SourceCheck Help & FAQ

SourceCheck tells you what a file can prove about itself and what it cannot. This page explains each verdict, what the evidence behind it means, and how to combine the checks into a conclusion you can defend.

SourceCheck: Detect Fake Photos & Deepfake app icon SourceCheck: Detect Fake Photos & Deepfake View product page →

Frequently asked questions

What do the seven verdicts mean?

Verified: valid Content Credentials, signed by a certificate on the C2PA trust list, and the file is unchanged since signing. Valid Signature: the signature and content match, but the signer is not on the trust list. Signature Invalid: the file carries credentials, but the content no longer matches what was signed. Credentials Present: credentials were found but could not be fully validated. AI-Generated: the credentials themselves say a generator produced it. AI Traces Found: no credentials say so, but metadata, watermarks or the classifier point to generation. No Credentials: nothing to verify - which is true of most photos and proves nothing either way.

Does "No Credentials" mean the photo is fake?

No. Most photos carry no Content Credentials, because most cameras and phones do not add them and most websites and messaging apps strip metadata when you upload. A missing signature is an absence of evidence, not evidence of fakery. Look at the rest of the report - metadata, AI signals and, in Pro, forensics - and at where the image came from.

What is the difference between Verified and Valid Signature?

Both mean the file has not changed since it was signed. Verified also means the signer's certificate chains up to the official C2PA trust list. Valid Signature means anyone could have made that certificate - the maths checks out, but the identity is unproven. A self-signed manifest claiming to come from a camera maker lands here, not in Verified.

Why would a real photo show Signature Invalid?

Because something changed the bytes after signing. That can be a malicious edit, but it is often innocent: a crop, a colour adjustment in an app that does not update credentials, or recompression by a platform that kept the metadata but re-encoded the pixels. The report shows the recorded edit history and ingredients, which usually tells you which it was.

How much should I trust the AI likelihood score?

As a strong hint, not proof. In our benchmark the classifier flagged 94 of 105 recent images from Midjourney, Flux and GPT and raised no false alarms on 75 verified camera photos. Real photos - especially heavily processed ones from modern phones - can still score high, and heavily recompressed AI images can score low. Combine the score with provenance and metadata before drawing a conclusion.

What are AI traces in metadata?

Many generators write their settings into the file. Stable Diffusion WebUI, for example, stores the prompt and generation parameters in a PNG text chunk called "parameters", and other tools leave their name in software fields or add an IPTC source type that marks the image as algorithmically generated. These are strong signals when present - but they disappear the moment a file is re-saved or screenshotted, so their absence proves nothing.

What does the watermark scan look for?

TrustMark watermarks - invisible marks embedded in the pixels that are designed to survive resizing and recompression. They are used to recover Content Credentials that were stripped from a file. SourceCheck scans for TrustMark specifically; other watermarking schemes, such as those used privately by some AI companies, are not detected, so a negative result is not a clean bill of health.

How do I read error level analysis?

The ELA view re-saves the JPEG and shows how much each region changes. Areas that were pasted in or edited often compress differently from their surroundings and stand out. But edges, text and fine texture are always brighter, and an image re-saved many times flattens out entirely. Look for a region that differs from similar content nearby, not for bright areas in general. It only works on JPEG.

Does SourceCheck upload my files?

No. Every check runs on your device. There is no account, no tracking, and it works offline - switch to Airplane Mode and check a file if you want to confirm it.

What is the SHA-256 in the report for?

It is a fingerprint of the exact bytes that were checked. If anyone later needs to know whether a file is the one you examined, they can compute its SHA-256 and compare. Change a single byte and the hash is completely different. See what SHA-256 is.

Which file types can I check?

JPEG, PNG, WebP, HEIC, AVIF, TIFF and GIF images, MP4 and QuickTime video, PDF, and Office documents. Content Credentials can be attached to all of these; forensics such as error level analysis apply to JPEG.

Can it detect deepfake videos?

It verifies Content Credentials and reads metadata in MP4 and QuickTime files, which is how signed or AI-labelled video is identified. Frame-by-frame deepfake analysis of unsigned video is a different and much harder problem, and the report is explicit about what was and was not checked.

Does my history sync between devices?

History is saved on the device where the check was made. One purchase unlocks Pro on all your devices, but reports stay local to each one - which is part of keeping the files private.

What is free and what is in Pro?

The free version verifies Content Credentials, reads metadata and keeps your recent reports. Pro adds AI detection, watermark scanning, JPEG forensics, batch checking, unlimited history and report export to PDF, CSV and JSON. Choose monthly, yearly with a free trial week, or a one-time lifetime purchase.

SourceCheck: Detect Fake Photos & Deepfake

Get SourceCheck: Detect Fake Photos & Deepfake

Check whether a photo came from a camera, an AI generator or an editor - C2PA verification, AI detection and metadata, all on the device.

How-to guides

How to check a photo in under a minute

The fastest useful routine, for a photo someone just sent you.

