SourceCheck tells you what a file can prove about itself and what it cannot. This page explains each verdict, what the evidence behind it means, and how to combine the checks into a conclusion you can defend.
Verified: valid Content Credentials, signed by a certificate on the C2PA trust list, and the file is unchanged since signing. Valid Signature: the signature and content match, but the signer is not on the trust list. Signature Invalid: the file carries credentials, but the content no longer matches what was signed. Credentials Present: credentials were found but could not be fully validated. AI-Generated: the credentials themselves say a generator produced it. AI Traces Found: no credentials say so, but metadata, watermarks or the classifier point to generation. No Credentials: nothing to verify - which is true of most photos and proves nothing either way.
Does "No Credentials" mean the photo is fake?
No. Most photos carry no Content Credentials, because most cameras and phones do not add them and most websites and messaging apps strip metadata when you upload. A missing signature is an absence of evidence, not evidence of fakery. Look at the rest of the report - metadata, AI signals and, in Pro, forensics - and at where the image came from.
What is the difference between Verified and Valid Signature?
Both mean the file has not changed since it was signed. Verified also means the signer's certificate chains up to the official C2PA trust list. Valid Signature means anyone could have made that certificate - the maths checks out, but the identity is unproven. A self-signed manifest claiming to come from a camera maker lands here, not in Verified.
Why would a real photo show Signature Invalid?
Because something changed the bytes after signing. That can be a malicious edit, but it is often innocent: a crop, a colour adjustment in an app that does not update credentials, or recompression by a platform that kept the metadata but re-encoded the pixels. The report shows the recorded edit history and ingredients, which usually tells you which it was.
How much should I trust the AI likelihood score?
As a strong hint, not proof. In our benchmark the classifier flagged 94 of 105 recent images from Midjourney, Flux and GPT and raised no false alarms on 75 verified camera photos. Real photos - especially heavily processed ones from modern phones - can still score high, and heavily recompressed AI images can score low. Combine the score with provenance and metadata before drawing a conclusion.
What are AI traces in metadata?
Many generators write their settings into the file. Stable Diffusion WebUI, for example, stores the prompt and generation parameters in a PNG text chunk called "parameters", and other tools leave their name in software fields or add an IPTC source type that marks the image as algorithmically generated. These are strong signals when present - but they disappear the moment a file is re-saved or screenshotted, so their absence proves nothing.
What does the watermark scan look for?
TrustMark watermarks - invisible marks embedded in the pixels that are designed to survive resizing and recompression. They are used to recover Content Credentials that were stripped from a file. SourceCheck scans for TrustMark specifically; other watermarking schemes, such as those used privately by some AI companies, are not detected, so a negative result is not a clean bill of health.
How do I read error level analysis?
The ELA view re-saves the JPEG and shows how much each region changes. Areas that were pasted in or edited often compress differently from their surroundings and stand out. But edges, text and fine texture are always brighter, and an image re-saved many times flattens out entirely. Look for a region that differs from similar content nearby, not for bright areas in general. It only works on JPEG.
Does SourceCheck upload my files?
No. Every check runs on your device. There is no account, no tracking, and it works offline - switch to Airplane Mode and check a file if you want to confirm it.
What is the SHA-256 in the report for?
It is a fingerprint of the exact bytes that were checked. If anyone later needs to know whether a file is the one you examined, they can compute its SHA-256 and compare. Change a single byte and the hash is completely different. See what SHA-256 is.
Which file types can I check?
JPEG, PNG, WebP, HEIC, AVIF, TIFF and GIF images, MP4 and QuickTime video, PDF, and Office documents. Content Credentials can be attached to all of these; forensics such as error level analysis apply to JPEG.
Can it detect deepfake videos?
It verifies Content Credentials and reads metadata in MP4 and QuickTime files, which is how signed or AI-labelled video is identified. Frame-by-frame deepfake analysis of unsigned video is a different and much harder problem, and the report is explicit about what was and was not checked.
Does my history sync between devices?
History is saved on the device where the check was made. One purchase unlocks Pro on all your devices, but reports stay local to each one - which is part of keeping the files private.
What is free and what is in Pro?
The free version verifies Content Credentials, reads metadata and keeps your recent reports. Pro adds AI detection, watermark scanning, JPEG forensics, batch checking, unlimited history and report export to PDF, CSV and JSON. Choose monthly, yearly with a free trial week, or a one-time lifetime purchase.
Get SourceCheck: Detect Fake Photos & Deepfake
Check whether a photo came from a camera, an AI generator or an editor - C2PA verification, AI detection and metadata, all on the device.
You’re browsing inside Instagram, and its built-in browser isn’t allowed to hand
links over to the App Store. Open this page in Safari and the link will work.
Tap •••the three-dot menu
at the top right, then choose Open in external browser.