A PDF is not a picture of a page — it is a container with a history. Edits are usually appended rather than overwritten, which means the version before the edit is often still inside the file. Upload one here and see its saved revisions, the values an earlier revision carried, hidden and covered text, and the structural traces an edit leaves whether or not anyone meant to leave them.
You've used your free checks for today. Create a free account to keep going — it takes about thirty seconds.
Every appended revision still recoverable inside the file, with how many bytes each one added and which pages it touched — the document's own edit log, written by the format itself.
Where an earlier revision's text is still physically present, the previous value shown beside the current one, with the page it sits on and how it was reconstructed.
Text rendered invisibly, clipped off-page, or covered by a shape drawn over it — including optional-content layers that can be switched off, and what they were hiding.
Whether the pages are native digital text, a searchable scan, a pure raster capture, or a mix — derived from the pixels and the page tree, never from the Producer string.
Which revision each signature actually seals, and whether any bytes were appended after the range it covers — the difference between “signed” and “signed and then changed”.
The events the evidence supports, in order, with what each one is based on — observations separated from interpretation, and competing explanations kept on the table.
When you change a PDF and save, most software does not rewrite the document. It appends: the new version of each changed object goes on the end of the file, followed by a fresh cross-reference table pointing at the new objects instead of the old ones. The old objects are still there. They are simply no longer referenced.
This design exists for good reasons — it makes saving fast, and it is what lets a digital signature keep sealing the exact bytes it signed while later annotations pile up behind it. But it has a side effect that document examiners have relied on for twenty years: an appended edit leaves the pre-edit document inside the file.
So a PDF that was altered after issue frequently still contains the original amount, the original date, the original payee. Reconstructing the earlier cross-reference table and following it to the objects it pointed at is what “recovered values” means on this page. When it works, it is about as close to proof as document forensics gets: not an inference from a suspicious font, but the previous text, physically present, in the file the sender handed you.
Plenty of workflows fully rewrite the file — printing to PDF, flattening, running it through an optimizer, or exporting from a tool that always writes a fresh document. That destroys the appended history, and no amount of analysis brings it back. A file with one revision and no recoverable prior state is completely ordinary, and it is not evidence of anything.
That is why the result separates what was observed from what it might mean, keeps competing explanations visible, and reports what could not be checked instead of quietly scoring it as clean.
It cannot tell you a document is genuine. Structure is one layer of five, and it is silent about whether the invoice matches a real purchase order, whether the company on the letterhead exists, or whether the numbers add up. A structurally pristine PDF can be a complete fabrication produced in one pass by someone who never edited anything.
It also cannot tell you who made a change or why. Revisions carry no identity. An edit after signing might be fraud, or it might be the recipient adding an annotation — the evidence shows what happened to the bytes, and the judgement is yours.
Nothing is saved. The free tools hold your input for the length of the request and drop it with the response — no stored report, no archived file, no record of the URL, the message or the filename. The only thing we keep is an anonymous count so the daily allowance means something, and it is a number, not an identity.
Everything you see comes from deterministic analysis: public registration records, live DNS and TLS handshakes, header parsing and PDF structure. The same engines answer the same way whether or not you have an account.
Paste a link. Get registration age, DNS and mail records, the live certificate, security headers and a corroborated safety verdict.
Check a linkPaste the raw headers. Read SPF, DKIM and DMARC, walk the relay chain, and see the display-name and reply-to tricks behind most invoice fraud.
Read a headerSix checks that actually work, in the order an examiner runs them.
What a signature actually seals, and how to tell when something arrived later.
Why a black rectangle is not redaction, and what stays inside the file.
Sometimes, yes. PDFs are commonly saved by appending changes rather than rewriting the file, so the previous version's objects are often still physically present inside it. When that happens the earlier text can be reconstructed and shown next to the current value. When the file was fully rewritten, it cannot — and the tool says so rather than guessing.
No. Revisions are completely normal: signing a document adds one, filling a form adds one, annotating adds one. What matters is what changed and whether the change is consistent with the document's story. A one-revision file claiming years of amendments, or a signed contract with content added after the signature's coverage ends, are the shapes worth looking at.
Text that is present in the file but not visible when you read it — white on white, clipped outside the page, rendered in an invisible mode, or covered by a shape drawn on top. It has innocent causes, especially the invisible text layer scanners add so a scan is searchable. It also has an obvious dishonest use, which is why it is worth seeing.
No, and the difference matters. Metadata is what the file claims about itself, and it is trivially editable. This tool reads structure — the cross-reference tables, object generations, and appended revisions that the format itself creates. Structure is much harder to falsify because it is a side-effect of how the file was written, not a field anybody typed.
Because coverage is reported honestly. Encrypted files, unusual object structures and very large documents can put a check out of reach within the bounded time the free tool allows. Missing coverage is reported as missing — it never quietly becomes a clean result.
No. The file is analyzed in an isolated worker and discarded when the response is sent. It is never stored, never archived, and never used for anything else.
A free account runs the full forensic scan — metadata, content, images and cross-document intelligence — and keeps the report.