xz file signature
Magic number at the start of the file · ý7zXZ.
The xz container starts with the six magic bytes FD 37 7A 58 5A 00, which spell 7zXZ around two guard bytes. It usually wraps LZMA2-compressed data such as a .tar.xz archive.
What this magic number means
A magic number is a short, fixed run of bytes at a known position that tells a program what a file really is, no matter what the filename says. If a file starts with the bytes FD 37 7A 58 5A 00 (the text ý7zXZ.), it is a xz file.
The two guard bytes are deliberate. FD has its high bit set so the file cannot be mistaken for text, and the trailing 00 catches transfers that strip or translate null bytes. The four in between are the readable part, 7zXZ, a nod to the LZMA algorithm's origin in 7-Zip.
A .tar.xz is a tar archive inside an xz stream, so these bytes are what the file starts with, while tar's own ustar marker only appears 257 bytes into the decompressed data. A bare .tar carries neither of the xz bytes.
What each byte of FD 37 7A 58 means
Here is the signature byte by byte, the way a hex editor shows it: the position in the file, the value in hex and in decimal, and the character that value stands for in ASCII. Bytes with no printable character show a dot.
| Byte offset | Hex | Decimal | ASCII |
|---|---|---|---|
| 0 | FD | 253 | . |
| 1 | 37 | 55 | 7 |
| 2 | 7A | 122 | z |
| 3 | 58 | 88 | X |
| 4 | 5A | 90 | Z |
| 5 | 00 | 0 | . |
Formats that use the FD 37 7A 58 signature
These file types in our database carry this signature:
It is also seen in: TXZ.
How to check a file's signature
You can read the bytes of any file yourself. They are shown in hex, the same way this page lists them.
Linux & macOS
- xxd -l 16 example.xz
- hexdump -C -n 16 example.xz
- file example.xz
Windows (PowerShell)
- Format-Hex -Path example.xz -Count 16
Python
- open("example.xz","rb").read(6).hex()
In your browser
- Drop the file into the WhatFileType identifier, which reads the signature without uploading it.
Frequently asked questions
What is the xz file signature?
xz files start with the hex bytes FD 37 7A 58 5A 00 (ý7zXZ. in ASCII). This magic number identifies the format regardless of the file's name or extension.
How do I check a file's magic number?
Open the file in a hex editor, or run a command such as xxd -l 16 example.xz on Linux or macOS, or Format-Hex -Path example.xz -Count 16 in Windows PowerShell, and read the first bytes.
Can a file fake the xz signature?
Renaming a file does not change its bytes, so the extension can lie but the signature usually cannot. A genuine xz file has these exact bytes; a file with the wrong bytes is not really xz, whatever its name says.
Related signatures
Sources
Reuse this signature
This entry is part of the WhatFileType file signature reference, published under a CC BY 4.0 licence with the full provenance for every entry, a copy-paste embed and a JSON export. Credit WhatFileType and the data is yours to republish.