Change one byte of a digitally signed PDF and every serious PDF reader will tell you. Not because someone looked at the page, but because the file no longer matches the number that was locked into it when it was signed.
That's the thing a digital signature does that a picture of your handwriting can't. A drawn signature says "I agree." A certificate signature says "I agree to exactly this file, and here's the proof it hasn't changed since."
Quick answer: A digital signature PDF is a PDF carrying a cryptographic signature made with your private key and an X.509 certificate. It covers the whole file, so any later change breaks it. You need a certificate as a .pfx or .p12 file. Digital Sign PDF signs in your browser with it, and Validate Signature checks a signed PDF you received. Neither uploads the document.
Two Things Called "Digital Signature"
Search for "digital signature PDF" and you'll get two kinds of tool mixed together.
The first kind puts your signature on the page: you draw it, type it or upload a photo, and it becomes part of the drawing. Legally, that's an electronic signature, and for most contracts it's all you need. We covered it in how to sign and fill a PDF for free.
The second kind, and the subject of this post, puts a signature in the file. It isn't a picture. It's a block of data that ties a hash of the document to a certificate, and it's what Acrobat's signature panel, a court's e-filing system or a government portal is checking for when they say "digitally signed."
The EU's eIDAS regulation draws the same line in law. An electronic signature is any "data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign," which a typed name meets. An advanced one has to be linked to the data so that "any subsequent change in the data is detectable," and a qualified one is an advanced signature made with a qualified device and "based on a qualified certificate." Only that last tier gets the automatic legal effect of a handwritten signature across the EU (Regulation 910/2014, Articles 3, 25 and 26).
What a Certificate Signature Actually Does
When you sign, two things go into the PDF.
The first is a signature field with a /ByteRange, a list of which bytes of the file are covered. That's every byte except one gap: a /Contents slot, reserved before signing, where the signature will sit.
The second fills the slot. It's a CMS package (the format also called PKCS#7) holding a SHA-256 hash of the covered bytes, signed with your private key, plus your certificate, so anyone can check the signature with your public key.
Checking runs the same steps backwards. The reader hashes the two ranges again and tests the stored signature against that hash with the certificate's public key. A match means these are the bytes that were signed. No match means something changed, whether a character, a pixel or a hidden annotation.
We tested this on our own output. We signed a two-page PDF with Digital Sign PDF and a test certificate, and poppler's pdfsig reported "Total document signed" and "Signature is Valid." We changed a single byte and ran it again: "Digest Mismatch."
What it does not prove on its own is who you are. The signature proves that whoever held the private key for this certificate signed this exact file. Whether that certificate belongs to a real, verified person depends on who issued it.
Valid Is Not the Same as Trusted
This is where most "my signature shows a warning" questions come from. A PDF reader runs two separate checks, and people treat them as one.
| Check | Question it answers | What breaks it |
|---|---|---|
| Integrity | Has the file changed since it was signed? | Any edit to the signed bytes |
| Trust | Does the certificate chain to an authority this reader trusts? | Self-signed certificate, unknown CA, missing chain |
A signature can pass the first and fail the second. Our test file did exactly that: pdfsig said "Signature is Valid" and, in the next line, "Certificate issuer isn't Trusted," because we'd signed with a certificate we made ourselves.
Adobe Acrobat and Reader decide trust with the Adobe Approved Trust List (AATL), a list of certificate authorities whose signing certificates Acrobat trusts automatically. Sign with a certificate from an AATL member and the recipient sees a green check. Sign with a self-signed one, or one your company's internal CA issued, and they'll see "signature validity is unknown" until they trust your certificate by hand.
So which certificate should you use?
- Self-signed (made with OpenSSL or your OS keychain): free, fine for internal approvals and for proving to yourself that a file hasn't changed. Expect the warning everywhere else.
- From your company or university CA: many employers and universities issue signing certificates. Trusted wherever that CA is trusted, usually inside the organisation.
- From an AATL provider: paid and identity-checked, and the one to use when the recipient's Acrobat has to trust you with no setup.
- Qualified (eIDAS) or a national ID card: the strongest legal standing in the EU. These keys usually live on a smart card or in a remote signing service, not in a
.pfxfile you can export, which matters for the next section.
How to Digitally Sign a PDF in Your Browser
You need a PDF and a certificate in PKCS#12 format, a .pfx or .p12 file with its password. Windows exports one from the certificate manager; macOS Keychain Access exports one as "Personal Information Exchange."
- Open Digital Sign PDF and drop in the PDF.
