No, the digital signature visible on a printout cannot itself be cryptographically verified. The signed PDF may still be genuine and fully verifiable, but the paper preserves only its appearance. Keep or obtain the original electronic file, verify the signature against that file, and read the result for identity, integrity, scope, certificate trust, revocation and time instead of relying on a tick or signature picture.
Quick answer: Printing a digitally signed PDF does not cancel or damage the signature in the original file. It creates a different object that no longer carries the machine-verifiable signature evidence. A printed signature panel, name, date, QR code or green tick is not the verification result. Verify the original PDF.
The most useful metaphor is not a bulletproof jacket worn where there is no threat. It is a sealed evidence bag. Receiving a signed PDF and keeping only its printout is like photocopying the label on the bag and throwing the sealed bag away. The copy may show who supposedly sealed it and when, but you can no longer examine the seal that connected those claims to the evidence.
That is India's quiet digital-signature gap. Offices add signatures to electronic letters, citizens print those letters, files move as scans and photocopies, and the visible signature is treated as the proof. Even when the original PDF survives, the person reading it may never open the signature details. The control exists, but the decisive act, verification, is often missing from the workflow.
A digital signature is a mathematical relationship between an electronic record, a private signing key and the corresponding public key in a certificate. Rule 5 of the Information Technology (Certifying Authorities) Rules, 2000 describes verification as computing a new hash result over the original electronic record and using the public key to check the signature. Verification succeeds when the corresponding private key created the signature and the electronic record has not been altered since.
Paper cannot perform that calculation. A printout can reproduce the signature graphic, the signer's displayed name, a date and even the words “Signature valid.” Those marks are useful as labels, but they are not cryptographic evidence. The original PDF contains the signed byte ranges and certificate data that verification software needs.
| What the original signed PDF may carry | What the printout carries |
|---|---|
| Cryptographic signature object | A visual representation, if one was displayed |
| Exact signed byte ranges | Printed text and images |
| Signer certificate and issuer information | Whatever certificate details were printed on the page |
| Evidence of later permitted or disallowed changes | No machine-readable change history |
| Timestamp token, when one was added | A date printed as text |
| Data needed to test integrity | No embedded signature to test |
This is also why an invisible signature can be real and a beautiful blue signature panel can be fake. Adobe's documentation confirms that certificate-based signatures may be visible or invisible. Appearance is a presentation choice; validation is a technical operation.
“Does it have a digital signature?” is only the first question. A useful result separates at least these seven checks.
1. Is a cryptographic signature actually present?
A pasted image, scanned handwritten signature or printed rosette is not a digital signature. The verifier must find a signature object in the original electronic file.
2. Does the signature mathematics validate?
The verifier recomputes the document digest and checks it with the signer's public key. A failure here can mean the signed bytes changed, the signature data is damaged or the signature cannot be processed. The detailed reason matters.
3. What portion of the document was signed?
A PDF can contain revisions. Verification should say whether the signature covers the whole current document, an earlier revision, or only a defined part, and whether changes made after signing were allowed by the signature policy. A bare green tick can hide this distinction.
4. Who does the certificate identify?
Read the certificate subject, not only the name typed below the letter. Compare the certificate identity and organisation with the officer and office named in the document. This still does not prove that the person had administrative authority to issue that particular order; authority must be checked against office records.
5. Is the certificate chain trusted for this purpose?
The Controller of Certifying Authorities says verification needs the signer's certificate and the complete issuer chain up to the Root Certifying Authority of India. A reader may be unable to build that chain because a certificate is missing or its trust store is not configured. “Signer unknown” or “trust not established” is therefore not automatically a finding of forgery, but it is not a reason to rely on the document without resolving the gap.
6. Was the certificate valid, and was it revoked?
Check the certificate's validity period and the revocation information supplied by its issuer. The CCA specifically includes Certificate Revocation Lists in the material needed for verification. Expiry today does not by itself prove that an older signature was invalid when made; long-term verification depends on evidence about the relevant signing time and historical certificate status.
7. What does the date actually prove?
Keep three dates separate: the date typed in the letter, the signing time reported by the signer's computer, and a time established by a trusted timestamp service. Adobe explains that a signature can use the signer's local computer time or a secure timestamp-server time. Only the latter provides independent time evidence of the kind people often assume every date beside a signature supplies.
The most dangerous result is the one a person does not understand. Software products use different labels, so open the details instead of translating every warning into either “fake” or “fine.”
| Result you may see | What it can support | What to do next |
|---|---|---|
| Signature cryptographically valid and document intact | The signed bytes passed the integrity check | Still check coverage, signer, trust, certificate status, time and authority |
| Identity unknown or trust not established | Integrity may have passed, but the verifier did not establish a trusted certificate path | Obtain the issuer chain or use a verifier configured for the relevant trust framework |
| Could not check revocation or timestamp | That check is unresolved, not passed | Retry with the required network or issuer data; keep the result as incomplete |
| Signature invalid or document altered | A critical check failed | Do not rely on the file until the detailed cause is understood and a fresh original is obtained |
| No signature found | The file has no cryptographic signature the verifier can process | Do not treat a visible signature image as a substitute |
A verifier's green, amber or red summary is a starting point. The evidence is in the named checks underneath it.
We tested VeriPatra's public verifier with a non-confidential sample PDF carrying a valid self-signed certificate. The signature mathematics passed, the document was intact, the signature covered the complete file and the certificate was within its date range at signing. But the certificate did not chain to a trusted authority and no trusted timestamp was present. VeriPatra reported a partial or caution result rather than converting several successful checks into a blanket “verified” claim.
