What is the IQY file format?
Text files holding Web queries - Internet Query files used by Microsoft applications, most notably Excel, are saved with the .iqy extension. Such files allow users to fetch information from websites and import it directly into a spreadsheet. .iqy files are by default saved in the MS Office subfolder Program Files\Microsoft Office\Queries.
.iqy is a plain-text file and can be easily opened with any text editor. Each file contains various definitions such as:
- URL - the address to send the query to
- Selection - the range of data to be fetched, for example
EntirePageor a numbered table index - Formatting - controls how data is arranged on the worksheet
- Optional parameters such as
PreFormattedTextToColumnsandSingleBlockTextImport
The canonical structure opens with the keyword WEB on the first line, the version number (typically 1) on the second, and the target URL on the third.
.iqy files are used to import external data into spreadsheet documents. In Windows, such files are by default associated with Microsoft Excel. A related .DQY file serves a similar role for ODBC database queries, while imported data is frequently saved as an .XLSX workbook or exported as a CSV. Because .iqy files can point Excel at arbitrary remote locations - including file:// and UNC paths - they became a notorious malware-delivery vector around 2018, exploited in phishing campaigns to download and execute malicious payloads via email attachments. Many mail filters now block .iqy attachments by default. Excel 2016 and later recommend the Power Query ("Get & Transform") connectors as a safer and more capable replacement.
Security & safety
RISK: HIGHIQY files are a recognized malware delivery vector. Opening one tells Excel to connect to the URL inside, which attackers have used to fetch remote payloads and trigger script/macro chains (notably the 2018 Marap and FlawedAmmyy malspam campaigns). Treat any .iqy that arrives by email or chat as hostile: do NOT double-click it. Inspect it first in Notepad/TextEdit - it's plain text, so you can read the destination URL. Only run .iqy files from a source you fully trust, and keep Excel's external-data and Protected View prompts enabled. Many mail gateways block .iqy attachments by default for this reason.
Format details
in a nutshellPrograms that open IQY files
Technical details
deep spec| File category | Plain-text instruction file - tells Excel which URL to fetch; contains no spreadsheet data itself |
| Opening keyword | First line is always the literal text `WEB`, identifying the query type to the application |
| Version field | Second line holds the format version number, typically `1` |
| URL field | Third line holds the target URL Excel connects to when the query is executed |
| Text encoding | ASCII / UTF-8, plain text; CRLF line endings on Windows |
| Typical file size | Under 1 KB - usually just a handful of lines |
| Binary signature | None - no magic bytes; the file is identified by the `WEB` keyword on line 1 |
| Selection parameter | Controls which content to import: `EntirePage` pulls all tables; an integer (e.g. `1`) targets a specific table on the page |
| Parameter prompts | Optional `["name","prompt"]` lines let Excel ask the user for a runtime value before executing the query |
| Refresh behavior | Excel can refresh the query automatically on file open or on a configurable interval (e.g. every 60 minutes) via worksheet connection settings |
| MIME type | `text/plain`; also registered as `application/x-ms-iqy` |
| Security risk | Can reference arbitrary `http://`, `file://`, or UNC paths; heavily exploited in phishing campaigns from 2018 onward; commonly blocked by email filters |
| Default query folder | `%ProgramFiles%\Microsoft Office\Queries\` - Excel's built-in storage location for saved web queries |
| Superseded by | Power Query ("Get & Transform") in Excel 2016+, which supports OAuth, REST APIs, and dozens of additional data-source connectors |
| Related query formats | `.dqy` (ODBC queries), `.rqy` (OLE DB queries), `.oqy` (OLAP/cube queries) |
| Released | 1990s (Microsoft Excel Web Query, since Excel 97/2000) |
| Latest version | Stable legacy format; superseded by Power Query (Get & Transform) in Excel 2016+ |
| Specification | support.microsoft.com |
IQY conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about IQY files.