Security

How to spot a fake signed PDF: pasted signature images, forged certificates and other red flags

Run the file through a signature checker first: if it finds no digital signature, the signature you see is only an image and proves nothing about who signed or whether the document changed. If there is a digital signature, check three things. That it is intact, that nothing unexpected was added after it, and that the certificate was issued by an authority you would expect for that sender, not a self-signed or unknown one.

6 min read

Forging a signed PDF has never been easier. A signature can be copied off an old email, a letterhead can be lifted from a website, and a figure can be retyped in any editor. Payment-redirect fraud, fake job offers, forged bank letters and doctored certificates very often arrive as PDFs that look signed.

The good news: a real digital signature is very hard to fake convincingly, and the common forgeries fall into a handful of patterns you can check for in a couple of minutes.

The short answer

  1. Is there a digital signature at all? If not, the signature you see is a picture. Pictures can be pasted onto anything.
  2. If there is one, is it intact? An invalid signature means the document changed after signing.
  3. Was anything added after signing? A valid signature with a new text box on top is a classic trick.
  4. Who issued the certificate? Anyone can create a certificate with any name in it. The issuer is what gives the name meaning.

Pattern 1: the pasted signature image

By far the most common "forgery" is simply a picture of a signature. Copied from a genuine document and placed on a new one. It looks perfect because it is a real signature; it just belongs to a different document.

How to check: upload the file to Verify PDF Signature. If it says No digital signature found in this file, the visible signature is an image. The checker also looks for things that resemble signatures. Pictures shaped like a signature, hand-drawn marks, stamps, and signature fields that were prepared but never signed, and tells you which page they are on.

What it means: not necessarily fraud. Most honest documents are signed this way too. But it means the signature cannot vouch for the content. For anything involving money or identity, confirm through another channel.

Visual clues that often accompany a pasted image (none is proof on its own):

  • The signature sits perfectly on top of printed text with no ink bleed or pressure variation, on a document that claims to be a scan.
  • The same signature appears pixel-identical on documents supposedly signed on different days. Real handwriting always varies.
  • The signature has a white rectangle around it that hides part of a line or stamp.
  • Zooming in shows the signature is sharper or blurrier than everything around it.

Pattern 2: a genuine signature on an altered document

Someone takes a genuinely digitally signed PDF and adds something afterwards: a new bank account number in a text box, a changed figure drawn over the old one, an extra page. Because PDFs allow content to be appended after signing, the original signature can still report as valid.

How to check: in Verify PDF Signature, look for Signed by [name], but the file was changed after signing or the warning that the file has been changed after its last signature. The list below tells you what. "Page 1: a text box was added", "Page 2: the page content was changed". Use Compare the changed pages to see the page as signed next to the page now, and Download the version that was signed to get the real one.

This single check defeats a very common invoice fraud: a legitimate signed invoice with the payment details changed in an overlay.

Pattern 3: a signature that no longer matches

If someone edited the signed content directly, the signature breaks: This signature is broken. The document was changed or the signature is damaged, with Signature: Invalid. A careless forger might send it anyway, betting nobody checks.

Occasionally a signature breaks innocently (a program "repaired" the file) so ask for a fresh copy from the sender directly. If it is still broken, do not rely on it.

Pattern 4: a real digital signature from a meaningless certificate

This is the subtle one. Anyone can create a certificate with the name "Deutsche Bank" or "Ministry of Finance" in it, in a minute, for free. The signature made with it will be mathematically valid. What it cannot have is a trustworthy issuer.

How to check: open Certificate details in the result and look at:

  • Issued by: who vouches for this identity. A certificate that is self-signed (issued by itself) is described as such: "no one else vouches for who it belongs to."
  • Certificate chain: the line from the signer up to a root. "Incomplete: the certificates in the file do not reach a root certificate" is a reason for caution.
  • Trust: whether the chain ends at a root this service recognises. Not trusted is common and often legitimate (company certificates, some national authorities), so treat it as a question, not a verdict.
  • Organisation and Country: do they fit the sender?

Then compare with what you would expect. A letter from a government ministry should be signed with a certificate from that government's official authority. A multinational bank will typically use a well-known commercial authority. A "bank" letter signed by a self-signed certificate is a serious red flag.

The strongest check of all: ask the genuine organisation, through contact details you found independently, for the SHA-256 fingerprint of the certificate they sign with, and compare it to the one shown in Certificate details. A match is very hard to fake.

Pattern 5: a revoked certificate

If a signing key is stolen, the issuer revokes the certificate. Signatures made with it afterwards will show Revocation: Revoked and the verdict Signed by [name], but the certificate used has been revoked. Treat these as untrustworthy unless a trusted timestamp proves the signature was made before the revocation, and even then, ask.

Other red flags that have nothing to do with signatures

A signature check is one tool, not the whole investigation. Also consider:

  • Payment details that changed from previous invoices. Always confirm by phone, using a number you already had.
  • Urgency and secrecy: "pay today", "don't discuss with finance".
  • Email address mismatches: a lookalike domain one letter off.
  • Document properties: a document that claims to come from a bank's system but was produced by a consumer editing app is worth a question.
  • Verification codes that don't verify: many official documents carry a QR code or reference number checked on the issuer's own site. Scan it, but check the address it opens is really the issuer's.

What to do if you think a PDF is forged

  1. Don't act on it: no payments, no data.
  2. Keep the original file exactly as received, and the email it came in.
  3. Save a report with Download report (PDF). It records every check and the file's SHA-256 fingerprint.
  4. Contact the supposed sender through a channel you found yourself, not one in the document.
  5. Report it to your bank, your organisation's security team or the relevant authority if money or identity is involved.

Common questions

How can I tell if a signature on a PDF is just a pasted image?

Upload it to a signature checker. If it reports no digital signature, what you see is an image: drawn, typed, scanned or pasted. Verify PDF Signature also points out the page where it found something that looks like a signature image, drawing or stamp.

Can a digital signature be faked?

The maths cannot practically be faked, but the name can: anyone can create a certificate with any name. That is why the issuer matters. A self-signed certificate, or one from an authority you would not expect, does not prove identity.

Can someone add text to a signed PDF without breaking the signature?

They can append a text box, drawing or page after the signature without breaking it, because PDF allows later additions. A good checker lists those additions separately and shows the page as signed next to the page now.

The signature is valid and trusted. Is the document definitely genuine?

It proves the signed content is unchanged and that a recognised authority issued the signer's certificate. Still check that nothing was added after signing, that the signer is the person or organisation you expect, and (for payments) confirm details by phone.

How do I prove a certificate really belongs to an organisation?

Ask the organisation, using contact details you found independently, for the SHA-256 fingerprint of their signing certificate and compare it with the one in the certificate details. A match is strong evidence.

Is a PDF without a digital signature fake?

No. Most genuine documents are signed with a picture or a scanned signature. It just means the signature cannot prove anything about the content, so confirm important details another way.