That is the verification literacy citizens need. “The bytes match the signature” and “I can rely on this signer, time and authority” are different conclusions.
Use this sequence when an RTI reply, order, certificate, notice or sanction arrives.
A QR code can help retrieve an issuer-controlled electronic record, but the printed code is not proof on its own. Follow it only if it resolves to the expected official domain, retrieve the original, and verify that file. A copied QR code can point wherever its creator chooses.
Use this before you print or forward a signed document: Download the free one-page Digital Signature Verification Checklist (PDF). It has spaces to record all seven checks, the source record and the evidence you preserved.
Section 3 of the Information Technology Act, 2000 establishes authentication of an electronic record by digital signature. Section 5 gives legal recognition to electronic signatures when the prescribed requirements are met. The verification mechanism in Rule 5 is explicitly tied to the original electronic record and detection of alteration.
This does not mean every signed statement is factually correct, every certificate holder had authority, or every printout becomes independently verifiable. Digital-signature verification answers defined questions about the electronic record and key. Administrative authority, accuracy of the contents and the legal effect of the underlying decision remain separate questions.
If you need the document as evidence, preserve the original electronic record and its provenance. For a legal proceeding, take advice on the applicable evidentiary requirements rather than assuming that a printout and visible signature panel are enough.
The Bharatiya Sakshya Adhiniyam, 2023, in force from 1 July 2024, keeps the electronic record and a computer output conceptually separate. Section 63 allows information from an electronic record that is printed, stored or copied to be admitted when its statutory conditions and certificate requirements are satisfied. That is an evidentiary route for the output; it does not put the embedded signature object back into the paper. Section 73 is even more direct: a court examining a purported digital signature may require production of the Digital Signature Certificate and direct a person to apply its public key to verify the signature.
The Supreme Court's decision in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1, decided under the earlier Evidence Act, also distinguished an original electronic record from a computer output and treated the statutory certificate as a condition for admitting the latter. The governing statute has since changed, so use the current BSA provisions for a current proceeding. The enduring practical lesson is narrower: preserving an electronic original and proving a paper output are not the same exercise.
Ask the issuing office for the original electronically signed file through its official channel. If the issuer is a public authority and the record is not supplied informally, the RTI Act lets you request existing records in electronic form.
You can ask for:
Do not ask the PIO to decide whether your copy is “genuine.” The RTI Act provides access to records, not a new forensic opinion. Ask for the source records and compare them.
Sample request item: “Please provide, in electronic form and in its original digitally signed file format, the office copy of Letter No. _ dated _. Please also provide the existing record showing the name and designation of its digital signatory and the office order or delegation in force on that date authorising the signatory to issue the letter.”
Section 6(1) governs the request, Section 6(3) covers transfer to the correct authority, Section 7(1) provides the ordinary response period, Section 10 allows exempt material to be severed, and Section 19(1) provides the first-appeal route. You can prepare the request with the AI RTI Drafter, track the deadline with the RTI Timeline Tracker, assess a vague or incomplete response with the PIO Reply Checker, and prepare the next step with the First Appeal Builder.
Disclosure: VeriPatra is made by Bighelpers Software, the organisation behind RTI Wiki. This section describes our own service. The verification principles and primary sources on this page apply whichever capable tool you use.
The VeriPatra public verifier is designed to expose separate checks instead of hiding them behind one badge. Its current verification page reports signature integrity, signer and issuer information, whether the signature covers the document, whether disallowed changes were found, certificate-date validity, trust, revocation status and timestamp status. It also shows the document's SHA-256 fingerprint and supports checking multiple files.
The service uses three plain-language outcomes: verified, caution and could not verify. An unavailable check is shown as unavailable rather than silently treated as a pass. Its public page states that the verifier can be used without an account and that submitted files are not kept. Read the current service and privacy information before uploading any confidential record.
VeriPatra does not certify that the words inside a document are true, that a signatory had official authority, or that a decision was lawful. No signature verifier can answer those questions from cryptography alone.
No. Printing does not modify or invalidate the signature inside the original PDF. It creates a paper copy that does not carry the cryptographic object needed to validate that signature. Keep the original file and verify it; treat the printout as a convenience copy.
Not from the scan alone. A scan contains pixels, not the original signature data. Use a trusted QR or official reference to retrieve the issuer's original signed PDF, then verify that electronic file.
It means a check failed, but you need the detailed result to know which one. The signed bytes may have changed, the signature may be malformed, or the software may have encountered another processing failure. Do not assume either forgery or harmlessness without reading the cause.
It often means the reader could not build or trust the certificate chain even though the integrity calculation passed. That is different from a proven alteration. Resolve the trust chain and certificate status before relying on the document.
Not automatically. It may be a typed document date or time taken from the signer's computer. Look specifically for a trusted timestamp and validate its certificate and status. A secure timestamp provides stronger independent evidence of when the signature existed.
It connects the signed bytes to a private key corresponding to the certificate. It does not prove who drafted every sentence, whether the certificate holder personally operated the key, or whether that person had authority to issue the decision. Check office records where those matters are important.
A PDF can contain later revisions, and some changes may be permitted by its certification settings. A good verifier reports what portion was signed and whether later changes were permitted. Do not reduce this to “the file can never change.”
Treat it as a summary, not a conclusion. Open the signature properties and check integrity, coverage, signer, trust chain, certificate validity, revocation and timestamp. Then separately assess the signer's authority and the truth of the contents.
Preserve the original signed PDF, the email or portal receipt showing where it came from, a verification report, the file fingerprint and the verification date. Do not keep only a printout or screenshot.