ZeroFee Tools

Home › Blog › Free Filename Sanitizer: Fix Unsafe Names

Filename sanitizer guide cover illustration

Filename Sanitizer: Clean Up Filenames That Break Everything

Filenames break things in the quietest ways. A report named "Q3 Results: Final (v2).pdf" sails through your Mac, then chokes a Windows colleague's sync, breaks a URL and confuses a command-line script, all because of a colon and some spaces. The free Filename Sanitizer from ZeroFee Tools takes any messy name and rewrites it into a safe, portable filename that works on Windows, macOS and Linux, with your file extension preserved untouched.

It handles the full mess: illegal characters, stray spaces, accented letters, overlong names. Sanitizing happens live as you type, entirely in your browser, so even sensitive filenames never leave your device. When one file becomes dozens, hand the cleaned names to the bulk filename generator; when the file is a web image, the SEO image filename generator builds a search-friendly name instead; and for URLs rather than files, the URL slug cleaner applies the same discipline to web addresses.

Which characters are actually illegal in filenames?

Windows forbids nine characters: < > : " / \ | ? * plus any control character. macOS and Linux forbid the forward slash and the null character. A filename that is perfectly legal on your Mac can be un-saveable, un-syncable or un-openable on a colleague's Windows machine, which is why cross-platform safety means satisfying the strictest system.

The colon is the classic trap. macOS users type "Meeting Notes: March" without thinking, because the Mac has historically tolerated colons in display names while the underlying filesystem quietly translated them. Send that file to Windows and the save fails outright, or worse, a sync tool renames it into something unrecognizable and now two versions of the file exist. Question marks, asterisks and quotes cause similar chaos in URLs, shell scripts and older backup software.

Spaces are not illegal anywhere, but they are guilty by association. They break in unquoted command lines, need percent-encoding in URLs and trip up sloppy upload forms. The sanitizer gives you all four strategies: hyphens for web-facing files, underscores when a system treats hyphens specially, full removal for maximum compactness, or keeping them when a human-readable archive name matters more than machine safety.

Should filenames use hyphens, underscores or nothing?

Hyphens are the best default: they are URL-safe, readable and treated as word separators by search engines. Underscores suit programming contexts and systems that treat hyphens specially. Removing separators entirely is the most compact but the least readable. Keep spaces only for personal archives where humans, not machines, do the reading.

The hyphen's advantage is that it pleases both humans and machines. "annual-report-2026.pdf" reads naturally and survives URLs, email attachments and every operating system without encoding. Search engines treat hyphens as word separators, so if the file ever lives on the web, the hyphenated name doubles as a tiny SEO signal, a detail the SEO image filename generator exploits deliberately.

Underscores have one stronghold: code. Some build tools, variable-naming conventions and legacy systems parse hyphens as minus signs, so "dataset_v3.csv" is safer than "dataset-v3.csv" in a data pipeline. Full removal, "annualreport2026.pdf", is a relic of ancient 8.3 filename limits and is rarely worth the readability cost today. Whatever you choose, the sanitizer applies it consistently, which matters more than the choice itself: a folder where every file follows the same convention is navigable, and a mixed folder is not.

Why does the tool preserve the file extension?

The extension tells the operating system which application opens the file, so mangling it breaks the file's usability even when the name looks cleaner. The sanitizer splits the name at the last dot, cleans only the base name and reattaches the extension exactly as it was, so "My Report.PDF" becomes "my-report.PDF" and still opens correctly.

This sounds obvious until you watch a naive find-and-replace do it wrong. A blanket rule that strips dots or lowercases everything can turn "archive.tar.gz" into a file the system no longer recognizes, or rename ".PDF" to ".pdf" and break a case-sensitive web server's link to it. Splitting at the last dot is the correct behavior: everything before it is the human's naming choice and fair game, everything from it onward is machine instructions and must be preserved.

There is a subtlety worth knowing: files with no extension, or dotfiles like ".htaccess" that start with a dot, need care. A sanitizer that assumes an extension exists can mangle these edge cases, which is why extension-awareness is a feature worth checking rather than assuming. The same care applies to the max-length control: trimming applies to the base name so a long title never eats into the characters the extension needs.

What about accents, emoji and very long filenames?

Accented characters like e with an accent are legal on modern systems but break older software, some servers and cross-platform archives, so the sanitizer can transliterate them to plain ASCII. Emoji in filenames cause failures in backup tools, email gateways and Windows applications. Long names should be trimmed to stay safely under the 255-character limit most filesystems enforce.

Accents live in an uncomfortable middle ground. "resume-jose.pdf" works everywhere; "resume-jose-with-accent.pdf" works on modern systems but can corrupt inside zip files extracted on older machines or choke a misconfigured web server. Transliteration to plain ASCII is the conservative choice for anything that will travel: emailed, uploaded, archived or synced. For a personal local folder you will never share, keeping the accents is perfectly fine.

Length is the silent killer of deep folder structures. Most filesystems cap a single name at 255 characters, but the full path limit on Windows, historically 260 characters, counts every folder above the file. A descriptive 180-character filename nested five folders deep can exceed the path limit even though the name itself is legal. The max base-name length control trims the name to a budget you set, keeping archives portable no matter how deep the folder tree grows.

How to use the Filename Sanitizer in 4 steps

  1. Paste the messy filename. Drop in any name, illegal characters, spaces, accents and all. The clean version appears instantly below.
  2. Choose your space and character rules. Pick hyphens, underscores, removal or kept spaces; decide whether illegal characters are removed or replaced; toggle lowercase and accent removal.
  3. Set a length cap if needed. Use the max base-name length to trim long names for archives, uploads or systems with path limits. Zero means no limit.
  4. Copy the clean name. One click copies the sanitized filename, extension intact, ready to paste wherever the file is going.

6 practical filename tips

Frequently asked questions

Which characters are illegal in filenames?

On Windows, nine characters are forbidden: : " / \ | ? * plus any control character. macOS and Linux forbid / and the null character. This tool removes or replaces all of them so the result works across every operating system.

Is this filename sanitizer really free?

Yes. Unlimited sanitizing with no signup, no watermark and no daily caps. Everything runs locally in your browser with plain JavaScript, so there is no server cost to pass on to you.

Will it keep my file extension?

Yes. The tool splits the name at the last dot, sanitizes only the base name and reattaches the extension untouched, so a file ending in .PDF keeps working exactly as before.

Spaces or hyphens: which is better for filenames?

Hyphens or underscores are safest, since spaces break in URLs, command lines and some upload forms. Use hyphens for web-facing files and SEO, underscores when a system treats hyphens specially.

Do you upload or store my filenames?

No. Sanitizing happens entirely in your browser as you type, using plain JavaScript. Nothing is sent to a server, stored in a database or logged, so even filenames containing sensitive project or client names stay completely private.

Ready to try it yourself? It's free, no signup required.

Try the free Filename Sanitizer →