Digital signature validator for signed PDFs
Check whether a signed PDF is genuinely signed, by whom, when, and to what PAdES or eIDAS level. Every certificate is validated against its issuing chain and current revocation lists.
A signature graphic is not a signature
Most 'signed' PDFs circulating in UK business carry only a pasted image of a signature — visually convincing, cryptographically worthless. A real digital signature embeds a certificate, binds it to a byte range of the document, and can prove that nothing has changed since signing.
The validator tells you which of the two you are holding, and where a real signature exists it walks the certificate chain to a trusted root, checks CRL and OCSP revocation status, and confirms whether the timestamp came from a qualified trust service provider.
eIDAS and PAdES levels explained
UK eIDAS recognises simple, advanced and qualified electronic signatures, and PAdES defines the corresponding PDF profiles (B-B, B-T, B-LT, B-LTA). The level determines how much evidential weight a signature carries years later, once certificates expire.
The report names the achieved level and explains the gap — for example, a signature with no trusted timestamp cannot reach B-T and will become unverifiable when the signing certificate lapses.
What is validated
- Signer identity and issuing certificate authority
- Full certificate chain to a trusted root
- CRL and OCSP revocation status at signing time and now
- Trusted timestamp presence and issuing authority
- PAdES profile level (B-B, B-T, B-LT, B-LTA) and eIDAS classification
- Whether any content was added after the signature was applied
Frequently asked questions
- Can it tell a real digital signature from a pasted image?
- Yes — that is the first thing it reports. A pasted graphic has no certificate and no byte-range binding, so the validator marks the document as visually signed but cryptographically unsigned.
- Does it support DocuSign, Adobe Sign and Qualified Trust Service Providers?
- Yes. Any signature embedded to the PDF standard is validated, including those applied by DocuSign, Adobe Sign, Dropbox Sign and UK/EU qualified trust service providers.
- What if the signing certificate has expired?
- An expired certificate does not invalidate a signature if a trusted timestamp proves it was valid at the moment of signing. The report distinguishes the two cases explicitly.
- What happens to the documents I upload?
- Every uploaded file is permanently deleted from DocumePro servers within 60 minutes under our Non-Persistence Guarantee. Nothing is retained for analytics, shared with third parties, or used to train AI models.
Sign a PDF · Flatten a PDF for court filing · Chain-of-custody report