25

PDF file signature

Magic number at the start of the file · %PDF-

25 50 44 46 2D

A PDF begins with %PDF- followed by its version, for example %PDF-1.7. Modern Adobe Illustrator (.ai) files are PDF-compatible and start with the same bytes, so they are detected as PDF.

Hex signature
25 50 44 46 2D
Offset
0 (start of file)
ASCII
%PDF-
Length
5 bytes

What this magic number means

A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes 25 50 44 46 2D (the text %PDF-), it is a PDF file.

The specification allows up to 1024 bytes of junk before the header, so strict readers scan the opening kilobyte for %PDF- rather than testing byte 0 alone. That tolerance is also why some scanners see a PDF where a naive check sees nothing.

What each byte of 25 50 44 46 means

Here is the signature byte by byte, the way a hex editor shows it: the position in the file, the value in hex and in decimal, and the character that value stands for in ASCII. Bytes with no printable character show a dot.

Byte offsetHexDecimalASCII
02537%
15080P
24468D
34670F
42D45-

The marker at the end of the file

PDF carries a fixed marker at the end of the file as well as its header at the start. The bytes 25 25 45 4F 46 close the file (%%EOF closes the file). The header is what identifies the format; this is an additional marker, not the signature.

ISO 32000-1 puts the %PDF- header at the start of the file and requires the last line to be %%EOF, immediately after the startxref keyword and the byte offset of the cross-reference table. A reader opens a PDF from the back: it seeks to the end, finds %%EOF, reads the offset above it and jumps straight to the object table, which is how a 200-page document can render its last page without parsing the first 199. The header is what identifies the file as a PDF; %%EOF is an end marker, and a missing one is the classic sign of a truncated download rather than of a different format.

Formats that use the 25 50 44 46 signature

These file types in our database carry this signature:

How to check a file's signature

You can read the bytes of any file yourself. They are shown in hex, the same way this page lists them.

Linux & macOS

  • xxd -l 16 example.pdf
  • hexdump -C -n 16 example.pdf
  • file example.pdf

Windows (PowerShell)

  • Format-Hex -Path example.pdf -Count 16

Python

  • open("example.pdf","rb").read(5).hex()

In your browser

Frequently asked questions

What is the PDF file signature?

PDF files start with the hex bytes 25 50 44 46 2D (%PDF- in ASCII). This magic number identifies the format regardless of the file's name or extension.

How do I check a file's magic number?

Open the file in a hex editor, or run a command such as xxd -l 16 example.pdf on Linux or macOS, or Format-Hex -Path example.pdf -Count 16 in Windows PowerShell, and read the first bytes.

Can a file fake the PDF signature?

Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine PDF file has these exact bytes; a file with the wrong bytes is not really PDF, whatever its name says.

Related signatures

Sources

Reuse this signature

This entry is part of the WhatFileType file signature reference, published under a CC BY 4.0 licence with the full provenance for every entry, a copy-paste embed and a JSON export. Credit WhatFileType and the data is yours to republish.