Media type / text
text/xml
XML intended to be readable by a casual user. In practice application/xml is the type to send — RFC 7303 keeps this one only for legacy reasons.
Served inline: Browsers display this in the tab without granting it script access to the page. Safe to serve inline, provided the bytes really are what the header claims.
Browser behaviour
Renders inertly
Charset
charset required
Compression
Compress in transit
Send it like this
Content-Type: text/xml; charset=utf-8Send `; charset=utf-8`. Without it the receiver falls back to its own default — for some text types that default is us-ascii, and any non-ASCII character then renders wrong.
Handling verdict
Browsers display this in the tab without granting it script access to the page. Safe to serve inline, provided the bytes really are what the header claims.
Send `; charset=utf-8`. Without it the receiver falls back to its own default — for some text types that default is us-ascii, and any non-ASCII character then renders wrong.
The payload is text-like or otherwise repetitive, so gzip or Brotli removes real bytes. Enable it at the server or CDN.
Registered with IANA through a public review process, so the name is stable and every implementation can rely on it meaning the same thing.
Anatomy of the name
RFC 6838Top-level type
text
Text
Subtype
xml
Registered in the standards tree.
Structured syntax
none
No suffix, so the payload format is defined entirely by the subtype itself.
Parameters
charset
Beyond the charset rule above, this type defines no parameters of its own.
What trips people up
1 note- text/xml defaults to us-ascii when the charset parameter is absent, which is why an unlabelled UTF-8 document can break under it.
Response headers
Content-Type: text/xml; charset=utf-8
X-Content-Type-Options: nosniff
Content-Disposition: inline
Vary: Accept-Encodingnosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Serving it inline is safe here because the browser renders it without granting it script access.
Server configuration
extension mappingnginx
types {
text/xml xml;
}Apache
AddType text/xml .xml
AddCharset UTF-8 .xmlCaddy
@type path *.xml
header @type Content-Type "text/xml; charset=utf-8"Extensions and other spellings
declaredFile extensions
File signature
No fixed signature — this format has no reliable magic number, so identify it by parsing rather than by the first few bytes.