File Type Detector — the bytes decide, not the name
File Type Detector
The extension of a file is just a label — renaming virus.exe to
photo.jpg changes nothing inside. This page reads the first bytes of each
uploaded file and matches them against 60+ real magic signatures: images, documents,
archives, audio/video, fonts, executables, databases and keys. You get the detected type, the
MIME type, the extensions that type normally uses, a warning when the extension
contradicts the content, and where the format carries it (image dimensions, PDF version,
MP4 brand). Everything is inspected locally in your browser.
Pick files
Drop files here, or click to choose them
One file or many. Only the first 512 bytes of each are read; the files never leave this machine.
No files selected.
Results
The detection table appears here after you pick files and press Detect.
What “match” means:consistent — the extension
agrees with the detected format; mismatch — the content is a
different format than the extension claims (a renamed file, or worse); “no
signature” — the first bytes do not match any known signature, which is normal for
plain text, CSV, and most data formats that simply have no header.
Privacy: files are read with the browser's own FileReader; nothing is uploaded.
What is a file signature?
Almost every binary format starts with a fixed byte sequence — the magic
number — placed there so a program can recognise its own files without trusting
the name. A PNG always begins with the eight bytes 89 50 4E 47 0D 0A 1A 0A
(“\x89PNG\r\n\x1a\n”), a PDF with the ASCII text %PDF, a ZIP with
PK\x03\x04 (the initials of Phil Katz, who designed the format). Operating
systems mostly ignore these bytes and look at the extension instead — which is exactly
why a renamed file “opens fine” nowhere, and why security tools sniff content.
Famous first bytes
Bytes
Format
Note
89 50 4E 47 0D 0A 1A 0A
PNG image
the \r\n guards against line-ending corruption
FF D8 FF
JPEG image
every JPEG frame starts with an SOI marker
25 50 44 46 2D
PDF document
“%PDF-1.7” — the version follows
50 4B 03 04
ZIP archive
docx/xlsx/odt/epub are ZIPs wearing an extension
D0 CF 11 E0
Legacy Office
doc/xls/ppt/msi — the OLE2 compound file
4D 5A
Windows EXE
“MZ”, after Microsoft's Mark Zbikowski
7F 45 4C 46
Linux ELF
\x7fELF — programs and shared libraries
1A 45 DF A3
Matroska/WebM
EBML container start
75 73 74 61 72 at offset 257
TAR archive
the signature hides deep in the header
How the detector decides
The first 512 bytes of each file are compared against a table of signatures in
specificity order: container brands (RIFF…WAVE vs
RIFF…AVI vs RIFF…WEBP, ISO brand boxes at offset 8)
are checked before their generic containers, and ZIP-based formats (EPUB, ODF, OOXML)
before plain ZIP. Where a format carries self-describing metadata the page digs one level
deeper: PNG/GIF/BMP/JPEG/WebP dimensions are read from their headers, the PDF version from
byte 5, the MP4 brand and the Java class version from their standard offsets. Files that
match nothing get a text heuristic pass (BOM, <?xml, <html,
shebang, printable ratio) before being called unknown.
Common mistakes
“It says ZIP but the file is .docx” — that is correct: a .docx is
a ZIP archive whose first entry is [Content_Types].xml; the detector recognises
that case and reports Office Open XML specifically. “It says no signature but the
file opens fine” — CSV, most source code, and countless scientific formats
have no magic bytes at all; “no signature” is not an accusation.
“Can it tell me if the file is safe?” — no. Content sniffing says what
a file is, not what it does; an EXE is an EXE whether it is an installer or
malware.
FAQ
Why only 512 bytes? — every supported signature lives within the first 512
bytes (the deepest is TAR's ustar at offset 257); reading more would slow big
batches down for nothing. Does it detect video duration? — no, only the container and its brand; duration
requires parsing the whole index, which is a player's job. Multiple files at once? — yes, drag a whole selection; each row is detected
independently. Related page: to go the other way — extension to MIME type — use the
; to hash the same files, use
.