Security

How to read a signature check result: intact, who signed, and trusted

A signature check answers three separate questions: has the document changed, who does the certificate say signed it, and does anyone independent vouch for that certificate. A good result on one does not imply a good result on the others.

5 min read

Verify PDF Signature never gives you one big green tick. It gives a sentence and then a list of rows. That is deliberate, and this page explains how to read them.

Why not one tick?

Because "the maths checked out" and "this person is who they claim" are not the same fact, and a tool that merges them will eventually tell somebody a forged document is trustworthy.

Here is a real and very common situation: a large company issues certificates to its own staff. A contract signed by one of them is perfectly intact and genuinely from that employee. But the company's in-house authority is not on any public trust list, so no outsider's software recognises it. One tick would have to be green or red, and both would be misleading.

The headline sentence

At the top you get one plain sentence, which is about the document, never about trust. It is one of:

  • "Unchanged since [name] signed it on [date]." The best outcome. Nothing has been altered.
  • "Unchanged since [name] signed it. Only permitted additions were made afterwards." Things were added, but only things the signature allowed. A later signature, or form filling the signer permitted. What was signed is intact.
  • "Signed by [name], but the file was changed after signing." Something was altered that the signature did not allow. Read the list of changes below it.
  • "Signed by [name], but the certificate used has been revoked." The signature is intact, but the certificate was cancelled.
  • "This signature is broken." The signed content does not match the signature.

Underneath it, a second sentence deals with trust: who issued the signer's certificate and whether anyone recognises them. Two sentences, because two questions.

The rows, one by one

Signature: Valid / Invalid. The most important line. *Valid* means the signed part of the document has not changed since it was signed. *Invalid* means it has, or the signature is damaged.

Certificate: Valid / Invalid. Was the signer's digital ID in date and meant for signing at the time?

Revocation: Not revoked / Revoked / Not checked. Was the certificate cancelled early? *Not checked* is an honest answer, not a failure: some certificates name no cancellation service, or it could not be reached. See what revocation checking means.

Certificate chain: Valid / Invalid. Does the line of certificates above the signer hold together? See what a certificate chain and a root are.

Trust: Trusted / Not trusted / Unknown. Does an independent list recognise the issuer? "Not trusted" does not mean fake. It means nobody on our lists vouches for that issuer. Routine for company certificates and always true for self-signed ones.

Adobe trust list (AATL). Whether Adobe Acrobat and Reader will trust this certificate out of the box. See what Adobe's AATL is.

Timestamp: Valid / Invalid / None. Whether an independent service recorded when it was signed.

Long-term validation: Present / Not included. Whether the file carries its own evidence for later checking.

How to actually decide

Ask yourself in this order:

  1. Is the Signature row Valid? If no, stop. Whatever else is true, this is not the document that was signed. Do not act on it.
  2. Do I know who this should be from? Look at the certificate details: name, organisation, issuer. If you were expecting a document from a bank and the certificate belongs to a private individual, that matters far more than any row.
  3. Do I need proof of identity, or proof of integrity? If a colleague sends a signed report and you just need to know it was not edited, *valid, not trusted* is fine. If a stranger sends a contract and you are relying on who they are, *not trusted* is a real gap.

Things you should look at as well

"Changed after this signature." When something was altered, the result lists exactly what: a page added, a comment added, a form field changed, a later signature. You can even "Compare the changed pages" side by side, as signed and as now.

"Download the version that was signed." This pulls the exact file the signer signed, before any later change, straight out of the file you already have. It is the single most useful button when there is a dispute.

"Also in this file." Notices about drawings, images, stamps or empty signature fields that look like a signature but are not one. See why a picture of a signature is not a signature.

If you want to trust a certificate yourself

Sometimes you know perfectly well who an issuer is. Your own employer, a partner organisation. You can add their root certificate with "Trust your own certificate" and check again. The result then says "Trusted because you added it", so the report never quietly upgrades itself into looking like public trust.

Saving the answer

Two downloads are offered: a readable PDF report of everything shown, and a machine-readable ETSI report (XML) for systems that process validation results. Both say the same thing in different languages.

Common questions

What does 'signature valid but not trusted' mean?

It means the document has not changed since it was signed, but the certificate's issuer is not on a public trust list. This is normal for certificates a company issues to its own staff, and always the case for self-signed IDs.

Which line matters most in a signature check?

The Signature row. If it is not Valid, the file is not what was signed, and nothing else in the report rescues that.

The result says changes were made after signing. Is the document useless?

Not necessarily. Some additions are permitted by the signature itself, such as a later signature or allowed form filling; those are listed separately. Anything else is listed under 'Changed after this signature', with a page-by-page comparison.

What does 'Revocation: not checked' mean?

The certificate does not name a cancellation service, or that service could not be reached. It is an honest 'we do not know', not a sign of a problem.

Can I see the exact file that was signed?

Yes. The result offers 'Download the version that was signed', which extracts the signed version from the file you uploaded, before any later changes.

Can I get the result as a document?

Yes. You can download a readable PDF report, or an ETSI XML report for systems that process validation results automatically.