00

Shapefile file signature

Magic number at the start of the file

00 00 27 0A

An Esri shapefile's .shp geometry file starts with the file code 9994 stored big-endian, which yields the bytes 00 00 27 0A. The same header also appears in the companion .shx index file of the set.

Hex signature
00 00 27 0A
Offset
0 (start of file)
Length
4 bytes

What this magic number means

A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes 00 00 27 0A, it is a Shapefile file.

The 100-byte header mixes byte orders on purpose: the file code and lengths are big-endian while the bounding box that follows is little-endian, a quirk identifiers must handle.

Formats that use the 00 00 27 0A signature

These file types in our database carry this signature:

How to check a file's signature

You can read the first bytes of any file yourself. The magic bytes are shown in hex, the same way this page lists them.

Linux & macOS

  • xxd -l 16 example.shp
  • hexdump -C -n 16 example.shp
  • file example.shp

Windows (PowerShell)

  • Format-Hex -Path example.shp -Count 16

Python

  • open("example.shp","rb").read(4).hex()

In your browser

Frequently asked questions

What is the Shapefile file signature?

Shapefile files start with the hex bytes 00 00 27 0A. This magic number identifies the format regardless of the file's name or extension.

How do I check a file's magic number?

Open the file in a hex editor, or run a command such as xxd -l 16 example.shp on Linux or macOS, or Format-Hex -Path example.shp -Count 16 in Windows PowerShell, and read the first bytes.

Can a file fake the Shapefile signature?

Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine Shapefile file has these exact bytes; a file with the wrong bytes is not really Shapefile, whatever its name says.

Related signatures

Sources