About PDF signature inspector
Two very different things are called a signature on a PDF, and confusing them causes real problems. An electronic signature is a picture: a scanned squiggle, a drawn line from a touchpad, or a typed name in a script font, placed on the page like any other image. It contains no cryptography, proves nothing about who put it there, and can be copied from one document to another in seconds. A digital signature is a cryptographic object. A hash of a defined byte range of the document is signed with a private key, and a certificate is embedded so a verifier can check the signature and see who the key is attributed to. Any change to the covered bytes breaks it. This tool examines the signature objects in a file and tells you which kind you are looking at — and for digital signatures, the signer name in the certificate, the claimed signing time, the algorithms used, and whether the signature covers the whole document or only part of it.
How to PDF signature inspector
- 01
Load the signed PDF
Any document you have been told is signed. Signature fields live in the AcroForm structure and annotation objects.
- 02
Read the classification
Each signature object is classified as a cryptographic digital signature or an appearance-only electronic signature.
- 03
Check the byte-range coverage
For digital signatures, confirm whether the signature covers the entire file or only an earlier revision of it.
- 04
Verify trust elsewhere
For a legally meaningful trust decision, open the file in a reader with a configured trust store.
What this tool does
- Separates cryptographic digital signatures from image-only electronic signatures
- Reports the signer name and issuer recorded in the embedded certificate
- Shows the claimed signing time and whether a trusted timestamp is attached
- Reports byte-range coverage, exposing signatures that cover only part of a document
- Detects empty signature fields awaiting a signature, and lists them separately
Limitations worth knowing
Every PDF tool has constraints. Stating them plainly is more useful than discovering them halfway through your work.
- This tool does not perform full certificate-chain trust validation. It reports the presence and properties of signature objects; it does not decide whether a signature should be trusted.
- No revocation checking is performed — no CRL or OCSP lookups, which would require network requests.
- A signer name in a certificate is a claim by whoever issued it, not proof of identity.
- An image-only electronic signature cannot be attributed to anyone, no matter how authentic the handwriting looks.
How your file is handled
This tool runs entirely inside this browser tab. When you choose a file, your browser reads it from your own disk and hands the bytes to JavaScript running on this page — no network request carries your document anywhere. You can confirm that yourself: open your browser’s developer tools, switch to the Network panel, and run the tool. You will see no upload.
Nothing is stored after the fact. Closing or reloading this tab discards the file, the result and everything derived from them, because none of it ever left your machine. Read how local processing works.
Questions about PDF signature inspector
What is the difference between an electronic and a digital signature?
An electronic signature is an image or drawing placed on the page — visual only, with no cryptography behind it. A digital signature is a cryptographic object: a signed hash over a byte range, with an embedded certificate, that breaks if the covered content changes.
Does this tool tell me whether a signature is valid and trustworthy?
No, and it deliberately does not claim to. It reports what the signature objects contain and how much of the document they cover. Full validation means checking the certificate chain against trusted roots and testing revocation, which needs a proper trust store.
The signature looks real but it reports no cryptography. What does that mean?
That it is an appearance, not a signature — a pasted image of handwriting. It may still be what the parties agreed to use, but the document carries no cryptographic evidence of who applied it or that nothing changed afterwards.
Why does byte-range coverage matter?
Because a signature only protects the bytes it covers. If content was appended after signing, the signature can remain intact while the visible document differs from what was signed. A coverage gap is worth investigating.
Can I add a digital signature with this site?
Sign PDF places a visible signature appearance. A true digital signature requires access to a private key and certificate, which a browser tool cannot handle responsibly on your behalf.
Tools that pair with this one
- PDF Security InspectorEvery security-relevant feature of a document, inventoried in one pass.
- PDF Security AnalyzerNot just what is in the file — which parts of it are a problem.
- Flatten PDF FormBake the current answers into the page and drop the fillable layer.
- PDF Metadata ViewerRead the fields a PDF carries about itself, including the raw XMP.
- PDF Encryption CheckerOne question, answered exactly: what encryption does this file use?
- PDF Permissions CheckerRead the permission bits a PDF sets — and what they are really worth.
Read more about this
- How to sign a PDFThis site does not add electronic or cryptographic signatures. Use this guide to distinguish a visible mark from a certificate-backed signature and choose an appropriate external workflow.5 min guide
- How to password protect a PDFMyPDFilles does not encrypt or decrypt PDFs here. This guide explains real PDF encryption, weaker permission flags and the limits of local inspection so you can choose an appropriate external workflow.6 min guide