Loading date…
LinkedIn Twitter Instagram YouTube WhatsApp
Malwarebytes - Cybersecurity for Everyone

Linux mkfs Command Cheat Sheet: Format Disks Safely (2026)

Terminal showing the Linux mkfs command formatting a disk partition as ext4 with lsblk output

Linux mkfs Command Cheat Sheet: Create ext4, XFS, Btrfs, FAT32 and NTFS Filesystems Safely

Last verified: October 7, 2026

Picture a Friday evening change window. An admin is asked to prepare a fresh data disk for a new application server. Two disks look similar, and the device names shifted after a reboot. What was /dev/sdb1 yesterday is /dev/sdc1 today. One mkfs command later, a partition that held production backups is empty. Nothing was hacked, yet the outcome is the same as a destructive attack.

That is why mkfs deserves more respect than most cheat sheets give it. In this guide you'll get every common mkfs command for ext4, XFS, Btrfs, FAT32 and NTFS, plus the verification habits SOC teams and sysadmins use to avoid wiping the wrong device. We'll also cover why formatting is not secure data sanitization, which matters for enterprise data protection and disaster recovery planning.

Table of Contents

What mkfs Actually Does

mkfs is a front end that calls a filesystem-specific tool such as mkfs.ext4, mkfs.xfs or mkfs.btrfs. It writes new filesystem metadata (superblock, inode tables, journal and so on) to a block device. It does not normally overwrite every sector, so creating a filesystem is generally much faster than wiping a drive. Exact behavior depends on the tool and options, so don't assume every mkfs run is a guaranteed "quick format."

To see which filesystem creation tools exist on your system and review general usage:

ls /sbin/mkfs.*
mkfs --help

The first command lists installed filesystem-specific utilities. The second prints general usage. Output varies by distribution and installed packages (for example, NTFS and FAT tools come from separate packages on many systems).

Pre-Format Safety Checks

Warning: Every command in the sections below that runs mkfs is destructive. It makes existing data on the target partition inaccessible. Always double-check the device name.

Start by identifying what is on each device:

lsblk -f

This shows filesystem type, label, UUID and mount point for each device. For a cleaner view focused on identification:

lsblk -o NAME,SIZE,TYPE,FSTYPE,MOUNTPOINTS

Compare size and filesystem type against what you expect. A 4 TB disk is not the 32 GB USB stick you meant to format. To inspect a specific partition:

sudo blkid /dev/sda1

This displays the existing filesystem type and UUID. If it already reports a filesystem you didn't expect, stop and investigate.

Next, check whether the partition is mounted:

findmnt /dev/sda1

No output generally means it is not mounted. If it is mounted, unmount it first:

sudo umount /dev/sda1

Formatting a mounted filesystem is a classic way to corrupt a running system, and mkfs will normally refuse without a force option.

Creating ext4, ext3 and ext2 Filesystems

ext4 remains the default choice on many Linux distributions for general-purpose storage.

sudo mkfs.ext4 /dev/sda1

This formats /dev/sda1 as ext4 and prints progress, including inode and journal creation. Legacy systems or specific compatibility needs may call for the older variants:

sudo mkfs.ext3 /dev/sda1
sudo mkfs.ext2 /dev/sda1

ext3 adds journaling to ext2, and ext4 builds on ext3 with larger limits and performance features. For new deployments, ext4 is generally the practical pick.

Useful ext4 Options

sudo mkfs.ext4 -v /dev/sda1

Verbose mode prints more detail while the filesystem is created, which helps when documenting a change.

sudo mkfs.ext4 -m 1 /dev/sda1

Reserves 1% of blocks for privileged processes instead of the default 5%. On large data-only volumes this recovers usable space. Keep a higher reserve on volumes that hold system files.

sudo mkfs.ext4 -b 4096 /dev/sda1

Sets a 4096-byte block size, which is common and well supported.

sudo mkfs.ext4 -I 256 /dev/sda1

Sets the inode size to 256 bytes.

sudo mkfs.ext4 -F /dev/sda1

Forces creation when mkfs detects a condition that normally requires confirmation. Use this carefully. It bypasses a safety net that exists to protect you.

Creating XFS and Btrfs Filesystems

XFS is widely used on enterprise Linux servers for large files and parallel workloads. Btrfs offers snapshots and checksumming for teams that want those features.

sudo mkfs.xfs /dev/sdd1
sudo mkfs.btrfs /dev/sde1

Each command formats the named partition with the respective filesystem. If the device already contains a recognizable filesystem, mkfs.xfs and mkfs.btrfs typically refuse to proceed unless you add their force option (-f for both). Treat that refusal as a useful warning, not an obstacle.

Creating FAT32, FAT16 and NTFS Filesystems

Removable media often needs a filesystem that Windows, macOS and Linux can all read.

sudo mkfs.vfat -F 32 /dev/sdb1
sudo mkfs.vfat -F 16 /dev/sdb1

The first creates FAT32, which suits many USB drives. The second creates FAT16, which has much smaller size limits and is mostly relevant for legacy hardware. FAT32 also caps individual file size at 4 GB, which surprises people moving large disk images.

sudo mkfs.ntfs /dev/sdc1
sudo mkfs.ntfs -Q /dev/sdc1

The second command uses the quick-format option, which skips zeroing the whole partition. NTFS creation on Linux relies on the ntfs-3g tooling, which you may need to install separately.

