Excel CSV Damage Checker
See, cell by cell, what Excel silently changes when you double-click a CSV: leading zeros, digits past the 15th, dates made from gene names and fractions, formulas and more. Then download a copy Excel cannot damage.
How to Use
- Paste a CSV or drop a .csv file (up to 20 MB), or press a preset. The check runs as you type.
- Read the grid: red cells lose data or run as formulas, amber cells turn into dates or numbers, blue cells only change how they look. Each one shows what Excel would display beneath it.
- Check the list under the grid for each flagged cell’s reason, and the file-level notes for the delimiter, the “ID” SYLK warning and the encoding.
- Choose how to protect cells: ="…" (shows the text unchanged) or a leading apostrophe. Formula risks always get the apostrophe.
- Press Download safe CSV, or better, open the original in Excel with Data › From Text/CSV and set the columns to Text before loading.
Predicts Excel desktop with English (United States) settings, opening the .csv by double-click: comma-separated, month/day dates, General format. Other locales differ — day/month date order, ; as the list separator, a comma as the decimal point. Recent Microsoft 365 versions can switch some conversions off under File › Options › Data. Results marked may depend on version and settings.
Worked Example
One line from a customer export: Ada,02134,+1-555-0100,1234567890123456789,MARCH1,true, double-clicked in Excel with English (United States) settings.
02134 looks like a number, so it is stored as 2134: the leading zero is gone.
+1-555-0100 starts with +, so Excel reads the formula =+1-555-0100. The 0100 is just 100, so it calculates 1 − 555 − 100 = −654 and shows that instead of the phone number.
1234567890123456789 has 19 significant digits. Excel keeps 15 and turns the other 4 into zeros, storing 1234567890123450000, and General format shows 1.23457E+18 (6 significant digits, rounded, to fit 11 characters).
MARCH1 is a month name followed by a day, so it becomes the date 1 March of the current year, shown as 1-Mar.
true becomes the logical value TRUE. Only “Ada” survives untouched: 5 of 6 cells change.
The safe CSV writes 02134, the ID, MARCH1 and true as, for example, "=""02134""" (the formula ="02134", which shows the text exactly) and the phone number as '+1-555-0100, so none of them can be converted or run.
The common mistake: fixing it inside Excel after the double-click — selecting the column and formatting it as Text, or re-saving the file. By then 02134 is already the number 2134 and the 19-digit ID is already 1234567890123450000; formatting as Text just turns those wrong values into text, and saving writes them back to the CSV for good. The types have to be set before the data is loaded (Data › From Text/CSV), or the file has to be protected first.
Show Work
The Rules Checked
Why Excel Changes CSV Files
A CSV file is only text: it has no column types, no formats and no way to say “this is a code, not a number”. When you double-click one, Excel guesses each cell’s type the same way it would if you typed it, which is helpful for a column of prices and destructive for anything that only looks like a number or a date.
The 15-digit limit comes from how Excel stores numbers: as 64-bit IEEE 754 floating point, which holds about 15–17 significant decimal digits. Microsoft’s specifications list the number precision as 15 digits, and its documentation says digits beyond the 15th are changed to zeros — which is why credit card numbers, IMEIs and database IDs of 16 or more digits cannot survive as numbers.
Dates caused the best-known damage. In 2016 Mark Ziemann, Yotam Eren and Assam El-Osta reported in Genome Biology that about one in five papers with supplementary Excel gene lists contained gene names converted to dates, such as SEPT2 and MARCH1. In 2020 the HUGO Gene Nomenclature Committee renamed the affected human genes — SEPT1 became SEPTIN1 and MARCH1 became MARCHF1 — citing the spreadsheet problem among its reasons.
Formula injection was described in security research in the mid-2010s, and OWASP’s CSV Injection page lists the characters to neutralise: =, +, -, @, tab and carriage return. Microsoft also documents that a text file whose first two characters are the capital letters “ID” is taken for a SYLK (symbolic link) spreadsheet, which produces a format warning.
About This Tool
This tool reads a CSV with an RFC 4180 parser (quoted fields, doubled quotes and line breaks inside quotes), detects the delimiter, and runs every cell through the conversions Excel applies on a double-click: numbers, leading zeros, the 15-digit limit, E-notation, dates, times, booleans, number formats, formulas and hidden spaces. Each flagged cell shows what Excel would display and why, and the file is checked for the delimiter, the SYLK “ID” warning, the encoding and Excel’s sheet limits.
