Blog How to Verify the Authenticity of a Document
Documentos Digitais · 4 min de leitura

How to Verify the Authenticity of a Document

A practical step-by-step guide to verifying whether a document is authentic, from traditional methods (notarization) to digital tools based on hashing and blockchain.

Jo

Josue Costa

Autor

How to Verify the Authenticity of a Document

How to Verify the Authenticity of a Document

Receiving a contract, a report, or a certificate and not being sure whether it's genuine is an uncomfortable situation — and an increasingly common one, since editing a PDF today takes seconds. Verifying a document's authenticity means confirming, with concrete evidence, that it is what it claims to be. Here's how to do it, from traditional methods to digital ones.

1. Check the document's origin

The first step is always confirming who sent the document and through which channel. Documents received via suspicious emails, shortened links, or unconfirmed sources deserve extra scrutiny, regardless of their content.

2. Look for formal authentication markers

Documents issued by institutions usually carry authenticity marks, such as:

  • A notary seal or stamp with a registration number.
  • A digital signature with a certificate (such as a qualified electronic signature).
  • A QR code or verification code linking to a public portal.
  • A protocol number that can be checked on the issuing body's website.

If the document claims to have one of these markers, the next step is confirming it directly at the source — never trust a stamp just by how it looks, since stamp images are easy to copy.

3. Compare against a reference copy, when one exists

If the document was registered before — for example, a contract you generated yourself and kept, or a certificate issued in duplicate by an institution — compare it byte-for-byte, or at least visually, with the original.

4. Use cryptographic verification (the most reliable method)

This is the method that solves the problem definitively, because it doesn't rely on "looking similar" — it relies on math. Here's how it works:

  1. A hash (a unique fingerprint) is generated from the exact content of the file, typically using the SHA-256 algorithm.
  2. That hash is compared against a hash registered earlier in an immutable location, such as a blockchain smart contract.
  3. If the two hashes match, the file is exactly the same — not a single letter, comma, image, or metadata field has changed. If even one character changes, the resulting hash is completely different.

In practice, with a platform like Attestify, this means:

  • You (or whoever received the document) go to the public verification page.
  • Upload the file, enter the certificate code, or scan the QR code.
  • The hash is recalculated directly in the browser — the file doesn't need to be sent to any server.
  • The system compares it against the hash registered on the Polygon blockchain and the RFC 3161 timestamp, and tells you whether the document is authentic and intact.

This process is free, public, and requires no sign-up — any interested party (a judge, a client, an accountant) can verify it independently.

5. Check the date and timestamp

Authenticity is also a matter of timing: a document can be genuine but created or modified on a different date than claimed. A trustworthy timestamp — like the RFC 3161 standard, signed by an external certification authority — proves when the document came to exist in that form, independently of whoever registered it.

6. Be wary of documents that resist verification

If an important document can't be verified through any means — no seal, no hash, no protocol, no timestamp — that doesn't prove it's fake, but it's a red flag. Documents with legal or financial weight should always have some verification mechanism available.

Quick summary

Method Reliability Ease of use
Visually checking seals and stamps Low (easy to forge) High
Confirming on issuer's portal Medium-high Medium
Cryptographic hash + blockchain verification Very high High (done in seconds)

Whenever possible, prefer methods that generate public, mathematical proof rather than relying solely on a document's appearance. That's exactly the role of tools like Attestify: registering a document's hash on the blockchain with an RFC 3161 timestamp, letting anyone confirm its authenticity in seconds, with legal validity.

Compartilhar: