Guides

How to verify a digital signature on a PDF

Inspect signature integrity, revision coverage, certificate trust and timestamps. Learn to read an intact-but-untrusted result using a real synthetic example.

To verify a digital signature on a PDF, inspect the signature’s integrity, the document revision it covers, its certificate trust and any timestamp. A signature that looks correct on the page does not answer those questions. Keep the received file unchanged and read the detailed findings before treating a single “valid” label as a complete result.

First, check which kind of signature you have

A certificate-based digital signature carries information that a verifier can inspect. A name typed into a form, a drawn mark or a scanned signature image is visible page content; its appearance alone does not provide that certificate evidence. Adobe’s certificate-signature overview explains the role of digital IDs in signing and validating PDFs.

If your task is to add a visible mark, see our guides to drawing a signature and placing a typed signature. If you received a certificate-signed document, continue with verification.

Read these checks separately

  • Integrity: Does the signature check succeed for the content it signed? This is a check on signed content, not a conclusion about every later document revision.
  • Coverage: Which version or portion of the PDF does the signature cover? Read this finding alongside integrity, especially when the file contains multiple signatures.
  • Certificate trust: Does the verifier trust the certificate’s chain? A successful integrity check does not automatically establish that trust.
  • Timestamp: Is a timestamp present, and was it validated? A time from the signer’s computer and a verified timestamp-server result are different findings.
  • Revocation: Was certificate revocation checked, and what did the check establish? An “unknown” result leaves that question unresolved.

Adobe’s signature-validation instructions show where to inspect certificate properties and distinguish timestamp results in Acrobat. If you use Acrobat, open the Signatures panel, choose its validation command and review each signature’s properties rather than relying on the visible mark.

How to inspect a PDF with AlphaPDF

  1. Keep the original. Save the file you received separately so you can associate the findings with that exact document.
  2. Open Verify PDF signature. Review the current input limits and access requirements. This is a Premium tool: an account and paid access are required, as shown on the tool page and pricing page.
  3. Upload the PDF and run verification. Follow the tool’s upload, options and retention steps. Its stated output is a report about the signatures in the file.
  4. Read every signature’s findings. Check integrity, coverage, certificate trust, timestamp and any warnings. Do not stop after the first successful check.
  5. Save the report with the received PDF. Record unresolved findings explicitly. If your team requires a particular verification process, pass those findings to the person responsible for that process.

Worked example: intact does not mean trusted

The tool page links a public synthetic example report. It contains one signature from “AlphaPDF Test Signer.” These are the actual example findings, not results from a customer document or a prediction about your file.

  • Integrity: true. The integrity finding passed.
  • Cryptographic check: true. The cryptographic check passed.
  • Certificate trust: false. The verifier did not establish certificate trust.
  • Full revision coverage: false. The report does not establish full revision coverage.
  • Timestamp present: false. No timestamp is reported.
  • Revocation status: unknown. Revocation remains unresolved.

The same example sets network_revocation_checks to false. Do not describe it as an online revocation check. The tool page identifies the example certificate as self-signed.

A useful handoff would read: “One signature; integrity and cryptographic checks passed. Certificate trust was not established, full revision coverage was not established, no timestamp was reported and revocation status was unknown.” Calling the same report simply “verified” would hide information the next reader needs. The coverage flag alone also does not explain why coverage was not established; avoid inventing a cause.

What to do with an unresolved result

Keep the warning and the original file together. Ask the sender or the person who manages your signing process for the expected certificate, document version or verification method. Do not change trust settings merely to make a warning disappear. A technical verification report does not decide whether a document meets a recipient’s acceptance requirements.

Open AlphaPDF’s Verify PDF signature tool to review the live workflow and its downloadable example before inspecting your own file.

Comments

Comments are reviewed before appearing here. Your email is never displayed.

No approved comments yet.

Join the conversation

ALPHAPDF PRO

Explore paid tools

AlphaPDF Pro: $99/year · $12/month

An account and payment are required for PDF-to-JPG, all other converters and Premium tools. No free Premium jobs.

Compare free and paid access

Plan purchasing is not available here yet. Review supported inputs and limits before choosing a tool.

View pricing

Privacy choices

The device allowance is essential and cannot be disabled without deleting your AlphaPDF data. Optional uses are controlled separately.

Are you sure?