When Was This Really Made? A Field Guide to Document Time
Documents carry more clocks than people expect — and fraud usually breaks at least one. Where timestamps live, which ones lie easily, and how to read them together.

Almost every document fraud is, at bottom, a lie about time. The invoice claims to predate the audit. The contract claims to predate the dispute. The "scan from 2019" claims to predate last Tuesday. Which is convenient for the examiner, because documents are full of clocks — and a forger has to set every one of them consistently to sustain the lie. Most don't know half the clocks exist.
Key takeaways
- A document's claimed date is one timestamp among many: file metadata, internal structure, embedded objects, and content each carry their own clocks.
- Forgers reliably fix the visible date and miss the invisible ones — modification stamps, XMP history, embedded-image dates, timezone offsets.
- Impossibilities are the gold standard: modified-before-created, content referencing events after the claimed date, fonts or software that postdate it.
- Trusted time exists — signed timestamps from a time authority — and its absence from a document that "needed" it is itself informative.
The clocks a document carries
Declared dates — the date typed on the page. Fully attacker-controlled, worth nothing alone.
File metadata dates — creation and modification stamps in the PDF Info dictionary or Office properties. Editable with effort, but consumer editors update them automatically, which is how "issued January 2023, modified last week" contradictions land in files whose owners swear nothing was touched. The anatomy is the same one we mapped in metadata forensics.
Structural time — PDFs edited with incremental updates retain their prior versions in-file; each revision is a layer with its own stamps. XMP metadata can carry a whole edit-history chain. A single-revision file claiming a decade of annual amendments, or a five-revision file claiming to be an untouched original, are both telling stories the structure contradicts.
Embedded-object time — pasted images carry EXIF dates, embedded fonts carry versions with release dates, and generator strings map to software release windows. A "2015 scan" containing a photo whose camera model shipped in 2021 is done.
Content time — the deepest layer: reference numbers in formats the issuer adopted later, addresses that didn't exist yet, tax rates from the wrong year, a signatory who had left the company. No tool fully automates this one; domain knowledge does.
Reading clocks together
Single timestamps are weak evidence — clocks are wrong, scanners batch-process, migrations rewrite metadata innocently. The method is consistency analysis:
- List every timestamp the file carries, from declared date to deepest embedded object.
- Order them. Creation should precede modification; content events should precede file creation; embedded objects should predate or match assembly.
- Hunt impossibilities — the orderings that no innocent workflow produces. Modified-before-created. A signature dated after the "final" file it signs. A document created before the template it was built from was released.
- Weigh anomalies against workflow stories. "The scanner default-dates everything 2000-01-01" is a real thing; so is "we re-saved the archive during migration." An anomaly plus a story that checks out is noise. An anomaly plus a story that keeps changing is a finding.
Timezone offsets deserve special mention: PDF stamps carry them, and a document supposedly issued by a New York bank whose every timestamp sits in UTC+3 has some explaining to do.
Trusted time exists — use its absence too
Cryptographic timestamps from a time authority bind a document hash to a moment in a way forgers can't backdate; national metrology labs anchor the underlying time infrastructure (nist.gov). High-stakes workflows (signed contracts, filings) increasingly carry them. That cuts both ways for the examiner: a trusted timestamp settles the question, and the absence of one — on a document from a counterparty whose systems normally apply them — is a quiet anomaly of its own.
Time is where fakes are brittle
A careful forger can match fonts and clone a letterhead. Matching every clock — metadata, structure, embedded objects, content references, timezone offsets — against a fabricated history is a different order of difficulty, which is why timestamp contradiction remains one of the highest-yield checks in document forensics. It's also tedious to do by hand, and tedium is what machines are for: an automated forensic scan reads every clock in the file in one pass and surfaces exactly the impossible orderings a human would have found on hour three.
Check the PDF you are holding
Run a free PDF X-Ray in your browser — it recovers text from the file’s earlier revisions, so you can see what a value was before it was changed. No account needed.
Keep reading
The Free Document Forensics Toolkit
ExifTool, pdfid, qpdf, mutool, FotoForensics and the rest — what you can genuinely establish about a suspicious document with software that costs nothing, in what order, and the four things free tooling cannot do.
How to Tell if a PDF Has Been Edited: 6 Checks That Actually Work
Six practical checks — from metadata dates to hidden revision history — that reveal whether a PDF was modified after it was created, and what each one can and can't prove.
PDF Metadata: What It Reveals and How to Read It
Every PDF carries two hidden records about where it came from. Here's how to read the Info dictionary and the XMP packet, what each field means, and the disagreement that exposes tampering.