OxygenPDF

Digitale PDF-Signaturen prüfen & verifizieren

Digitale Signaturen in PDFs prüfen: Unterzeichner, Zertifikatskette, Signaturzeit und Manipulationserkennung. Kostenlos, komplett im Browser.

Check whether a signed PDF is still trustworthy

What verification actually checks

A PDF signature is a CMS (PKCS#7) blob embedded in the file, covering a declared byte range. This tool parses every signature dictionary, extracts the CMS structure, and runs three checks: does the signature cryptographically verify against the bytes it claims to cover, does the byte range span the whole file (so nothing was appended after signing), and what does the embedded certificate chain look like.

The result is a per-signature report: signer name and full subject, issuing CA, serial number, validity window, SHA-256 fingerprint, signing time, and a clear verdict — valid, modified after signing, or invalid.

What the report shows

Everything a verifier needs to make a trust call.

Validity verdict

Valid, modified-after-signing, or invalid — with the cryptographic check behind each call.

Certificate details

Subject, issuer, serial, validity dates, and SHA-256 fingerprint for every embedded certificate.

Signing time

The claimed signing time from the CMS attributes, plus RFC 3161 timestamp tokens when present.

Batch + JSON export

Verify several PDFs at once and export the whole result set as a JSON report for compliance records.

Tamper detection

The most important check is coverage: a signature only protects the bytes inside its byte range. If a document was modified after signing — a page added, a field changed, an incremental update appended — the signature either fails verification or provably does not cover the tail of the file. Both cases are flagged, so 'signed' never silently means 'unchanged'.

Document timestamps (ETSI.RFC3161 signatures) are recognized and reported separately, including the time the timestamping authority certified.

Local and private

Verification is pure parsing and math — no network, no upload, no OCSP or CRL fetches. The chain check reports what the embedded certificates prove on their own; whether you trust the issuing CA is a decision the report informs rather than makes.

Digitale PDF-Signaturen prüfen & verifizieren: Häufig gestellte Fragen

Häufige Fragen zu diesem Tool und seiner Funktionsweise.

Dauerhaft kostenlos

Alle 119+ Tools – dauerhaft kostenlos
Visueller Workflow-Builder – Tools miteinander verknüpfen
Desktop-App holen

Pro

$29 einmalig
Mehrere Dateien gleichzeitig im Batch verarbeiten
Indie-Entwicklung unterstützen
14 Tage Geld-zurück-Garantie

Wir nutzen Analysen, um zu verstehen, wie unsere Tools verwendet werden, und um das Nutzererlebnis zu verbessern. Es werden niemals persönliche Dateien übertragen.