The predictions follow Excel’s documented and widely reproduced default behaviour for English (United States); anything that depends on version, settings or locale is marked may. Formula results are calculated by a small arithmetic parser, never by running the text. Everything happens in your browser; nothing you paste or drop is uploaded.
Related tools: JSON ⇄ CSV Converter, CSV Viewer, and Database Viewer.
Frequently Asked Questions
Why does Excel remove the leading zeros from my CSV?
A CSV file has no column types, so Excel opens every cell in General format and reads anything that looks like a number as a number: the ZIP code 02134 becomes 2134 and the ID 00501 becomes 501. Putting the value in quotes in the CSV does not help; quotes only group characters. Either import with Data › From Text/CSV and set the column to Text, or write the cell as ="02134", which is what the safe download does.
Why do long numbers show as 1.23457E+18 and end in zeros?
Excel stores numbers as 64-bit floating point and keeps only 15 significant digits; Microsoft documents that any digit after the 15th is changed to zero. 1234567890123456789 is stored as 1234567890123450000, and the 16-digit card number 4111111111111111 as 4111111111111110 — the original is gone once the file is saved. Numbers of 12 to 15 digits keep their value but show as, for example, 1.23457E+11, because General format fits a number into 11 characters.
Why does Excel turn gene names and fractions into dates?
Excel recognises a month name followed by a number as a day: MARCH1 becomes 1-Mar, SEPT2 becomes 2-Sep and DEC1 becomes 1-Dec. With English (United States) settings it also reads m/d and m-d, so 1/4 becomes 4-Jan, not 0.25, and 3-4 becomes 4-Mar (in a day-first locale such as English (UK) it would be 3-Apr). When the second number cannot be a day, as in 11-50, it may become a month and year (Nov-50). Recent Microsoft 365 versions have Automatic Data Conversion settings under File › Options › Data that can turn some of these off.
What is CSV injection, and how does the safe download handle it?
A cell starting with =, +, - or @ is read as a formula. Harmless ones just change your data (+1-555-0100 shows -654, +1+2 shows 3); a crafted one such as =HYPERLINK("http://…","Click") or a DDE payload can send data out or start a program once the user accepts the warnings. OWASP recommends prefixing such cells with a single quote, so the safe download always writes them as '=1+1. The apostrophe becomes part of the text, which is the price of making it inert.
How big a file can it check, and is anything uploaded?
Up to 20 MB of text. The first 1,000,000 cells are checked and exported; the rest are counted, so a file with more rows than Excel’s 1,048,576 is still reported. The check runs in short slices so the page stays responsive: a 20 MB, 1.7-million-cell test file took about 3 seconds for its first million cells. The grid shows the first 200 rows and 30 columns, and the list the worst 300 cells. Nothing leaves your browser.
How do I use the Excel CSV Damage Checker?
Simply type your numbers and read the result, which refreshes the instant you change something. There is nothing to submit and nothing to wait for.
Does it cost anything or need an account?
No. The tool is completely free, there is no account to create, and it keeps working offline after the page first loads.
Is anything I type uploaded?
No. The tool works entirely on your device, so the values you enter never leave your browser.
Common Use Cases
Customer and order exports
Before sending a CRM export to a colleague: ZIP 02134 would arrive as 2134 and the order number 1234567890123456789 as 1234567890123450000. The safe CSV keeps both.
Gene lists
A differential-expression table with SEPT2, MARCH1 and DEC1 would turn 3 symbols into 2-Sep, 1-Mar and 1-Dec. Check it before it goes into a supplementary file.
Product sizes and ranges
Sizes such as 1/2 and 1/4 become 2-Jan and 4-Jan, and a 10-12 age range becomes 12-Oct. Wrap them as text before the catalogue goes to the supplier.
Exports from a web app
Any user-typed field can start with = or +. Run a sample export through the check: a comment of +1+2 shows 3, and =HYPERLINK(…) is flagged as dangerous.
European files on a US machine
A semicolon-separated file with 1,20 decimals is flagged: a double-click in English (United States) Excel may put each line in column A. The safe copy is rewritten with commas.
Last updated: