If the PDF has a certificate-based digital signature, open it in Adobe Acrobat, open the Signatures panel, and check the validation status. Acrobat can also show you the exact version that was signed and compare it to what’s in the file now. If the “signature” is only a drawn or typed image, the file can’t tell you anything by itself, so you compare it against a copy you already trust.

Which situation you’re in matters more than any tool, so start there.

What kind of signature is on your PDF?

There are two very different things people call a “signed PDF,” and only one of them can detect tampering on its own.

The first is a signature image. When you sign with Acrobat’s Fill & Sign tool or with the Sign button in macOS Preview, you type, draw, or photograph your signature and drag it onto the page. That’s a perfectly normal way to sign plenty of documents (I cover it in how to sign a PDF online). But neither Adobe’s Fill & Sign help page nor Apple’s Preview guide describes any mechanism that checks whether the rest of the document changed afterward. The signature is marks on a page.

The second is a certificate-based digital signature. Here the signing software uses a digital ID (a certificate) to cryptographically sign the document’s contents. Adobe’s documentation describes how Acrobat validates these, keeps a copy of the version that was signed, and flags changes. If you want the longer explanation of why these two are different, see electronic signature vs digital signature.

A quick way to tell: click on the signature in Acrobat. If a signature validation dialog appears, it’s a digital signature. If it just gets selected like any other object on the page (or nothing happens), you’re probably looking at an image.

How do I check a digital signature in Adobe Acrobat?

Open the PDF in Acrobat and click the signature; the Signature Validation Status dialog tells you whether the signature is valid. For more detail, click Signature Properties in that dialog.

Acrobat usually does this for you on open. Adobe’s help page says the preference “Verify Signatures When The Document Is Opened” is selected by default, so the result typically shows up in the document message bar at the top as soon as the file loads.

To see every signature in the file, open the Signatures panel. Adobe gives two routes: click the Signature Panel button in the document message bar, or choose View > Show/Hide > Navigation Panes > Signatures. (Adobe has been rolling out a redesigned Acrobat interface, so if that menu path doesn’t match your screen, the message bar button is the reliable one.) The panel lists each signature with an icon for its status, and you can expand each entry to see who signed, when, and the trust details.

Adobe mentions one icon specifically: a blue ribbon means a valid certifying signature. For the other warning icons, Adobe points you to its Digital Signature Guide rather than spelling them out on the help page, so I won’t guess at them here. When in doubt, click the signature and read the dialog. The words are more useful than the icon anyway.

How do I see exactly what changed after signing?

In the Signatures panel, select the signature and choose Compare Signed Version To Current Version from the Option menu. Acrobat then shows the differences between the version that was signed and the file as it stands now.

This works because, per Adobe, each time a document is signed with a certificate, “a signed version of the PDF at that time is saved with the PDF.” So the original signed state is still inside the file. If you just want to look at it, select and expand the signature and choose View Signed Version from the same Option menu. Acrobat opens that earlier version so you can read it as it was.

A made-up example: you manage a handful of rental units and a tenant emails back a digitally signed lease renewal. Acrobat says the document was modified after signing. You compare signed version to current version and see that the only change is a sticky note the tenant added saying “thanks.” Fine. If instead the rent on page two is different in the current version, you have your answer, and you have the original signed version sitting right there to show them.

A change after signing isn’t automatically sinister. Adobe describes certified documents where the author specifies which changes are allowed (for example, letting people fill in form fields and add signatures while the document stays certified). Later signers adding their own signatures also changes the file. The comparison tells you what changed, and then you judge whether it matters.

Why does Acrobat say the signature status is unknown?

“Unknown” usually means Acrobat can’t confirm who signed, not that the document was changed. Adobe explains that a signature is valid when “you and the signer have a trust relationship,” and that signatures made with self-signed certificates can’t be validated automatically because the certificate isn’t in the list of Trusted Identities Adobe uses.

So an unknown status is a question about identity, and a modified document is a question about integrity. They’re separate problems. Adobe’s advice for an unknown or unverified status is to validate the signature manually, which in practice means clicking it, opening Signature Properties, and reading why validation stopped. If the document integrity part checks out and the only issue is trust, you can confirm the signer’s certificate with them directly (a phone call works) before deciding whether to trust it.

Timestamps matter too. Adobe says a timestamp “assures the authenticity and existence of a document at a particular time,” and without one, the signing time shown may come from the clock on the signer’s own computer. If the date of signing matters to you, look for a timestamp in the signature properties.

What if the signature is just an image?

With an image signature, the PDF can’t tell you it was altered, so you need an outside reference: a copy of the file you know is the real one. That might be the copy the other person emailed you right after signing, the one you downloaded from an e-signature service, or the one sitting in your own sent folder.

Opening both side by side and reading them works for a two-page letter. For anything longer, compare file hashes. A hash function turns a file of any size into a short, fixed-length fingerprint (NIST’s definition: it maps “a message of arbitrary length to a fixed-length message digest”). Microsoft’s PowerShell documentation puts the practical point plainly: “Changing even a single character in the contents of a file changes the hash value of the file,” and if two files have identical hash values, their contents are identical.

On Windows, open PowerShell and run:

Get-FileHash "C:\Contracts\signed-agreement.pdf"

It uses SHA-256 by default. Run it on both copies and compare the long strings. Same string, same file. Different string, something changed, even if it’s just a re-save that touched nothing visible. A different hash doesn’t tell you what changed, only that the files are not byte-for-byte identical, so then you open both and read.

The habit that makes this useful: record the hash when you receive the signed document. Say you’re a freelance designer and a client signs a $3,200 project agreement. Paste the hash into the email thread or your project notes the day it comes in. If a different copy surfaces six months later during a billing dispute, you can show in about ten seconds whether it’s the same file.

What about PDFs signed through an e-signature service?

E-signature services generally keep their own record of what was signed, so the service itself is often the best reference copy. Download the completed document from the service rather than trusting a copy that was forwarded around, and look at whether the service provides an audit trail or completion certificate. That record usually shows who signed and when, which is exactly what you need if someone later claims the document was different. There’s more on what those records contain in what is an e-signature audit trail.

If the completed PDF from the service also carries a digital signature, you can run the same Acrobat checks described above on it.

We’re building SignWren so every completed document comes back as a sealed PDF with an audit trail, which makes this kind of check straightforward. It’s still pre-launch, with a waitlist open.