To verify a digital signature in a PDF, open the file in a reader that supports signatures and look at its signature panel; for an independent second opinion, upload it to the European Commission's DSS demonstration validator; and look up the provider behind the certificate in the EU trusted lists. Each step answers a different question: has the file changed, who does the certificate belong to, and was it valid when the document was signed?
What verifying a signature actually checks
A digital signature can be checked mathematically, which is what makes it useful. The eIDAS Regulation sets out what validating a qualified electronic signature must confirm (Article 32(1)). In plain terms:
- the certificate was a qualified certificate at the time of signing, issued by a qualified trust service provider and valid at that moment;
- the validation data matches what you are shown, and the signer's identity in the certificate, or any pseudonym, is presented correctly;
- the signature was created by a qualified signature creation device;
- the signed data has not been changed;
- the requirements of an advanced electronic signature were met at the time of signing.
Since the 2024 amendment, Article 32a sets the same checks, without the device, for advanced signatures based on a qualified certificate. The Commission's DSS software applies the European standard for this kind of validation, ETSI EN 319 102-1.
Step 1: the signature panel of your PDF reader
Open the PDF in a reader that supports digital signatures, such as Adobe Acrobat Reader, and open its signature panel. For each signature or seal it shows who signed, when, whether the document has changed since and whether the certificate is trusted. A reader can only trust the certificates it knows: if it cannot trace a certificate back to a source it trusts, it will tell you that validity could not be confirmed, which is not the same as saying the file was altered. Not every PDF viewer, on a phone or a computer, checks signatures: if yours shows no signature panel, use a reader that does, or the online validator below.
Step 2: the European Commission's DSS validator
The Commission maintains Digital Signature Services (DSS), an open-source library for creating and validating electronic signatures, and a demonstration web app with a "Validate a signature" page. Upload the signed PDF and you get a simple report and a detailed one. For each signature the result is one of three indications:
- TOTAL-PASSED: the signature passed verification and complies with the validation policy.
- INDETERMINATE: the format and cryptographic checks did not fail, but there is not enough information to determine whether the signature is valid.
- TOTAL-FAILED: the signature format is incorrect or the signature value fails verification.
Two cautions come from the page itself. It is a demonstration: the Commission says it does not intend to provide a validation service through it and that its use should be limited to testing. And uploaded files are sent to the Commission's infrastructure; they are not retained, but the Commission advises against using documents with sensitive content. For confidential contracts, use validation software you control or a qualified validation service (Article 33 eIDAS).
Step 3: the provider in the EU trusted lists
A certificate is only as trustworthy as whoever issued it. The EU/EEA Trusted List Browser lets you search the national trusted lists by provider name, by type of service, such as certificates for electronic signatures or time stamping, and by country. You can also upload a signed file to find the trust service that issued its signing certificate. This tells you whether the certificate behind a signature, seal or time stamp comes from a qualified provider.
Why the time stamp matters
Certificates expire and can be revoked. A signature is judged on whether the certificate was valid when the document was signed, so the moment of signing must itself be provable. A trusted time stamp fixes that moment, and a qualified time stamp enjoys a presumption of the accuracy of its date and time and of the integrity of the data it is bound to (Article 41(2)). The European standards also define long-term levels: a signature with a time stamp (B-T), with the material needed to validate it embedded (B-LT), and with periodic time stamps that keep it verifiable over time (B-LTA). These levels are what allow a signature to be validated years later, even when the original sources of validation data are no longer available.
Common results and what they mean
- Changed after signing. Something was added or altered after the signature. A further signature or seal added later is normal; any other change means the content differs from what was signed.
- Validity unknown or INDETERMINATE. The certificate chain or its revocation status could not be checked. Try the other tool, or ask the sender which provider issued the certificate.
- Certificate expired. Not a problem in itself if a trusted time stamp shows the document was signed while the certificate was valid.
- No signature at all. The signature may be only an image, or a simple electronic signature with no certificate behind it. There is nothing cryptographic to verify, and the evidence lies in the audit trail.
What a valid result does not prove
A valid result tells you that the file is intact and was signed with a particular certificate. It does not tell you whether the person meant to sign or, for a simple electronic signature without a personal certificate, who clicked. Many platforms protect the finished PDF with their own seal: a valid seal shows that the document has not changed since the platform sealed it, while who signed and how is recorded in the audit trail. That is why the signed PDF and the audit trail belong together. Our comparison of digital and electronic signatures explains the difference between a seal and a signature, and our guide on when a qualified signature is required covers the documents where only a QES will do.
Checking a DOCUJET document
From the Starter plan upwards, a PDF signed with DOCUJET carries a qualified electronic seal and a qualified time stamp from Namirial in PAdES format. You can inspect them in your PDF reader's signature panel or, with a document that holds nothing sensitive, on the DSS validator, so the verdict does not come from us. Every document's fingerprint is also anchored on the Bitcoin blockchain: on our verification page you drag in the PDF, its SHA-256 fingerprint is calculated in your browser and compared with the public anchors, and the file never leaves your device. That anchoring is a complement to the legal evidence, not a substitute for it. DOCUJET does not offer qualified electronic signatures.
Sources: Regulation (EU) No 910/2014 (eIDAS), Articles 32, 33 and 41; Regulation (EU) 2024/1183, Article 32a; European Commission, DSS validation demo; DSS documentation; EU/EEA Trusted List Browser.
Ready to try it?Open a free account: 3 documents a month, forever, with a complete audit trail.Start for free →
