MIME type lookup
Find the MIME type for a file extension, or what extensions a type covers — and why the same file gets a different type on a different machine.
The real question behind this lookup
Most people arriving here are not curious about MIME types. They have had a file rejected by an upload form that claims to accept it, and they want to know why.
The answer is almost always this: the same file has different MIME types on different machines. A browser does not inspect the file to decide what to call it — it asks the operating system, and the operating system consults a registry that software installs into.
So a .csv arrives as text/csv on a machine with nothing special installed, as application/vnd.ms-excel on a Windows machine with Excel, and as text/plain on plenty of others. An upload filter that accepts only the first refuses a perfectly good file from anyone with Office installed, and the person uploading has no way to work out why.
Where a type has more than one form in real use, all of them are listed here, and the ambiguity is called out.
What this table is, and is not
It is drawn from the IANA registry and from what browsers actually send. It is deliberately not read from the operating system.
That distinction is not academic: Python's own mimetypes module reads the Windows registry, and on a machine with Excel installed it reports a .csv as application/vnd.ms-excel. That is a true answer about that computer and the wrong answer for a web upload filter, and building a filter from it produces exactly the bug described above.
Both directions
Give it an extension, a filename or a full MIME type. .csv, report.xlsx and image/webp all work, and a type tells you which extensions carry it — useful when a server has told you it received application/octet-stream and you are trying to work out what the user actually sent.
One per line to look up a whole set at once, which is what you want when writing an accept list.
How to write an upload filter that works
Three things, in order of importance.
Filter on the extension, not the MIME type, or accept every type listed here for the extensions you want. The extension is what the user controls and what is consistent across machines.
Then check the actual bytes. The MIME type a browser sends is a claim, not a fact — it comes from the filename and the OS registry, and anyone can change it. Real formats have magic bytes at the start of the file: %PDF, PK for anything zip-based including every Office document, \xFF\xD8\xFF for JPEG. That is the check that means something.
And never trust it for security. A file called photo.jpg sent as image/jpeg can contain anything at all.
application/octet-stream
Means "bytes, no further information". It is what you get when nothing recognises the extension, and it is also what some browsers send for a file with no extension at all. If a server logs it, the useful next step is to look at the filename and the first few bytes rather than the declared type.
Common questions
Why was my CSV rejected by a form that accepts CSV?
Because the browser asked your operating system what to call it, and on a machine with Excel installed that answer is application/vnd.ms-excel rather than text/csv. A filter accepting only one of them refuses valid files.
Which MIME type is the "right" one?
For an accept list, all of them. The IANA type is listed first here, but a filter has to allow the variants browsers actually send or it will reject real files.
Should I filter uploads by MIME type?
Filter by extension, then check the first few bytes of the file. The MIME type is a claim from the client, not a fact about the contents.
What is application/octet-stream?
Bytes with no further information — what you get when nothing recognises the extension, or when the file has none. Look at the filename and magic bytes instead.
Why not just use the operating system\u2019s answer?
Because it differs from machine to machine. Python\u2019s mimetypes module reads the Windows registry and reports .csv as an Excel type, which is true locally and wrong for a web filter.
Can someone lie about the MIME type?
Trivially. It is sent by the client. Never make a security decision on it — check the actual bytes.