType, https://whatfiletype.com. There is a copy-paste embed on this page and a JSON download at /api/signatures if you would rather hold the data yourself.
Where does the data in this table come from?
Every signature cites its source on its own page, 33 distinct ones across the corpus. Where a format has a published specification, that is what the entry cites: the PNG spec, PKWARE's APPNOTE for ZIP, RFC 1952 for gzip, RFC 8794 for Matroska and so on. The majority of the corpus rests on the cross-format signature list maintained by Wikipedia, which is the only public source for many older or abandoned formats. Check the source line on an individual page before quoting it, and treat a Wikipedia-only entry as exactly that. Formats with no reliable fixed signature are left out rather than guessed.