Digital signature validator for signed PDFs

Check whether a signed PDF is genuinely signed, by whom, when, and to what PAdES or eIDAS level. Every certificate is validated against its issuing chain and current revocation lists.

A signature graphic is not a signature

Most 'signed' PDFs circulating in UK business carry only a pasted image of a signature — visually convincing, cryptographically worthless. A real digital signature embeds a certificate, binds it to a byte range of the document, and can prove that nothing has changed since signing.

The validator tells you which of the two you are holding, and where a real signature exists it walks the certificate chain to a trusted root, checks CRL and OCSP revocation status, and confirms whether the timestamp came from a qualified trust service provider.

eIDAS and PAdES levels explained

UK eIDAS recognises simple, advanced and qualified electronic signatures, and PAdES defines the corresponding PDF profiles (B-B, B-T, B-LT, B-LTA). The level determines how much evidential weight a signature carries years later, once certificates expire.

The report names the achieved level and explains the gap — for example, a signature with no trusted timestamp cannot reach B-T and will become unverifiable when the signing certificate lapses.

What is validated

  • Signer identity and issuing certificate authority
  • Full certificate chain to a trusted root
  • CRL and OCSP revocation status at signing time and now
  • Trusted timestamp presence and issuing authority
  • PAdES profile level (B-B, B-T, B-LT, B-LTA) and eIDAS classification
  • Whether any content was added after the signature was applied

Frequently asked questions

Can it tell a real digital signature from a pasted image?
Yes — that is the first thing it reports. A pasted graphic has no certificate and no byte-range binding, so the validator marks the document as visually signed but cryptographically unsigned.
Does it support DocuSign, Adobe Sign and Qualified Trust Service Providers?
Yes. Any signature embedded to the PDF standard is validated, including those applied by DocuSign, Adobe Sign, Dropbox Sign and UK/EU qualified trust service providers.
What if the signing certificate has expired?
An expired certificate does not invalidate a signature if a trusted timestamp proves it was valid at the moment of signing. The report distinguishes the two cases explicitly.
What happens to the documents I upload?
Every uploaded file is permanently deleted from DocumePro servers within 60 minutes under our Non-Persistence Guarantee. Nothing is retained for analytics, shared with third parties, or used to train AI models.

Sign a PDF · Flatten a PDF for court filing · Chain-of-custody report