PE (EXE / DLL) file signature
Magic number at the start of the file · MZ
Windows executables and DLLs start with the two ASCII bytes MZ, the initials of Mark Zbikowski who designed the DOS header. A PE offset field later in the header points to the modern PE\0\0 marker.
What this magic number means
A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes 4D 5A (the text MZ), it is a PE (EXE / DLL) file.
The MZ header is a DOS stub for backward compatibility. The real Portable Executable begins at the offset stored at byte 0x3C, where the bytes 50 45 00 00 (PE\0\0) confirm a Windows binary.
Formats that use the 4D 5A signature
These file types in our database carry this signature:
It is also seen in: SYS, SCR, OCX.
How to check a file's signature
You can read the first bytes of any file yourself. The magic bytes are shown in hex, the same way this page lists them.
Linux & macOS
- xxd -l 16 example.exe
- hexdump -C -n 16 example.exe
- file example.exe
Windows (PowerShell)
- Format-Hex -Path example.exe -Count 16
Python
- open("example.exe","rb").read(2).hex()
In your browser
- Drop the file into the WhatFileType identifier, which reads the signature without uploading it.
Frequently asked questions
What is the PE (EXE / DLL) file signature?
PE (EXE / DLL) files start with the hex bytes 4D 5A (MZ in ASCII). This magic number identifies the format regardless of the file's name or extension.
How do I check a file's magic number?
Open the file in a hex editor, or run a command such as xxd -l 16 example.exe on Linux or macOS, or Format-Hex -Path example.exe -Count 16 in Windows PowerShell, and read the first bytes.
Can a file fake the PE (EXE / DLL) signature?
Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine PE (EXE / DLL) file has these exact bytes; a file with the wrong bytes is not really PE (EXE / DLL), whatever its name says.