An electronic signature is a legal idea: any electronic mark or action a person uses with the intent to sign something. A digital signature is a piece of cryptography: math that proves a file hasn’t changed since a particular key signed it. They often show up on the same document, but they answer different questions, and mixing them up leads people to pay for things they don’t need or skip the one thing that would have helped them.

What is an electronic signature?

An electronic signature is any electronic sound, symbol or process attached to a record and adopted by a person with the intent to sign it. That’s almost word for word how the US federal ESIGN Act defines it in 15 U.S.C. § 7006. A typed name at the bottom of an email, a squiggle drawn with your finger on a phone, a click on an “I accept” button: all of these can qualify.

Notice what the definition leaves out. It says nothing about encryption, certificates or special software. The law cares about two things: did the person mean to sign, and is the signature connected to the thing being signed? ESIGN’s general rule in § 7001 is that a signature or contract “may not be denied legal effect, validity, or enforceability solely because it is in electronic form.” We go into what that does and doesn’t cover in are electronic signatures legally binding, and into the humble typed name in is a typed name a legal signature.

The EU uses a very similar starting point. The eIDAS Regulation defines an electronic signature as “data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign.” Same shape: it’s about use and association, not technology.

What is a digital signature?

A digital signature is a value calculated from a document using a private key, which anyone can then check using the matching public key. NIST’s Digital Signature Standard (FIPS 186-5, February 2023) puts the purpose plainly: digital signatures “are used to detect unauthorized modifications to data and to authenticate the identity of the signatory.”

Here’s roughly how it works, without the math. The software runs the document through a hash function, which produces a short fingerprint called a message digest. Change a single comma in the document and the fingerprint comes out completely different. The signer’s private key then signs that fingerprint. Later, anyone with the public key can recompute the fingerprint and check it against the signature. If they match, the file is exactly what was signed. If not, something changed.

FIPS 186-5 currently approves three algorithms for this: RSA, ECDSA and EdDSA. The older DSA algorithm is no longer approved for creating new signatures, though it can still be used to verify ones made before the change.

One thing a digital signature can’t tell you is whether a human meant to agree to anything. Servers digitally sign software updates all day long. Nobody “signed” those in the legal sense. The cryptography proves which key was used and that the data is intact. Intent is a separate question.

So what’s the actual difference?

The short version: an electronic signature is about agreement, and a digital signature is about integrity and key ownership.

Electronic signature Digital signature
What it is A legal category A cryptographic technique
Question it answers Did this person intend to sign this? Has this file changed, and which key signed it?
Examples Typed name, drawn signature, “I agree” click RSA, ECDSA or EdDSA signature on a PDF or file
Needs a certificate? No Needs a key pair; a certificate ties the key to a name

People get tripped up because vendors use the terms loosely, and because in practice good signing tools use both at once.

Can one document have both?

Yes, and that’s usually the best setup. The person signing makes an electronic signature (they type or draw their name and confirm they agree), and the signing service then applies a digital signature to the finished PDF so any later edit becomes detectable.

Take a made-up case. Maya runs a one-person wedding photography business and sends a couple a $2,400 contract. They draw their signatures on a phone. That’s the electronic signature, and in most situations it’s enough to form the contract. Eight months later there’s a dispute: the couple insists the cancellation window was 30 days, and Maya’s copy says 14.

If the completed PDF was sealed with a digital signature, this gets boring fast. Open the file in a reader that validates signatures, and it will show whether the document was modified after sealing. If there was no seal, Maya and the couple are each holding a PDF and pointing at it. Nobody’s lying necessarily; it just becomes much harder to prove. We walk through that check in how to check if a signed PDF was altered.

Is a digital signature more legally binding?

In the US, not by itself. ESIGN is deliberately technology-neutral, so a drawn signature and a certificate-backed one both start from the same legal footing. What the digital signature adds is evidence. If the other side ever says “that’s not what I signed,” a valid cryptographic seal is a strong answer.

The EU is more layered. eIDAS has three levels: a plain electronic signature, an advanced electronic signature and a qualified electronic signature. One of the requirements for the advanced level (Article 26) is that the signature is linked to the data signed “in such a way that any subsequent change in the data is detectable.” That’s precisely the job a digital signature does, so the higher eIDAS levels lean on cryptography. At the top, a qualified electronic signature “shall have the equivalent legal effect of a handwritten signature” under Article 25. The full breakdown is in SES vs AdES vs QES under eIDAS.

Where do certificates and “digital IDs” come in?

A digital signature proves that whoever holds a particular private key signed the file. It doesn’t, on its own, say who that is. A certificate fills that gap by linking a public key to a named person or organization.

eIDAS describes a certificate for electronic signature as an electronic attestation that “links electronic signature validation data to a natural person and confirms at least the name or the pseudonym of that person.” How much you can trust that link depends on who issued it. A self-made certificate proves very little about identity. One issued by a certificate authority after checking ID proves more. In the EU, a qualified certificate has to come from a qualified trust service provider.

For most small businesses, this is the part you can mostly leave to your signing tool. When a service seals a completed PDF, it can use its own certificate to say “this is the document as it stood when signing finished,” while the audit trail records who signed, when and how.

Which one do you actually need?

For most US small-business paperwork (quotes, NDAs, contractor agreements, client onboarding forms), you need a valid electronic signature, and you want a digital seal on the final file plus an audit trail. You don’t need to go buy a personal certificate.

Signing a mutual NDA with a supplier you’ve worked with for years? Drawing your signature in macOS Preview (Apple’s built-in PDF app lets you sign with the trackpad, the camera or a nearby iPhone) and emailing the PDF back is plenty. Where it starts to feel thin is when you’re chasing signatures from several people, need proof of when each person signed, or expect a disagreement down the road.

You’d want to go further, into certificate-based or qualified signatures, when someone requires it: an EU counterparty asking for a QES, a government portal, a regulated process, or a contract that specifies the signing method.

We’re building SignWren to handle the everyday case: people sign on any device, and everyone gets back a sealed PDF with an audit trail. It’s not launched yet, but you can join the waitlist if you want early access.

This article is general information, not legal advice. For a specific contract or dispute, talk to a lawyer licensed where you are.