Verify PDF

Validate signature in PDF online, free

Upload a signed file and Chaindoc checks cryptographic integrity, the certificate chain, revocation status and timestamps through the EU DSS library, then returns an eIDAS verdict. No Acrobat, nothing to install on your machine. Aadhaar eSign and Indian DSC files are read the same way. When your reader says Signature not verified, the report names the check that actually failed instead of one vague warning.

VALIDATE A PDF

Validate Signature in PDF

Upload a signed PDF and verify a digital signature online, free, against EU DSS validation standards.

We'll send a verification code to confirm your identity.

What the PDF check includes

  • Verify digital signature online free
  • PDF signature validation: PAdES, eIDAS, certificate chain
  • Detailed report ready in seconds
  • Your document is never stored
Validate in Chaindoc

The PDF you upload is never stored. The verification report is kept, privately, for 7 days and then deleted. After that your account keeps only a minimal record: result, signature count, date.

Step by step

How to validate a signature in a PDF

Three steps, roughly two minutes. It is also a free way to verify a digital signature online, because validating and verifying are one operation here — how to verify a digital signature in a PDF lands on the same report.

  1. Upload the signed PDF

    Drag it into the form above, up to 50 MB. The file needs a real digital signature inside it; a scanned picture of a handwritten one won't validate, because there's no certificate to check.

  2. Confirm your email

    Enter the one-time code we send. First check only, later checks in the same session skip it.

  3. Read the report

    Integrity, the signing certificate and its chain, revocation status, timestamps and the PAdES profile, each with its own pass or fail. This is the part a single Acrobat banner hides.

You checked their signature. Now send your own

Chaindoc signs documents to the same PAdES profile this page checks, so the person on the other end opens a file that passes instead of a warning. Our guide to signature not verified in PDF covers what each message means.

Sign a document
EU DSS compliant

What a PDF signature validation check covers

Chaindoc runs PDF signature validation online through the EU Digital Signature Service (DSS) library. Four of the checks below decide whether the signature itself holds up. The last two decide whether your own reader will agree — and that is where PDF signature verification usually trips people up. PAdES, the format most signed PDFs use, is defined by ETSI EN 319 142.

Recalculates the document hash and compares it with the one sealed inside the signature. One changed byte fails this, and re-saving a PDF counts as a change.

Checks the signing certificate's chain, validity period, and revocation status against trusted certificate authorities.

Validates embedded timestamps that prove when the signature was created. This matters for long-term validity, especially if a certificate expires later.

Checks whether the signature meets EU eIDAS regulation standards for qualified electronic signatures and seals. The same trust model applies across all signature formats.

Sign with Chaindoc

Sign documents online, provably

You just checked a signature — Chaindoc creates ones that pass the same check. A free electronic signature to start, a blockchain audit trail on every document, and an eIDAS-aligned result any verifier can confirm.

Trust and roots

Where a valid signature still gets flagged

The four checks above decide whether the signature holds. These decide whether your reader will agree, and they are where most people actually get stuck.

Chaindoc anchors trust in the EU Trusted List plus the large commercial CAs. Worth knowing: that isn't the same list Adobe Acrobat ships with, which is why one file can pass here and get flagged there.

Take an Indian Digital Signature Certificate (DSC). The cryptography comes back intact, the chain comes back unresolved, because the CCA root sits outside the EU Trusted List. Two separate verdicts, kept separate on purpose, so you can tell a trust gap from a tampered document.

That message is usually about trust, not tampering. A reader keeps its own list of trusted roots, and a certificate whose root is missing from it comes back unverified even when the file has not been touched. The report here keeps integrity and trust apart, so you can see which one you have.

Marksheets, DGFT licences and NIELIT certificates are signed under the CCA India hierarchy. Integrity comes back clean, the chain comes back unresolved, because that root sits outside the EU Trusted List. Clearing the warning itself belongs in your reader.

Loan agreements and onboarding packs are usually signed through Aadhaar eSign, where a licensed provider issues the certificate after an OTP or biometric check. The result is an ordinary PAdES signature, so integrity checks the same way. The chain still ends at CCA India, so trust comes back unresolved rather than failed.

An Aadhaar eSign certificate lives for roughly half an hour, which alarms people validating a year later. The embedded timestamp carries the proof: it fixes the signing moment while the certificate was still live. Without one, the signature really does weaken over time.

ETSI standards

Supported signature profiles

Chaindoc validates all four PAdES baseline profiles defined by ETSI. Each adds a layer of assurance on top of the previous one.

PAdES-BASELINE-B

The basic profile. Meets the minimum requirements for an advanced electronic signature under eIDAS.

PAdES-BASELINE-T

Adds a trusted timestamp, proving the signature existed at a specific point in time. Useful if you need to show that a contract was signed before a deadline.

PAdES-BASELINE-LT

Embeds long-term validation data (certificates and revocation info) so the signature can be verified even if the CA goes offline later.

PAdES-BASELINE-LTA

Adds an archive timestamp for long-term storage. Ensures the signature stays verifiable for years, even as cryptographic algorithms are retired.

FAQ

Common questions about PDF signature verification

How the verification check works, what the results mean, and what to do next. More at our support page.

Upload the PDF to the checker on this page. It runs in the browser, costs nothing, and returns integrity, certificate chain, revocation status, timestamps and the PAdES profile as separate results. If you'd rather stay in Adobe Acrobat Reader, open the Signatures panel, right-click the signature and choose Validate Signature. Acrobat will tell you whether it's happy, but not which of the four checks it was unhappy about.

Usually not. That message means Acrobat couldn't build a trusted path from the signing certificate up to a root it recognises, which is a trust question rather than a tampering question. A Digital Signature Certificate (DSC) is issued by a Certifying Authority licensed by India's Controller of Certifying Authorities, and that root sits outside both Adobe's own trust store and the EU Trusted List. The usual fix is to import the issuing CA chain and the CCA India root into Acrobat's trusted identities, then revalidate. Chaindoc anchors trust in the EU Trusted List, so a DSC-signed file comes back here with intact cryptography and an unresolved chain. The report keeps those two verdicts apart, which is the bit you actually need in order to know whether the document was altered.

PAdES (PDF Advanced Electronic Signatures) is an ETSI standard for embedding digital signatures in PDF files. It defines four levels of assurance, from basic signatures to long-term archival formats. PAdES signatures are legally recognised under the EU eIDAS regulation as advanced or qualified electronic signatures.

Upload your signed PDF and the EU Digital Signature Service (DSS) library validates it. The check covers four things: cryptographic integrity (the document wasn't modified), certificate validity (the signer's certificate was valid at signing time), timestamp verification, and certificate revocation status via CRL and OCSP. It typically takes a few seconds.

It means four conditions are met: the cryptographic signature is mathematically correct, the document hasn't changed since signing, the signing certificate was valid at that time, and the certificate chain traces back to a trusted root authority. If any of these fail, the signature is marked invalid.

Guides and resources

Document verification guides and resources

How blockchain hashing, audit trails, and tamper detection help you confirm a PDF is authentic and unaltered.