File Signatures and Magic Numbers

Last reviewed on May 11, 2026

A file extension is just a label. The bytes inside the file are the file. Most well-known formats start with a fixed byte sequence — called a magic number or file signature — that identifies them no matter what the filename claims. Learning to read that signature solves a surprising number of "this file won't open" problems and makes it much harder for a disguised executable to fool you.

Why signatures exist

Operating systems can't always trust extensions. They might be missing, wrong, or stripped by an email gateway that rewrites attachments. Applications still need a way to know whether a file is something they can handle, so almost every binary format begins with a few bytes that act as a self-identifier. Text-based formats often do the same with a recognisable opening line.

The principle is older than the web: PNG, JPEG, ZIP, and PDF all use this approach, and so do most modern formats designed since. When you open a PDF and the reader complains it isn't a PDF, that message usually reflects a signature check, not the extension.

Common signatures worth recognising

You don't need to memorise every signature, but a handful come up so often that it's worth being able to spot them at a glance. The bytes below are shown in hexadecimal; the ASCII column shows how they look in a text view.

Several of those entries are the reason your computer treats a renamed DOCX or APK as a corrupt ZIP. They are ZIP archives — the signature is identical — just with specific contents.

Reading the signature without specialist tools

On any of the major operating systems, you can read the first few bytes of a file with built-in commands.

Linux and macOS

The file command does the whole job — it reads the signature, looks it up in a built-in database, and prints a human-readable description:

file unknown.bin

For the raw bytes, xxd or hexdump show the start of the file in hex with an ASCII column alongside:

xxd -l 32 unknown.bin
hexdump -C -n 32 unknown.bin

Windows

PowerShell can read the first bytes directly:

Format-Hex -Path unknown.bin -Count 32

Or, for plain raw bytes:

Get-Content unknown.bin -Encoding Byte -TotalCount 16

A GUI hex viewer is also useful; HxD, Frhed and many code editors with hex modes display the first bytes clearly alongside the ASCII representation.

Worked example: a mislabelled "PDF"

Suppose you receive report.pdf from a colleague and your PDF reader refuses to open it. Before blaming the reader, dump the first bytes:

$ xxd -l 16 report.pdf
00000000: 504b 0304 1400 0600 0800 0000 2100 ...   PK..........!.

The signature is 50 4B 03 04, which is ZIP — not PDF. The file is almost certainly a Word document saved with the wrong extension during export, or an export that produced a DOCX rather than a PDF and the user renamed it. Renaming the file to .docx and opening it in Word usually resolves the situation.

The same diagnostic catches the more dangerous case: a ".pdf" whose signature is MZ is a Windows executable disguised with a misleading filename. Stop and treat the file as untrusted.

When signatures don't help

Magic numbers solve a lot of the "what is this?" problem, but not all of it:

Where this leads

Once you've confirmed what a file really is, the rest of the diagnostic flow is much simpler. The unknown-extension guide walks through what to do when the extension itself was the mystery, and the file formats overview covers why extensions and signatures can drift apart in the first place.

For security-sensitive contexts — assessing files from untrusted senders, evaluating downloads, or auditing what ended up in a backup — verifying signatures together with checksums (covered in the integrity verification guide) gives a reliable picture of what a file is and whether it has been tampered with.