File Signatures and Magic Numbers
Last reviewed on May 11, 2026
A file extension is just a label. The bytes inside the file are the file. Most well-known formats start with a fixed byte sequence — called a magic number or file signature — that identifies them no matter what the filename claims. Learning to read that signature solves a surprising number of "this file won't open" problems and makes it much harder for a disguised executable to fool you.
Why signatures exist
Operating systems can't always trust extensions. They might be missing, wrong, or stripped by an email gateway that rewrites attachments. Applications still need a way to know whether a file is something they can handle, so almost every binary format begins with a few bytes that act as a self-identifier. Text-based formats often do the same with a recognisable opening line.
The principle is older than the web: PNG, JPEG, ZIP, and PDF all use this approach, and so do most modern formats designed since. When you open a PDF and the reader complains it isn't a PDF, that message usually reflects a signature check, not the extension.
Common signatures worth recognising
You don't need to memorise every signature, but a handful come up so often that it's worth being able to spot them at a glance. The bytes below are shown in hexadecimal; the ASCII column shows how they look in a text view.
25 50 44 46 2D→%PDF-— a PDF document.89 50 4E 47 0D 0A 1A 0A→‰PNG…— a PNG image.FF D8 FF— JPEG, with the fourth byte indicating the specific JPEG variant.47 49 46 38→GIF8— a GIF image (followed by7aor9a).50 4B 03 04→PK..— a ZIP archive, and therefore also DOCX, XLSX, PPTX, EPUB, JAR, APK, and many other ZIP-based formats.52 61 72 21 1A 07→Rar!..— a RAR archive.37 7A BC AF 27 1C— a 7-Zip archive.1F 8B— a gzip stream (.gz, .tgz, .tar.gz body).4D 5A→MZ— a Windows executable (.exe, .dll). Treat this with suspicion in anything that claims to be a document.7F 45 4C 46→.ELF— a Linux executable.CA FE BA BE— a Java class file or a macOS universal binary.FF FB,FF F3,FF F2, or49 44 33— MP3 audio (theID3form indicates an ID3 metadata tag at the start).66 4C 61 43→fLaC— a FLAC audio file.52 49 46 46 …. WAVE→RIFFcontainer withWAVEat offset 8 — a WAV file.00 00 00 20 66 74 79 70— an MP4/MOV container (the four bytes afterftypidentify the specific brand:isom,mp42,qt,heic, etc.).
Several of those entries are the reason your computer treats a renamed DOCX or APK as a corrupt ZIP. They are ZIP archives — the signature is identical — just with specific contents.
Reading the signature without specialist tools
On any of the major operating systems, you can read the first few bytes of a file with built-in commands.
Linux and macOS
The file command does the whole job — it reads the signature, looks it up in a built-in database,
and prints a human-readable description:
file unknown.bin
For the raw bytes, xxd or hexdump show the start of the file in hex with an ASCII
column alongside:
xxd -l 32 unknown.bin
hexdump -C -n 32 unknown.bin
Windows
PowerShell can read the first bytes directly:
Format-Hex -Path unknown.bin -Count 32
Or, for plain raw bytes:
Get-Content unknown.bin -Encoding Byte -TotalCount 16
A GUI hex viewer is also useful; HxD, Frhed and many code editors with hex modes display the first bytes clearly alongside the ASCII representation.
Worked example: a mislabelled "PDF"
Suppose you receive report.pdf from a colleague and your PDF reader refuses to open it. Before
blaming the reader, dump the first bytes:
$ xxd -l 16 report.pdf
00000000: 504b 0304 1400 0600 0800 0000 2100 ... PK..........!.
The signature is 50 4B 03 04, which is ZIP — not PDF. The file is almost certainly a Word document
saved with the wrong extension during export, or an export that produced a DOCX rather than a PDF and the user
renamed it. Renaming the file to .docx and opening it in Word usually resolves the situation.
The same diagnostic catches the more dangerous case: a ".pdf" whose signature is MZ
is a Windows executable disguised with a misleading filename. Stop and treat the file as untrusted.
When signatures don't help
Magic numbers solve a lot of the "what is this?" problem, but not all of it:
- Encrypted files show as high-entropy random bytes with no signature.
- Plain-text formats (CSV, JSON, XML, source code, log files) don't have a fixed magic number. A text editor and a guess based on the content are usually all you need; encoding issues are covered in the character encoding guide.
- Container formats like MP4 carry sub-format information further in (the four bytes after
ftypdistinguish MP4 from MOV from HEIC). - Stripped or truncated files may have lost the first bytes entirely; in that case see our guide on corrupted files.
Where this leads
Once you've confirmed what a file really is, the rest of the diagnostic flow is much simpler. The unknown-extension guide walks through what to do when the extension itself was the mystery, and the file formats overview covers why extensions and signatures can drift apart in the first place.
For security-sensitive contexts — assessing files from untrusted senders, evaluating downloads, or auditing what ended up in a backup — verifying signatures together with checksums (covered in the integrity verification guide) gives a reliable picture of what a file is and whether it has been tampered with.