Key facts
- Must be well-formed: one root element, every tag closed, tags properly nested and attribute values quoted.
- MIME type is application/xml (text/xml is also used); feeds and sitemaps often have more specific types.
- The optional declaration <?xml version="1.0" encoding="UTF-8"?> must be the very first thing in the file.
- Characters such as & and < must be escaped as & and < or placed in a CDATA section.
- Structure can be validated against a DTD or XSD schema; parsers should disable external entities to avoid XXE attacks.
How to open a .xml file
Open it in VS Code or Notepad++ for editing, or drag it into a browser for a collapsible tree view.
Open it in a browser, TextEdit or a code editor, or run xmllint --format file.xml in Terminal (xmllint ships with macOS).
Run xmllint --noout file.xml to check it is well-formed and xmllint --format file.xml to pretty-print (package libxml2-utils on Debian/Ubuntu).
Common problems and fixes
- "XML declaration allowed only at the start of the document"
- Something precedes <?xml, often whitespace, a blank line or a byte-order mark added by PHP or an editor. Remove everything before the declaration and save as UTF-8 without BOM.
- "Opening and ending tag mismatch" or "not well-formed"
- A tag is not closed or is closed in the wrong order. Go to the line the parser reports and fix the nesting.
- "EntityRef: expecting ';'" or errors at an ampersand
- A raw & appears in text or a URL. Replace it with &, or wrap the text in <![CDATA[ ... ]]>.
- "Input is not proper UTF-8"
- The file declares UTF-8 but contains Windows-1252 bytes. Convert it to real UTF-8 or change the declared encoding to match.
- Sitemap or RSS feed rejected by Google or a reader
- Check it is well-formed first, then confirm it uses the correct namespace and required elements. Search Console's sitemap report shows the specific error.
Often converted to or from: JSON, CSV, YAML, HTML