  1. Get the original file if you can - ask the sender to share it as a file rather than through a chat app that recompresses it.
  2. Open it in SourceCheck from Photos or Files, or drop it onto the window on Mac.
  3. Read the verdict, then the one-line explanation under it.
  4. If it says No Credentials, scroll to the metadata and AI signals rather than stopping there.
  5. Decide what the evidence supports, and write that down rather than "real" or "fake".

Screenshots destroy almost everything worth checking. If all you have is a screenshot, the most useful step is finding the original.

Try this in SourceCheck: Detect Fake Photos & Deepfake →

How to read a Content Credentials report

A C2PA report answers four separate questions. Take them one at a time.

  1. Content hash: does the file still match what was signed? A mismatch means something changed afterwards.
  2. Signed by and certificate issuer: who is vouching for this file?
  3. Trust chain: is that signer on the C2PA trust list, or could the certificate belong to anyone?
  4. Produced with: which camera, app or AI model created or last saved it.
  5. Edit history and ingredients: what was done to it, and which earlier files it was built from.

A valid chain proves who signed and that nothing changed since. It does not prove the scene was not staged before the shutter was pressed.

Try this in SourceCheck: Detect Fake Photos & Deepfake →

How to judge an image with no credentials

This is the common case. Build a picture from several weak signals rather than one strong one.

  1. Check the metadata: is there a camera model and capture date, or only a software field?
  2. Look at AI signals for generator traces in PNG chunks, software fields or IPTC source types.
  3. In Pro, run the AI classifier and note the score, remembering it is a hint.
  4. Run a reverse image search to find earlier copies, which often reveal the real origin.
  5. Weigh it all together, and be explicit about what remains unknown.

Metadata can be edited with free tools in seconds. Its presence is a lead; it is never proof on its own.

Try this in SourceCheck: Detect Fake Photos & Deepfake →

How to spot a local edit with error level analysis

ELA is good at one thing: finding a region that has a different compression history from the rest.

  1. Run JPEG forensics on the original JPEG, not a screenshot or a PNG conversion.
  2. Ignore bright edges and text first - they are bright in every image.
  3. Compare similar surfaces with each other: sky with sky, skin with skin, wall with wall.
  4. Look for a patch that is noticeably brighter or darker than matching content around it.
  5. Treat a suspicious region as a place to look closer, then check it against the original scene or other photos.

An image saved many times flattens out and shows nothing. A clean ELA result is not proof that no edit happened.

Try this in SourceCheck: Detect Fake Photos & Deepfake →

How to check a marketplace listing photo

Stolen, staged and generated product photos are the most common fakes people run into.

  1. Save the listing images at full size rather than screenshotting them.
  2. Check each one in SourceCheck and look for AI signals or an editing software field.
  3. Reverse-search the photos to see whether they appear on other listings or stock sites.
  4. Compare backgrounds, lighting and wear across all photos in the listing - they should agree.
  5. Ask the seller for one new photo with something specific in frame, such as a note with today's date.

Marketplaces usually strip metadata on upload, so No Credentials and empty EXIF are normal here and not suspicious by themselves.

Try this in SourceCheck: Detect Fake Photos & Deepfake →

How to batch-check a folder on Mac

Batch checking is part of Pro and suits moderators, researchers and newsrooms.

  1. Drag a folder or a selection of files onto the SourceCheck window.
  2. Let the batch run; each file gets its own verdict in history.
  3. Filter history by verdict to pull out Signature Invalid and AI-Generated results first.
  4. Open any report to see the evidence, using the keyboard to move between them.
  5. Export the results to CSV or JSON for a spreadsheet or your own tooling.

Each exported report includes the file's SHA-256, so results stay tied to the exact files that were checked.

Try this in SourceCheck: Detect Fake Photos & Deepfake →

How to keep a verification record

If a check might matter later, record it properly at the time.

  1. Check the file as you received it, before opening it in any editor.
  2. Note where and when you received it, outside the app.
  3. Export the report as PDF for people, or JSON for systems.
  4. Keep the original file alongside the report.
  5. If the file is questioned later, compare its SHA-256 with the one in the report.

Opening a photo in an editor and saving it changes the bytes and the hash. Always check and archive the untouched original.

Try this in SourceCheck: Detect Fake Photos & Deepfake →

How to explain a result to someone else

The verdict is not the message. The evidence is.

  1. Start with what was checked: credentials, metadata, AI signals, forensics.
  2. State what the evidence shows, in plain terms - for example, "signed by the camera and unchanged since".
  3. State what it does not show, such as whether the scene was staged.
  4. Share the exported report rather than a screenshot of the verdict.
  5. Avoid "fake" unless the evidence genuinely supports it.

Overclaiming is the fastest way to lose an argument about a real photo. "No evidence either way" is a legitimate result.

Try this in SourceCheck: Detect Fake Photos & Deepfake →

Related guides

Still need help?

Our support team usually replies within one business day.

Download SourceCheck: Detect Fake Photos & Deepfake Contact support