1F

gzip file signature

Magic number at the start of the file

1F 8B

A gzip stream starts with the two bytes 1F 8B, then the compression method (08 for DEFLATE). Most .tar.gz and .tgz files are a tar archive wrapped in gzip, so the outer signature is this one.

Hex signature
1F 8B
Offset
0 (start of file)
Length
2 bytes

What this magic number means

A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes 1F 8B, it is a gzip file.

Note what this signature does not cover. A plain .tar file does not start 1F 8B; its ustar marker sits 257 bytes in and there is nothing fixed at byte 0. It is the .tar.gz and .tgz combination that opens with these bytes, because gzip is the outer layer and tar the inner one. Read the gzip header first, decompress, then look for ustar underneath.

What each byte of 1F 8B means

Here is the signature byte by byte, the way a hex editor shows it: the position in the file, the value in hex and in decimal, and the character that value stands for in ASCII. Bytes with no printable character show a dot.

Byte offsetHexDecimalASCII
01F31.
18B139.

Formats that use the 1F 8B signature

No extension in our database is documented under this signature: the bytes belong to the gzip format itself, which usually appears as a wrapper around something else. Files that carry it are normally named GZ, TGZ, SVGZ.

How to check a file's signature

You can read the bytes of any file yourself. They are shown in hex, the same way this page lists them.

Linux & macOS

  • xxd -l 16 example.gz
  • hexdump -C -n 16 example.gz
  • file example.gz

Windows (PowerShell)

  • Format-Hex -Path example.gz -Count 16

Python

  • open("example.gz","rb").read(2).hex()

In your browser

Frequently asked questions

What is the gzip file signature?

gzip files start with the hex bytes 1F 8B. This magic number identifies the format regardless of the file's name or extension.

How do I check a file's magic number?

Open the file in a hex editor, or run a command such as xxd -l 16 example.gz on Linux or macOS, or Format-Hex -Path example.gz -Count 16 in Windows PowerShell, and read the first bytes.

Can a file fake the gzip signature?

Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine gzip file has these exact bytes; a file with the wrong bytes is not really gzip, whatever its name says.

Related signatures

Sources

Reuse this signature

This entry is part of the WhatFileType file signature reference, published under a CC BY 4.0 licence with the full provenance for every entry, a copy-paste embed and a JSON export. Credit WhatFileType and the data is yours to republish.