Free Tool

Verify a digital signature in any PDF

Upload a signed file and find out in seconds whether it was modified after signing — and who signed it, and when.

  • No account required
  • Your file is never stored
  • Full PAdES inspection

Drop a PDF here

Or click to choose a file from your device. Up to 10 MB.

Choose a file

Your file is checked in memory and discarded immediately. It is never written to storage, never linked to an account, and its contents are never logged.

What gets checked

Four checks separate a real signature from a picture of one

A signature image pasted into a PDF proves nothing — anyone can edit it. A digital signature seals a cryptographic fingerprint of the document inside the file itself. That is what we inspect.

Digest binding

We recompute SHA-256 over the bytes covered by /ByteRange and compare it to the sealed messageDigest attribute. Any byte changed after signing breaks this match.

RSA validity

We verify the signature against the public key in the embedded certificate, over the DER encoding of the signed attributes per RFC 5652 §5.4.

RFC 3161 timestamp

When a timestamp token is present, we check that its imprint equals sha256 of the signature value — the binding ETSI EN 319 122-1 requires.

ESS attribute

PAdES mandates signing-certificate-v2, which ties the signature to one specific certificate. Its absence means the seal is not PAdES-conformant.

Frequently asked questions

How do I check if a PDF signature is valid?
Upload the PDF to a verifier that recomputes the document digest and checks it against the value sealed inside the signature. If the digest matches and the RSA signature verifies against the embedded certificate, the file has not been modified since it was signed.
Does a valid signature mean the document is legally binding?
Not by itself. A cryptographically intact signature proves the file is unmodified. Legal weight also depends on signer identity evidence, consent records, and the signature tier (SES, AES, or QES) recognised in the relevant jurisdiction.
Is my document uploaded or stored anywhere?
The file is sent to our server, held in memory for the length of the check, and discarded. It is never written to storage, never added to an account, and its contents are never logged.
Does this tool check whether the certificate is trusted?
No. It verifies integrity and signature structure, not certificate chain trust. It does not check the issuer against the Adobe Approved Trust List or the EU Trusted List, and it does not check revocation. A self-signed PDF can pass the integrity check.
What is an RFC 3161 timestamp and why does it matter?
An RFC 3161 timestamp is a countersignature from an independent time-stamping authority proving the signature existed at a given moment. Without one, the only available signing time is the one the signer asserted, which proves nothing. PAdES-B-T requires a timestamp.
Can it verify signatures made in Adobe Acrobat or DocuSign?
Yes, as long as the signature follows the PAdES/CMS structure that Acrobat, DocuSign, and other standards-based platforms produce. The verifier reads the PDF ByteRange and the embedded CMS SignedData directly rather than anything SahlSign-specific.

Want documents that pass this check by default?

Every document signed through SahlSign is sealed with a PAdES-B-T seal, an RFC 3161 timestamp, and a hash-chained audit trail. Start free — no credit card needed.

Start for free