PDF file signature
Magic number at the start of the file · %PDF-
A PDF begins with %PDF- followed by its version, for example %PDF-1.7. Modern Adobe Illustrator (.ai) files are PDF-compatible and start with the same bytes, so they are detected as PDF.
What this magic number means
A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes 25 50 44 46 2D (the text %PDF-), it is a PDF file.
The specification allows up to 1024 bytes of junk before the header, so strict readers scan the opening kilobyte for %PDF- rather than testing byte 0 alone. That tolerance is also why some scanners see a PDF where a naive check sees nothing.
What each byte of 25 50 44 46 means
Here is the signature byte by byte, the way a hex editor shows it: the position in the file, the value in hex and in decimal, and the character that value stands for in ASCII. Bytes with no printable character show a dot.
| Byte offset | Hex | Decimal | ASCII |
|---|---|---|---|
| 0 | 25 | 37 | % |
| 1 | 50 | 80 | P |
| 2 | 44 | 68 | D |
| 3 | 46 | 70 | F |
| 4 | 2D | 45 | - |
The marker at the end of the file
PDF carries a fixed marker at the end of the file as well as its header at the start. The bytes 25 25 45 4F 46 close the file (%%EOF closes the file). The header is what identifies the format; this is an additional marker, not the signature.
ISO 32000-1 puts the %PDF- header at the start of the file and requires the last line to be %%EOF, immediately after the startxref keyword and the byte offset of the cross-reference table. A reader opens a PDF from the back: it seeks to the end, finds %%EOF, reads the offset above it and jumps straight to the object table, which is how a 200-page document can render its last page without parsing the first 199. The header is what identifies the file as a PDF; %%EOF is an end marker, and a missing one is the classic sign of a truncated download rather than of a different format.
Formats that use the 25 50 44 46 signature
These file types in our database carry this signature:
How to check a file's signature
You can read the bytes of any file yourself. They are shown in hex, the same way this page lists them.
Linux & macOS
- xxd -l 16 example.pdf
- hexdump -C -n 16 example.pdf
- file example.pdf
Windows (PowerShell)
- Format-Hex -Path example.pdf -Count 16
Python
- open("example.pdf","rb").read(5).hex()
In your browser
- Drop the file into the WhatFileType identifier, which reads the signature without uploading it.
Frequently asked questions
What is the PDF file signature?
PDF files start with the hex bytes 25 50 44 46 2D (%PDF- in ASCII). This magic number identifies the format regardless of the file's name or extension.
How do I check a file's magic number?
Open the file in a hex editor, or run a command such as xxd -l 16 example.pdf on Linux or macOS, or Format-Hex -Path example.pdf -Count 16 in Windows PowerShell, and read the first bytes.
Can a file fake the PDF signature?
Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine PDF file has these exact bytes; a file with the wrong bytes is not really PDF, whatever its name says.
Related signatures
Sources
Reuse this signature
This entry is part of the WhatFileType file signature reference, published under a CC BY 4.0 licence with the full provenance for every entry, a copy-paste embed and a JSON export. Credit WhatFileType and the data is yours to republish.