Skip to content

Security · 7 min read · Updated 2026-09-19

Digital vs electronic signature

One is an image placed on a page. The other is a cryptographic proof that the bytes have not changed since signing. The words sound interchangeable and the guarantees are not.

The two terms are used as synonyms constantly, including by software that ought to know better, and the confusion has practical consequences. One of them is a visual gesture with no technical guarantee attached; the other is a cryptographic construction that can detect any subsequent alteration of the document. Knowing which one you have — and which one a counterparty has sent you — is the whole point.

Digital vs electronic signature

01

An electronic signature is a picture

In the ordinary sense the term is used in PDF tools, an electronic signature is an image or a drawn mark placed on the page: a photographed wet signature, a scribble made with a trackpad or stylus, or a name typed in a script typeface. Technically it is an annotation or an image drawn into the page content, no different in kind from a logo. The document now depicts a signature.

What it does not do is bind anything. There is no cryptography involved, so nothing in the file records who placed the mark, when, or what the document contained at that moment. If the text above the signature is edited afterwards, the mark sits there unchanged and unbothered, because it has no relationship to the content it appears to endorse. Nothing can detect the edit from the signature alone.

It is also trivially transferable. A signature image can be extracted from one PDF and placed on a completely different one in seconds, with no technical trace of the move. That is not a flaw in any particular tool; it follows inevitably from the mark being pixels on a page. None of which makes electronic signatures useless — for internal approvals, routine acknowledgements and low-stakes paperwork they are convenient and widely accepted. It simply means the assurance they provide is social and procedural, not technical.

02

A digital signature is a cryptographic proof

A digital signature works on the bytes rather than the appearance. The signing software computes a cryptographic hash of the document — a fixed-length value that changes unrecognisably if any byte changes — and encrypts that hash with the signer’s private key. The result, together with the certificate containing the corresponding public key, is embedded in the PDF as a signature object. A visible appearance may be drawn alongside it, but the appearance is decoration; the signature is the cryptographic data.

Verification reverses the process. The reader recomputes the hash over the signed byte range, decrypts the stored hash using the public key from the certificate, and compares. If they match, the signed bytes are exactly as they were at signing and the holder of that private key produced the signature. If anything in the covered range was altered — a figure, a date, a single character — the hashes differ and verification fails visibly. Tamper evidence is not an added feature here; it is a mathematical consequence of how the construction works.

The certificate is what connects the key to an identity. It is issued by a certificate authority that performed some level of identity checking, and it chains up to a root the verifier trusts. This is the part people skip and should not: a signature can be cryptographically perfect and still tell you nothing useful if the certificate is self-issued, unchained to any trusted root, or expired. A verification panel reporting "signed, but the signer’s identity could not be verified" is telling you precisely that the maths held and the identity claim did not. Signatures can also carry a timestamp from a trusted timestamping authority, which asserts independently when the signing happened rather than relying on the signer’s own clock.

03

PAdES and validating years later

A signature that verifies today may be hard to verify in a decade, and not because the cryptography weakened. Certificates expire. Revocation information — the lists and responses that record whether a certificate was withdrawn — is published at the time and may not be available later. Verifying an old signature therefore requires evidence about the state of the world at the moment of signing, and that evidence is not automatically part of the file.

PAdES, the PDF Advanced Electronic Signatures family of profiles standardised under ETSI, exists to address this. It specifies how signatures are embedded in PDF and defines levels that progressively add the material needed for long-term validation: the certificate chain, revocation data gathered at signing time, and trusted timestamps, with provision for adding further timestamps later so the evidence remains checkable as algorithms age. The intent is that a verifier in the distant future can establish that the signature was valid when made, without needing to contact services that may no longer exist.

This matters for anything with a long life — contracts, records retained for statutory periods, archival documents. If a signed PDF must still be verifiable long after signing, the question to ask is not simply whether it is digitally signed but whether it carries long-term validation material and a trusted timestamp. Inspecting a file’s signature objects tells you what is actually there rather than what was intended.

04

Legal acceptance is a separate question entirely

It is tempting to conclude that digital signatures are legally valid and electronic ones are not. That is not how it works, and treating it as a rule will eventually cost someone dearly. Whether a signature is legally effective depends on the jurisdiction, the type of document, the applicable regulation, and sometimes the specific requirements of an institution or counterparty rather than of any law.

Different frameworks exist and they differ in structure. In the European Union, eIDAS establishes tiers of electronic signature with different evidentiary treatment and defines qualified trust service providers. In the United States, the ESIGN Act and state-level UETA adoptions take a different approach. Other countries have their own regimes, and these frameworks do not map neatly onto each other. Meanwhile some categories of document — wills, certain property transfers, particular court filings — carry additional formal requirements that may demand notarisation or physical execution regardless of what any signature technology can prove.

The honest guidance is therefore narrow and practical. Understand what each mechanism proves technically, which is what this article covers. For anything legally sensitive, verify the requirements that apply to your document, in your jurisdiction, before relying on a particular signature method — and take professional advice where the stakes justify it. No tool, including any on this site, can tell you whether a given signature satisfies a given legal requirement.

Worth repeating

MyPDFilles tools described here run on your device.

When an article refers to a MyPDFilles tool, its parsing, compression or recognition runs in JavaScript and WebAssembly inside your browser tab on bytes read from your disk. Educational references to external software are not covered by that claim; review the external provider’s own privacy and security information.

How to verify MyPDFilles processing

Questions on this topic

Is a scanned image of my signature a digital signature?

No. It is an electronic signature — an image placed on the page. There is no cryptography attached, nothing records the document’s state at the moment it was added, and it can be copied onto another document without leaving any technical trace of having been moved.

What happens to a digital signature if I edit the document?

Verification fails for the altered range, by design. The signature covers a hash of specific bytes, so changing any of them makes the recomputed hash differ from the signed one. Some workflows permit defined later additions, such as further signatures, but arbitrary edits break verification.

Why does my viewer say a signature is valid but the signer is unknown?

Because those are two separate checks. The cryptography verified, meaning the bytes are unchanged and the private key holder signed them, but the certificate does not chain to a root your reader trusts — often a self-signed certificate. The document is intact; the identity claim is unconfirmed.

Which type do I need for a contract?

That depends on the jurisdiction, the document type and the applicable regulation, and frameworks such as eIDAS and ESIGN differ in how they treat each method. For anything legally significant, check the requirements that apply to your situation and take professional advice rather than assuming either method suffices.