Media type / video
video/x-m4v
Apple's MPEG-4 variant: structurally an MP4, distinguished so iTunes and QuickTime can treat it as a movie or TV episode rather than a generic video file.
Served inline: Browsers display this in the tab without granting it script access to the page. Safe to serve inline, provided the bytes really are what the header claims.
Browser behaviour
Renders inertly
Charset
no charset
Compression
Already compressed
Send it like this
Content-Type: video/x-m4vA binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.
Handling verdict
Browsers display this in the tab without granting it script access to the page. Safe to serve inline, provided the bytes really are what the header claims.
A binary payload has no character encoding. A charset parameter here is meaningless and occasionally confuses strict parsers.
The format compresses internally. Another transport encoding costs CPU on both ends and typically changes the size by less than a percent — sometimes upward.
An `x-` prefix marks a type that was never registered. RFC 6838 discourages new ones, but several — like application/x-www-form-urlencoded — are now too widespread to change.
Anatomy of the name
RFC 6838Top-level type
video
Video
Subtype
x-m4v
Registered in the unregistered tree.
Structured syntax
none
No suffix, so the payload format is defined entirely by the subtype itself.
Parameters
none
Beyond the charset rule above, this type defines no parameters of its own.
What trips people up
3 notes- An unprotected .m4v is an MP4 in every respect — renaming the extension makes it play anywhere MP4 plays.
- Files bought from the iTunes Store may carry FairPlay DRM, which no browser can decode regardless of the type you send.
- Serving it as video/mp4 is the safer default for the web; keep video/x-m4v for Apple-native workflows that read the distinction.
Response headers
Content-Type: video/x-m4v
X-Content-Type-Options: nosniff
Content-Disposition: inlinenosniff stops the browser second-guessing the type you declared, which is what makes the rest of this reliable. Serving it inline is safe here because the browser renders it without granting it script access.
Server configuration
extension mappingnginx
types {
video/x-m4v m4v;
}Apache
AddType video/x-m4v .m4vCaddy
@type path *.m4v
header @type Content-Type "video/x-m4v"Extensions and other spellings
with signatureFile extensions
File signature
?? ?? ?? ?? 66 74 79 70
Check these bytes rather than the client-supplied Content-Type when validating an upload. The header is a claim; the signature is evidence.