Is That Signed PDF Actually Valid? How to Tell
A digital signature on a PDF is meant to prove two things: who signed it, and that nothing changed after they did. The problem is that a file can look signed — even show a green checkmark — while the content you see is not the content that was signed.
How a PDF signature works
When someone signs a PDF, the signature covers a specific range of bytes. If even one byte in that range changes, the signature should break. This is what makes a signature meaningful: it ties the signer to an exact version of the file.
Where it goes wrong
Two things can fool a quick glance:
- Partial coverage — if the signature does not cover the whole file, text or images can be added in the uncovered part while the checkmark stays green.
- Shadow attacks — a file is signed, then changed so it shows different content without breaking the signature. The viewer still says "signed".
A normal PDF reader often won't warn you about these. It just shows the badge.
Check the signature properly
Orilami's PDF Signature Validator checks a signed PDF byte by byte. It confirms what the signature actually covers, verifies the signature itself, checks the PAdES level, and looks for added revisions and shadow attacks. It runs fully in your browser, so a confidential contract is never uploaded.
Who needs this
This matters in work built on signed documents: lawyers, notaries, auditors, banks and procurement teams. A contract, invoice or certificate that was quietly altered after signing can cost money or hold up in the wrong way — so checking the signature, not just the badge, is part of due diligence.
A green checkmark is a claim, not proof. Check what the signature really covers before you trust it.
