Skip to main content
Orilami

How to Check Whether a Signed PDF Is Really Valid

1 min read
PDFDigital SignaturesHow-to

A PDF can show a green "signed" badge and still have been changed after signing. This guide shows how to check a signature properly, instead of trusting the badge. It's aimed at lawyers, notaries, auditors and finance teams who act on signed contracts, invoices and certificates.

Know what a signature should prove

A real signature covers a set range of bytes. If anything in that range changes, the signature should break. Two tricks fool a quick look: a signature that doesn't cover the whole file, and a "shadow attack" where the file is signed and then altered to show different content.

Open the validator

Go to the PDF Signature Validator. It runs in your browser, so a confidential document is never uploaded. Load the signed PDF.

Check what the signature covers

The tool reads the file's ByteRange and shows how much of the document the signature actually protects. If there's content outside that range, treat the file with caution.

Verify the signature and look for tampering

It checks the signature itself, reports the PAdES level, and lists later revisions and any signs of a shadow attack. Read these results carefully — this is where a quietly altered file shows up.

Decide based on the evidence

If the signature covers the whole file, verifies cleanly, and shows no suspicious revisions, you can trust the version you see. If not, go back to the signer before you act on it.

A green checkmark is a claim, not proof. Always confirm what the signature covers before relying on the document.