PDF signature checker
Read the raw digital signature metadata inside a PDF in your browser: count, signer, signing time, algorithm (adbe.pkcs7.detached and friends), byte ranges and whether they cover the whole file. No cryptographic verification.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Choose a PDF file
The file is read locally in your browser and never uploaded
Choose a PDF to inspect its signatures here
What this tool does
- Before trusting a contract or archive that claims to be signed, confirm whether any signature field actually exists: selecting the file lists the count, object offsets and ByteRange.
- Cross-check the raw signer, signing time, reason and location fields against what the other party says they signed.
- Detect edits after signing: check whether the ByteRange reaches the end of the file — any trailing uncovered bytes mean content was appended after signing.
- Spot unsigned placeholders: some templates ship a signature field whose /Contents is all zeros, and the tool flags that as a placeholder rather than a real signature.
Example
Input
A PDF with an Adobe.PPKLite signature (460 bytes, PDF 1.7)
Output
PDF version: 1.7 Signatures: 1 Signature 1 Object offset: 118 Filter: Adobe.PPKLite SubFilter: adbe.pkcs7.detached Algorithm: PKCS#7 / CMS detached signature Signer: Zhang San Signing time: 2026-01-01T12:00:00+08:00 Byte ranges: Range 1: 0 - 301 (301 bytes); Range 2: 431 - 460 (29 bytes) Covered bytes: 330 Uncovered trailing bytes: 0 (covers the whole file)
This is a minimal sample built with the byte layout of a real signed PDF. The ByteRange numbers come from the file itself and differ greatly between documents; the tool only reads information and does not verify signatures.
Frequently asked questions
Does it tell me the signature is valid?
No. This tool does not judge validity; it scans and displays the signature fields of a PDF and performs no cryptographic verification — no signature check, no certificate chain, no revocation status. Use Adobe Acrobat or pdfsig when trust matters.
What does a non-zero "uncovered trailing bytes" mean?
It means the signature ByteRange does not reach the end of the file, so content was appended after signing — another edit, a second signature or a rewritten incremental update. That is not proof of tampering, but it does mean the signed content and the current file are not identical, which is worth investigating.
What is the difference between adbe.pkcs7.detached and etsi.cades.detached?
The first is the classic PKCS#7 / CMS detached signature; the second is the European CAdES standard (the basis of PAdES), which can carry optional attributes such as timestamps and revocation info. Five identifiers are built in — adbe.pkcs7.detached, adbe.pkcs7.sha1, adbe.x509.rsa_sha1, etsi.cades.detached and etsi.rfc3161 — and anything else is shown as a raw identifier.
Why does one signature field show "Contents are all zeros"?
That is an unsigned placeholder, common in templates meant for people to sign after downloading. The field structure and ByteRange are reserved but the signature container still holds no real data, so the tool adds a separate placeholder warning.
Is the PDF uploaded anywhere?
No. The file is read into a byte array with FileReader and parsed locally, and there is no upload logic in the page. For sensitive documents it is still best to work offline and avoid unknown online services.
Keywords:pdf签名数字签名signaturebyterangepkcs7数字证书pdf 签名检查