Media type / image
image/vnd.microsoft.icon
ICO containers holding several favicon sizes in one file, still expected at /favicon.ico.
Served inline: Browsers display this in the tab without granting it script access to the page. Safe to serve inline, provided the bytes really are what the header claims.
Browser behaviour
Renders inertly
Charset
no charset
Compression
Already compressed
Send it like this
Content-Type: image/vnd.microsoft.iconA binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.
Handling verdict
Browsers display this in the tab without granting it script access to the page. Safe to serve inline, provided the bytes really are what the header claims.
A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.
The format compresses internally. Another transport encoding costs CPU on both ends and typically changes the size by less than a percent — sometimes upward.
A `vnd.` subtype belongs to a specific product or organisation. It is registered, but its meaning is defined by that vendor rather than by a standards body.
Anatomy of the name
RFC 6838Top-level type
image
Image
Subtype
vnd.microsoft.icon
Registered in the vendor tree.
Structured syntax
none
No suffix, so the payload format is defined entirely by the subtype itself.
Parameters
none
Beyond the charset rule above, this type defines no parameters of its own.
What trips people up
1 note- image/x-icon is the unregistered spelling browsers actually send and accept; both work.
Response headers
Content-Type: image/vnd.microsoft.icon
X-Content-Type-Options: nosniff
Content-Disposition: inlinenosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Serving it inline is safe here because the browser renders it without granting it script access.
Server configuration
extension mappingnginx
types {
image/vnd.microsoft.icon ico;
}Apache
AddType image/vnd.microsoft.icon .icoCaddy
@type path *.ico
header @type Content-Type "image/vnd.microsoft.icon"Extensions and other spellings
with signatureFile extensions
Also written as
These reach the same handler in practice. Accept them on input; send image/vnd.microsoft.icon on output.
File signature
00 00 01 00
Check these bytes rather than the client-supplied Content-Type when validating an upload. The header is a claim; the signature is evidence.