Comma-Separated Values (.csv)
RFC StandardComma-Separated Values (CSV) is a ubiquitous plain-text format for tabular data, where each line represents a data record and fields are separated by delimiter characters.
Convert XLSX to CSV
Free in-browser XLSX to CSV converter. Convert files instantly on your device.
Compress CSV Online
100% private in-browser compression - files never leave your device
Inspect & Metadata
Operating systems and file analyzers identify CSV files by inspecting the leading binary byte sequence:
Byte-Level Header Signature (Magic Bytes)
Operating systems and file analyzers identify CSV files by inspecting the leading binary byte sequence:
HEX SIGNATURE (OFFSET 0):
Plain TextASCII REPRESENTATION: ASCII / UTF-8
Standardization: RFC 4180 / IETF
Technical Specifications
| Container Architecture | Delimited flat text file representing tabular data rows and columns |
| Compression | Gzip / Deflate achieves 85%-95% compression on repetitive tabular records |
| Byte Endianness | UTF-8 text stream (optional UTF-8 BOM EF BB BF used by Excel) |
| Color Spaces | Not applicable |
| Channels & Structure | Row records delimited by CRLF with columns delimited by commas |
| Max Dimensions | Unbounded; streamable to gigabytes without loading entire file in memory |
| Transparency | Not applicable |
| Streaming & Progressive | Native line-by-line stream processing supported by all data pipelines |
Technical Comparison Matrix: CSV vs Competitors
| Technical Attribute | CSV (Current) | Excel (XLSX) | Parquet | JSON |
|---|---|---|---|---|
| File Type | Plain text flat table | Zipped XML spreadsheet | Binary columnar storage | Hierarchical text |
| Multiple Sheets | No (single flat table only) | Yes (multiple workbooks and sheets) | Partition-based storage | Nested arrays and objects |
| Data Types | Untyped raw text | Typed cells, formulas, formatting | Strict binary column types | Primitive types (string, number, bool) |
| Big Data Analytics | Slow (requires reading every row linearly) | Not suitable for big data | Ultra-fast (column pruning & predicate pushdown) | Moderate |
Common Corruption Modes & Hex Recovery Guide
⚠️ Columns shift to the right or row counts do not match.
Root Cause: A text field containing an unescaped comma without surrounding quotation marks.
Recovery: RFC 4180 requires fields containing commas to be wrapped in double quotes: "Smith, John".
⚠️ Accented characters render as strange symbols (mojibake like é instead of é) in Excel.
Root Cause: Excel opened a UTF-8 CSV assuming the legacy Windows ANSI/CP1252 character encoding.
Recovery: Prepend the 3-byte UTF-8 Byte Order Mark (0xEF 0xBB 0xBF) to the beginning of the file.
Security Analysis & Parser Attack Vectors
CSV files open directly in spreadsheet software like Excel and Google Sheets, exposing users to Formula Injection (CSV Injection) attacks.
Known Attack Vectors
- Formula Injection: Cells starting with '=', '+', '-', or '@' executing spreadsheet macros or DDE commands (e.g. '=cmd|' /C calc'!A0').
- Data exfiltration via HYPERLINK() formulas sending sensitive cell data to remote attacker servers upon click.
Defensive Best Practices: When exporting user data to CSV, prepend a single quote (') or tab to any cell starting with '=', '+', '-', or '@' to force plain text rendering in Excel.
Historical Origins & Milestones
Key Advantages & Pros
- Maximum simplicity: readable in any text editor and importable into every database and spreadsheet.
- Extremely fast line-by-line streaming without building a full in-memory DOM.
- Minimal overhead: no verbose tag syntax or schema definitions.
Technical Limitations & Cons
- No standard data types: numbers, dates, booleans, and text are all stored as raw strings.
- No support for multiple sheets, cell formatting, formulas, or metadata.
- Delimiter conflicts (commas inside text, decimal commas in European locales) cause frequent parsing bugs.
Interesting Technical Trivia
- In many European countries where commas are used as decimal points, semicolons (;) are used instead of commas as CSV separators.
- Microsoft Excel historically required a UTF-8 BOM (0xEF 0xBB 0xBF) to correctly display non-ASCII accented characters.
Frequently Asked Technical Questions
What is RFC 4180?
RFC 4180 is the official IETF standard for CSV. It mandates that fields containing commas, line breaks, or double quotes must be enclosed in double quotes, and internal quotes must be escaped by doubling them ("").
Why do CSV files open with corrupted characters in Excel?
Older versions of Microsoft Excel default to the local Windows code page (like Windows-1252) rather than UTF-8 when opening CSV files directly. Adding a UTF-8 BOM (Byte Order Mark) at the start of the file forces Excel to decode UTF-8 correctly.
Related CSV Conversion Pairs
Export Microsoft Excel spreadsheets into clean, comma-separated plain text tables.
Import CSV tabular data into formatted Microsoft Excel XLSX workbooks.
Import tabular CSV spreadsheet records directly into indexed SQLite database tables.
Extract table records and rows from SQL INSERT statements into standardized comma-separated CSV spreadsheets.
Extract multidimensional scientific datasets and numerical matrices from HDF5 (.h5) into tabular CSV format.
Flatten multidimensional NetCDF (.nc) climate and oceanographic variables into comma-separated CSV spreadsheets.
Convert electronic business cards (vCard / VCF) into tabular CSV contact lists for Excel and Google Contacts.