Home > Resources > Tools > PDF Signature Verifier

Verify a digitally signed PDF

Check signature integrity, signer identity and certificate trust.

More Information About the PDF Signature Verifier

A digital signature inside a PDF binds the document bytes to a signer's certificate. This tool reads that signature and checks four things:

  • Integrity. The signed portion of the file is hashed and compared against the digest sealed inside the signature. Any change to the signed bytes, even one character, breaks the match.
  • Authenticity. The cryptographic signature is verified against the public key in the signer's certificate.
  • Trust. Each certificate in the chain is checked to be signed by the one above it, and the chain is checked against a built-in trust store. The store recognizes roots from the Adobe Approved Trust List, the Singapore NDI root, and participating ASEAN national root CAs. The Origin field shows which list vouches for a given signature. Where a signer leaves intermediate certificates out of the signature itself and places them in the document security store instead, as long-term validation formats allow, those are picked up too and marked in the chain.
  • Coverage. Whether the signature covers the whole file, or content was appended after signing.

It works with standard PDF signature formats (PKCS#7 and PAdES/CAdES), which includes documents signed with Sign with Singpass, for example through nSignSG, as well as Adobe and most other signing tools. Certificates from authorities not in the built-in trust store still verify as a valid chain, but are shown as not trusted.

Supported signature algorithms: RSA and RSA-PSS, ECDSA (P-256, P-384, P-521), and the NIST post-quantum standards ML-DSA (FIPS 204) and SLH-DSA (FIPS 205). Post-quantum signatures are verified by an implementation embedded in this page, since browsers do not yet provide native support for them.

Current limitations of this version: the ASEAN national-root coverage is partial and grows as roots are added, and password-protected PDFs are not supported. Revocation is checked only against evidence embedded in the document itself (PAdES-LTV document security store or Adobe revocation archival); no live OCSP or CRL lookup is performed, so a certificate revoked after the embedded evidence was produced can still verify.

This tool reports only what the checks above show. Treat the results as a strong signal, not a guarantee. It does not check everything, its trust store is limited, and like any software it can contain bugs or miss a case it was not built for. For high-stakes decisions, confirm through an independent method as well.

This is an independent tool. It is not affiliated with or endorsed by Adobe, IMDA, or any listed certificate authority. Origin labels and registry links point to those parties' own public pages for verification.

Need to sign a document first? Use nSignSG, free with your Singpass app.

Contact Us: General enquiries or free consultation

We’re really grateful for giving us a chance to connect with you. Please do not hesitate to ask us anything and we will respond to you asap.

image

    You have read, understood and agree to be bound by Netrust's Personal Data Protection Policy and Terms of Service.

    This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.