Verifier · browser-only
Check whether a signed PDF is genuine.
Drop any signed PDF below — FreeSign, DocuSign, Adobe Sign, or anything else. We'll tell you who signed it, whether it has been changed since, and when it was signed. The file never leaves your browser. Need to sign one instead? Use FreeSign's free e-signature — same privacy property.
Works on PDFs signed by any standard provider, not just FreeSign — a browser-only PAdES validator that checks the signature, chain and timestamps of PAdES-B-B / B-T documents (it reads B-LT files too; long-term-validation policy checks are out of scope — see the technical details below). Adobe Reader's green/yellow icon is a separate question about local trust settings — we explain that in the result panel.
No signed PDF on hand? Try a sample: sealed-good.pdf (drop it back here — expect 4 green ✓)
Signature details
- Signer name
- —
- Signer email
- —
- Signing time
- —
- Document SHA-256
- —
- CMS profile
- —
- Signature algorithm
- —
- Issuer
- —
The signature matches the document cryptographic signature · CMS PKCS#7 / RFC 5652
Pending…
Details
The signer's identity certificate checks out certificate chain · X.509 leaf → CA
Pending…
Details
The signing time is provable trusted timestamp · RFC 3161
Pending…
Details
Independent public timestamp on the Bitcoin ledger OpenTimestamps Bitcoin anchors · FreeSign bonus
Pending…
Details
A FreeSign seal carries two such anchors, and this one verdict covers both: one over the signed document (1.3.6.1.4.1.65834.1.1), one over the signed attributes themselves (….1.5) — the second is what dates the post-quantum key commitment below. Other vendors' signatures carry neither, which is informational, not a fault.
The signing-ceremony evidence is embedded and intact FreeSign evidence record · CMS signedAttribute 1.3.6.1.4.1.65834.1.2
Pending…
Details
The evidence record is a signed CMS attribute — editing it invalidates the signature above, and a record found only in the unsigned set is rejected here. Its integrity is also self-contained: it carries a signed canonical payload and the browser's public key, so this check re-verifies that signature independently.
The signature also holds against a quantum computer post-quantum co-signature · ML-DSA / FIPS 204 · FreeSign bonus
Pending…
Details
A second signature over the same signed attributes, made with ML-DSA (the NIST post-quantum standard, formerly CRYSTALS-Dilithium). The classical signature above is what today's PDF readers check; this one is insurance. Its public key is committed to inside the signed attributes, so today's signature is what binds that key to the signer — and the timestamps above are what prove the binding was made before any quantum computer existed. Most PDFs don't carry one; that is not a defect. How the post-quantum co-signature works →
Will Adobe Reader show a green check? Adobe Reader AATL trust-list membership
Drop a PDF above and this tile will report on the specific signer.
Audit trail
FreeSign keeps an append-only, hash-chained audit log for every envelope — each event commits to the one before it. This check fetches that chain and re-computes every link in your browser; it does not trust FreeSign's own verdict. Unlike the signature checks above, this one needs the FreeSign service to be online — the audit log lives in FreeSign's database, not inside the PDF.
What a green chain verdict means — and what it doesn't. A valid chain proves the log is internally consistent and untouched by anyone without write access to FreeSign's database. The chain is not signed and not anchored outside that database, so it does not, on its own, prove the timeline against the FreeSign operator. The document's authoritative tamper-evidence does not rely on this chain: it comes from the CMS signature, the RFC 3161 timestamp, and the OpenTimestamps/Bitcoin anchor verified above.
Sign a PDF without uploading it
The verifier on this page is the read-only counterpart of FreeSign's signing flow — both run entirely in your browser, both never see your PDF.
Sign a PDF now →