Labels and UUIDs

Labels and UUIDs make devices easier to identify, and they are safer in /etc/fstab than device names that can change between boots.

sudo mkfs.ext4 -L DATA /dev/sda1
sudo mkfs.xfs -L MyData /dev/sdd1
sudo mkfs.btrfs -L DATA /dev/sde1
sudo mkfs.vfat -n MYUSB /dev/sdb1

Note the different flags: ext4, XFS and Btrfs use -L, while mkfs.vfat uses -n. Length limits also differ. FAT labels are limited to 11 characters and XFS labels to 12, so keep labels short.

sudo mkfs.ext4 -U random /dev/sda1
sudo mkfs.ext4 -U 12345678-1234-1234-1234-123456789abc /dev/sda1

The first generates a random UUID for ext4. The second sets a specific one, which is useful when rebuilding a volume that other configuration already references. UUIDs must be unique on a system. For Btrfs, supply an explicit UUID, for example one generated with uuidgen:

sudo mkfs.btrfs -U "$(uuidgen)" /dev/sde1

Verify and Mount After Formatting

Never assume a format succeeded. Chain a verification step right after creation:

sudo mkfs.ext4 /dev/sda1; sudo blkid /dev/sda1
sudo mkfs.ext4 /dev/sda1; lsblk -f

Because of the semicolon, the second command runs even if mkfs fails, so read the mkfs output before trusting the verification. Then mount and check capacity:

sudo mount /dev/sda1 /mnt
df -h /mnt

You should see the new filesystem mounted at /mnt with nearly all space available (some is consumed by metadata and reserved blocks).

Formatting Is Not Secure Data Sanitization

This is the point many cheat sheets skip. Creating a new filesystem generally does not erase old file contents. Depending on the filesystem and options, much of the previous data can remain on disk and may be recoverable with forensic tools. In practice, that means:

  • Decommissioning drives: Reformatting a disk before resale or return is not sufficient for sensitive data. NIST SP 800-88 describes media sanitization approaches (clear, purge, destroy) that organizations use for this purpose.
  • Incident response: A responder who reformats a suspect disk can destroy evidence and metadata that investigators need. Image first, then rebuild.
  • Compliance: Regulated environments such as healthcare and finance often have documented media-handling requirements. Check your own policies rather than relying on a quick format.

For drives that held sensitive data, use a sanitization method appropriate to the media type (HDD, SSD or NVMe) and your organization's policy, and document it.

Which Filesystem Should You Choose?

FilesystemTypical useCommand
ext4General Linux data and system partitionsmkfs.ext4
XFSServer data volumes, large filesmkfs.xfs
BtrfsSnapshots and checksumming needsmkfs.btrfs
FAT32Cross-platform removable mediamkfs.vfat -F 32
NTFSWindows-oriented drivesmkfs.ntfs

Expert Tips

  • Run lsblk -f twice. Once before you type the command, once right before you press Enter. Device names can change after reboots or when USB devices are added.
  • Prefer labels or UUIDs in fstab. This reduces the chance of mounting or formatting the wrong disk after hardware changes.
  • Treat -F as a last resort. If mkfs asks for confirmation, find out why before forcing it.
  • Log your changes. Record the device, size, filesystem and time in your change ticket. This helps audits and disaster recovery reviews.
  • Test on a spare device first. A loop device or a cheap USB stick is a safe place to practice the options.
  • Back up before you format. Verify the backup restores. An untested backup is a hope, not a plan.

FAQ

Does mkfs erase all data on a partition?

It makes the old filesystem inaccessible by writing new metadata, but it generally does not overwrite every sector. Old data may remain recoverable, so it is not a substitute for secure sanitization.

What is the difference between mkfs and mkfs.ext4?

mkfs is a wrapper that calls the filesystem-specific tool. Running mkfs.ext4 directly is clearer and avoids relying on defaults.

Can I format a mounted partition?

You should not. Unmount it first with umount. Tools like mkfs.ext4 will usually refuse unless forced, and forcing it risks corruption.

How do I check the filesystem type before formatting?

Use lsblk -f or sudo blkid /dev/sda1. Both show the current filesystem type and UUID.

Why use FAT32 for USB drives?

It is readable on most operating systems. The tradeoff is the 4 GB per-file limit.

How do I set a label when formatting?

Use -L for ext4, XFS and Btrfs, and -n for mkfs.vfat. Mind the length limits for each filesystem.

Is mkfs.ntfs -Q the same as a full format?

No. The -Q option performs a quick format and skips zeroing the partition, which is faster but does not wipe old data.

Conclusion

The mkfs command is simple, and that is exactly what makes it risky. The workflow that keeps teams safe is consistent: identify the device with lsblk -f, confirm it is unmounted, run the correct filesystem-specific command, then verify with blkid and a test mount. Add the sanitization caveat for drives that held sensitive data and you will avoid both accidental data loss and false confidence about erased disks. Bookmark this cheat sheet and keep it next to your change checklist.

Analysis based on SOC monitoring and public threat intelligence review.

Shubham Chaudhary

Shubham Chaudhary is a cybersecurity specialist and founder of Xpert4Cyber. He shares practical tutorials, guides and the latest news on Networking, Windows Server, Linux Server, Ethical Hacking, Digital Forensics, Malware Analysis, Threat Hunting and Monitoring, OSINT, Cloud Computing and AI, with a focus on defense and security awareness. Educational and defensive use only.

Post a Comment

Previous Post Next Post