application/vnd.microsoft.portable-executable

All MIME types
Application · Vendor tree.exe .dll

Media type / application

application/vnd.microsoft.portable-executable

Windows executables and DLLs in the Portable Executable format.

Served inline: Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.

Browser behaviour

Downloads

Charset

no charset

Compression

Compress in transit

Send it like this

Content-Type: application/vnd.microsoft.portable-executable

A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.

Handling verdict

InlineDownloads

Browsers have no renderer for this, so it downloads even without a Content-Disposition header. That makes it the quiet default for anything you do not want opened in place.

Charsetno charset

A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.

CompressionCompress in transit

The payload is text-like or otherwise repetitive, so gzip or Brotli removes real bytes. Enable it at the server or CDN.

NameVendor tree

A `vnd.` subtype belongs to a specific product or organisation. It is registered, but its meaning is defined by that vendor rather than by a standards body.

Anatomy of the name

RFC 6838

Top-level type

application

Application

Subtype

vnd.microsoft.portable-executable

Registered in the vendor tree.

Structured syntax

none

No suffix, so the payload format is defined entirely by the subtype itself.

Parameters

none

Beyond the charset rule above, this type defines no parameters of its own.

What trips people up

1 note
  • The MZ signature at offset 0 is the reliable check; the extension is not, and renaming does not change the bytes.

Response headers

Content-Type: application/vnd.microsoft.portable-executable
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename="example.exe"
Vary: Accept-Encoding

nosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Content-Disposition: attachment names the saved file and removes any doubt about rendering.

Server configuration

extension mapping

nginx

types {
    application/vnd.microsoft.portable-executable  exe dll;
}

Apache

AddType application/vnd.microsoft.portable-executable .exe .dll

Caddy

@type path *.exe *.dll
header @type Content-Type "application/vnd.microsoft.portable-executable"

Extensions and other spellings

with signature

File extensions

Also written as

application/x-msdownloadapplication/x-dosexec

These reach the same handler in practice. Accept them on input; send application/vnd.microsoft.portable-executable on output.

File signature

4D 5A

Check these bytes rather than the client-supplied Content-Type when validating an upload. The header is a claim; the signature is evidence.

Related media types

8
Familyapplication
Treevendor
Suffix
Inlinedownload