- Choose your
.pfxor.p12file, type its password and press Load. The tool shows who the certificate was issued to, by whom, and when it expires. The key is read in your browser tab and never sent anywhere. - Pick visible or invisible. Visible places a signature box on the page: choose the page, one of nine positions (bottom-right by default) and a width, and decide whether it shows your name, the reason and the date. You can add an image of your handwritten signature to the box. Invisible adds the cryptographic signature with nothing drawn on the page.
- Add a reason ("Approved", "Reviewed") and a location if your process asks for them. Both are stored in the signature.
- Sign, and download
yourfile-signed.pdf.
The signature uses SHA-256 and embeds your certificate plus any chain certificates that were in the .pfx. Include the chain if you have it; a signature whose issuer isn't embedded is harder for a reader to check.
What to Know Before You Sign
Sign last, and sign once
Digital Sign PDF rewrites the whole file when it signs, rather than appending to it the way Acrobat does for a second signer. If the PDF already carries a signature, that earlier signature will break. We checked: signing our test file a second time left pdfsig reporting the first signature as "Digest Mismatch." Make every edit first, then sign. If a document needs several people's certificate signatures in sequence, use software built for incremental signing.
It's a standard PDF signature, not PAdES
The signature uses the adbe.pkcs7.detached format defined in the PDF standard, which Acrobat, poppler and other readers validate. The EU's PAdES profile (ETSI EN 319 142) asks for a different format, ETSI.CAdES.detached, with extra signed attributes. If a tender or portal says "PAdES-B" or "qualified electronic signature," this tool isn't the one, and a qualified certificate usually can't leave its smart card anyway.
The time comes from your computer
The signing time stored in the signature is your device clock, which anyone can change. To prove when a document existed, add a trusted timestamp: Timestamp PDF gets one from a timestamp authority (sending only a hash of the file), but use it on an unsigned document, since it also saves the file again and would break a signature already on it.
Password-protected files lose their text
If your PDF is password-protected, the tool rebuilds it from page images before signing, so the signed copy loses selectable text. Remove the password first if the text matters.
How to Check a Digital Signature Someone Sent You
Got a signed PDF and want to know if it's real? Validate Signature reads every signature in the file, in your browser, and reports for each one:
- Status: Valid, Modified after signing, Invalid, or Document timestamp.
- Coverage: whole document, or partial with bytes added after signing.
- Signer: the certificate's subject, issuer, serial number, validity dates and SHA-256 fingerprint.
- Chain: verified to the root embedded in the file, self-signed, incomplete (issuer not embedded) or broken.
You can drop in several PDFs at once and export the results as a JSON report.
Read the chain result for what it is. "Verified to embedded root" means the certificates in the file link up correctly, not that the root belongs to a CA anyone trusts, and the tool doesn't check revocation lists. It answers "has this file changed, and who does the certificate say signed it?" For "does my organisation trust this signer?", open the file in the reader your organisation uses, which applies its own trust list.
Your Key Stays on Your Machine
A signing certificate is a key: whoever has the file and its password can sign as you. Uploading it to a website so the site can sign on your behalf hands that key to someone else. Digital Sign PDF parses the certificate and signs with your browser's own WebCrypto, in the tab, and the PDF never leaves your computer either. Why we build every tool this way is in why local-first PDF tools.
Frequently Asked Questions
What is the difference between a digital signature and an electronic signature?
An electronic signature is anything that shows intent to sign: a typed name, a drawn signature, a click. A digital signature is a specific technology: a cryptographic signature made with a certificate, which makes any later change to the file detectable. Every digital signature is an electronic signature; most electronic signatures aren't digital.
Do I need to buy a certificate to digitally sign a PDF?
No. A self-signed certificate made with OpenSSL or your operating system works and proves the file hasn't changed. Recipients will see a "validity unknown" warning until they trust it, so for documents going to outside parties, a certificate from a trusted provider avoids the warning.
Why does Adobe say my signature validity is unknown?
The document check passed but the trust check didn't: the certificate doesn't chain to an authority on Adobe's trust list. This is normal for self-signed and company-issued certificates. The recipient can trust the certificate manually, or you can sign with a certificate from an Adobe Approved Trust List provider.
Can a digitally signed PDF be edited?
It can, but the edit breaks the signature, and any PDF reader that checks signatures will show it as invalid or modified. That's the point. If you need changes, edit the unsigned original and sign again.
Is a digital signature on a PDF legally binding?
In most countries an electronic signature of any kind can be binding, and a certificate signature is stronger evidence than most. In the EU, only a qualified electronic signature automatically has the same legal effect as a handwritten one. If a process names a specific level, check what it requires before you sign.
Have a certificate and a final draft? Digitally sign your PDF in your browser, then run it through Validate Signature to see exactly what your recipient will see.
Rohman

