TAR (ustar) file signature
Magic number at offset 257 · ustar
A POSIX tar archive has no header at byte 0. Instead the string ustar sits at offset 257, inside the first file's 512-byte header block. Older tar variants have no magic at all, only the structured header.
What this magic number means
A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file contains, at offset 257, the bytes 75 73 74 61 72 (the text ustar), it is a TAR (ustar) file.
Because the marker is 257 bytes in, tar is frequently seen through its outer compression: gzip (1F 8B), bzip2 (BZh) or xz. Read those outer signatures first, then the ustar marker underneath.
What each byte of 75 73 74 61 means
Here is the signature byte by byte, the way a hex editor shows it: the position in the file, the value in hex and in decimal, and the character that value stands for in ASCII. Bytes with no printable character show a dot.
| Byte offset | Hex | Decimal | ASCII |
|---|---|---|---|
| 257 | 75 | 117 | u |
| 258 | 73 | 115 | s |
| 259 | 74 | 116 | t |
| 260 | 61 | 97 | a |
| 261 | 72 | 114 | r |
Formats that use the 75 73 74 61 signature
These file types in our database carry this signature:
How to check a file's signature
You can read the bytes of any file yourself. They are shown in hex, the same way this page lists them.
Linux & macOS
- xxd -s 257 -l 5 example.tar
- hexdump -C -s 257 -n 5 example.tar
- file example.tar
Windows (PowerShell)
- Format-Hex -Path example.tar -Count 262
Python
- f=open("example.tar","rb");f.seek(257);f.read(5).hex()
In your browser
- Drop the file into the WhatFileType identifier, which reads the signature without uploading it.
Frequently asked questions
What is the TAR (ustar) file signature?
TAR (ustar) files carry, at offset 257, the hex bytes 75 73 74 61 72 (ustar in ASCII). This magic number identifies the format regardless of the file's name or extension.
How do I check a file's magic number?
Open the file in a hex editor, or run a command such as xxd -l 262 example.tar on Linux or macOS, or Format-Hex -Path example.tar -Count 262 in Windows PowerShell, and read the first bytes.
Can a file fake the TAR (ustar) signature?
Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine TAR (ustar) file has these exact bytes; a file with the wrong bytes is not really TAR (ustar), whatever its name says.
Related signatures
Sources
Reuse this signature
This entry is part of the WhatFileType file signature reference, published under a CC BY 4.0 licence with the full provenance for every entry, a copy-paste embed and a JSON export. Credit WhatFileType and the data is yours to republish.