Media type / image
image/bmp
Uncompressed Windows bitmaps — large files, but trivially simple to read and write.
Served inline: Browsers display this in the tab without granting it script access to the page. Safe to serve inline, provided the bytes really are what the header claims.
Browser behaviour
Renders inertly
Charset
no charset
Compression
Compress in transit
Send it like this
Content-Type: image/bmpA binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.
Handling verdict
Browsers display this in the tab without granting it script access to the page. Safe to serve inline, provided the bytes really are what the header claims.
A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.
The payload is text-like or otherwise repetitive, so gzip or Brotli removes real bytes. Enable it at the server or CDN.
Registered with IANA through a public review process, so the name is stable and every implementation can rely on it meaning the same thing.
Anatomy of the name
RFC 6838Top-level type
image
Image
Subtype
bmp
Registered in the standards tree.
Structured syntax
none
No suffix, so the payload format is defined entirely by the subtype itself.
Parameters
none
Beyond the charset rule above, this type defines no parameters of its own.
What trips people up
1 note- One of the few image types worth compressing in transit, because the pixel data is stored raw.
Response headers
Content-Type: image/bmp
X-Content-Type-Options: nosniff
Content-Disposition: inline
Vary: Accept-Encodingnosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Serving it inline is safe here because the browser renders it without granting it script access.
Server configuration
extension mappingnginx
types {
image/bmp bmp dib;
}Apache
AddType image/bmp .bmp .dibCaddy
@type path *.bmp *.dib
header @type Content-Type "image/bmp"Extensions and other spellings
with signatureFile extensions
File signature
42 4D
Check these bytes rather than the client-supplied Content-Type when validating an upload. The header is a claim; the signature is evidence.