How-to guideAug 18, 2026by Docurensic Team6 min read

When Was This Really Made? A Field Guide to Document Time

Documents carry more clocks than people expect — and fraud usually breaks at least one. Where timestamps live, which ones lie easily, and how to read them together.

When Was This Really Made? A Field Guide to Document Time
In this guide
  1. Key takeaways
  2. The clocks a document carries
  3. Reading clocks together
  4. Trusted time exists — use its absence too
  5. Time is where fakes are brittle

Almost every document fraud is, at bottom, a lie about time. The invoice claims to predate the audit. The contract claims to predate the dispute. The "scan from 2019" claims to predate last Tuesday. Which is convenient for the examiner, because documents are full of clocks — and a forger has to set every one of them consistently to sustain the lie. Most don't know half the clocks exist.

Key takeaways

The clocks a document carries

Declared dates — the date typed on the page. Fully attacker-controlled, worth nothing alone.

File metadata dates — creation and modification stamps in the PDF Info dictionary or Office properties. Editable with effort, but consumer editors update them automatically, which is how "issued January 2023, modified last week" contradictions land in files whose owners swear nothing was touched. The anatomy is the same one we mapped in metadata forensics.

Diagram: where a document's metadata and dates live
A document carries more clocks than the one printed on the page

Structural time — PDFs edited with incremental updates retain their prior versions in-file; each revision is a layer with its own stamps. XMP metadata can carry a whole edit-history chain. A single-revision file claiming a decade of annual amendments, or a five-revision file claiming to be an untouched original, are both telling stories the structure contradicts.

Embedded-object time — pasted images carry EXIF dates, embedded fonts carry versions with release dates, and generator strings map to software release windows. A "2015 scan" containing a photo whose camera model shipped in 2021 is done.

Content time — the deepest layer: reference numbers in formats the issuer adopted later, addresses that didn't exist yet, tax rates from the wrong year, a signatory who had left the company. No tool fully automates this one; domain knowledge does.

Reading clocks together

Single timestamps are weak evidence — clocks are wrong, scanners batch-process, migrations rewrite metadata innocently. The method is consistency analysis:

  1. List every timestamp the file carries, from declared date to deepest embedded object.
  2. Order them. Creation should precede modification; content events should precede file creation; embedded objects should predate or match assembly.
  3. Hunt impossibilities — the orderings that no innocent workflow produces. Modified-before-created. A signature dated after the "final" file it signs. A document created before the template it was built from was released.
  4. Weigh anomalies against workflow stories. "The scanner default-dates everything 2000-01-01" is a real thing; so is "we re-saved the archive during migration." An anomaly plus a story that checks out is noise. An anomaly plus a story that keeps changing is a finding.

Timezone offsets deserve special mention: PDF stamps carry them, and a document supposedly issued by a New York bank whose every timestamp sits in UTC+3 has some explaining to do.

Trusted time exists — use its absence too

Cryptographic timestamps from a time authority bind a document hash to a moment in a way forgers can't backdate; national metrology labs anchor the underlying time infrastructure (nist.gov). High-stakes workflows (signed contracts, filings) increasingly carry them. That cuts both ways for the examiner: a trusted timestamp settles the question, and the absence of one — on a document from a counterparty whose systems normally apply them — is a quiet anomaly of its own.

Time is where fakes are brittle

A careful forger can match fonts and clone a letterhead. Matching every clock — metadata, structure, embedded objects, content references, timezone offsets — against a fabricated history is a different order of difficulty, which is why timestamp contradiction remains one of the highest-yield checks in document forensics. It's also tedious to do by hand, and tedium is what machines are for: an automated forensic scan reads every clock in the file in one pass and surfaces exactly the impossible orderings a human would have found on hour three.

Check the PDF you are holding

Run a free PDF X-Ray in your browser — it recovers text from the file’s earlier revisions, so you can see what a value was before it was changed. No account needed.

Open the free PDF X-Ray

Keep reading

How-to guideAug 17, 20269 min

The Free Document Forensics Toolkit

ExifTool, pdfid, qpdf, mutool, FotoForensics and the rest — what you can genuinely establish about a suspicious document with software that costs nothing, in what order, and the four things free tooling cannot do.

How-to guideJul 06, 20264 min

PDF Metadata: What It Reveals and How to Read It

Every PDF carries two hidden records about where it came from. Here's how to read the Info dictionary and the XMP packet, what each field means, and the disagreement that exposes tampering.