How do you check whether a document was really signed digitally?

Updated

Short answer

You don't check a digital signing by the picture of the signature, but by the evidence that comes with it: the audit certificate and the document hash. If a document was signed with BuiltSign, drop the PDF on builtsign.com/verify. If the hash matches, it is exactly the signed document, and you see who signed, when and how that person was verified.

A signature image proves little

A drawn scribble or a scanned signature is an image. Anyone can copy it and put it under another document. What makes a digital signing strong is the recorded process around it: who received the link, how that person was verified, when they signed and whether the document changed afterwards.

That evidence is in an audit certificate: a separate document the signing platform creates for every signing.

What should the evidence contain?

A useful audit certificate records at least:

  • Who signed: name and email address, and how that person was verified (for example an SMS code or an ID check).
  • When: times in UTC for opening the link, signing and completion.
  • From where: IP address, approximate location and device.
  • Which document: a SHA-256 hash, a digital fingerprint. If a single character changes after signing, the hash no longer matches.
  • An independent timestamp (RFC 3161) from a third party, so the time doesn't rest on the platform's word alone.

How to check a document signed with BuiltSign

  1. Go to builtsign.com/verify. No account needed.
  2. Drop the signed PDF in the box. The check compares the hash of your file with the hash recorded at signing.
  3. No PDF at hand? Enter the certificate ID instead. You'll find it in the confirmation email after signing and on the certificate.
  4. On a match you see the document, the signers, when it was completed, the document integrity and the independent timestamp.

What does "no match" mean?

No match means this file is not exactly the file that was signed with BuiltSign. Either the document was never signed with BuiltSign, or it was changed after signing. Note: saving it again or using "print to PDF" also creates a different file, even if the text looks the same. In that case, ask for the original file or check with the certificate ID.

Reading the audit certificate

Look at a sample certificate with fictitious data. Per signer it shows which checks were done (email, SMS code, ID check), a timeline of every step, the filled-in fields with their time, and the document hash with timestamp.

Pay attention to the verification. A signer who only received a link by email is less strongly identified than someone who also entered an SMS code or did an ID check with selfie.

Checking a PDF with a certificate signature in Adobe Acrobat

Some PDFs contain a signature based on a digital certificate. Open the file in Adobe Acrobat Reader and look at the signature panel. Acrobat shows whether the document was changed after signing and whether the certificate is on the list Adobe trusts.

A yellow or missing check mark doesn't automatically mean the signing is invalid. It often only means Acrobat doesn't know the certificate's issuer. In that case, check the evidence of the platform that was used to sign.

Is that evidence strong enough?

Under the eIDAS regulation an electronic signature may not be denied legal effect or admissibility as evidence solely because it is electronic. How much weight the evidence carries depends on how well the signer was verified and how completely the process was recorded. For many contracts, quotes and employment agreements a simple electronic signature with a good audit certificate is appropriate, unless the law prescribes a specific form. Notarial deeds go through a civil-law notary. Read more on legal validity of electronic signatures.

Frequently asked questions

The picture of a signature is easy to copy. The recorded process is not: the document hash, the times and the independent timestamp make any later change visible.
No. The check at builtsign.com/verify is public. Anyone with the signed PDF or the certificate ID can run it.
The check compares the file, not how it looks. Saving again, editing or printing to PDF creates a new file with a different hash. Use the original file or the certificate ID.
A 64-character fingerprint calculated from the contents of a file. The same file always gives the same hash. Change one character and the hash is completely different.

Read also

Ready to get started?

Create a free account in seconds. Try everything free for 7 days, no credit card needed.

Uploads up to 1 GBBank-grade securityRecognised under eIDAS

By clicking Start free you agree to the terms and conditions and the privacy policy. If you do not finish your registration, we will send you a single reminder.