Image Verification Workbench — Check if a Photo Is Real

Last updated:

Image Verification Workbench

Case — · · Not saved yet

🔒 Runs in this tab. The image is not uploaded; the case is saved only in this browser.

1 · Intake — the file and where you found it

🖼️ Drop the image here, paste it (Ctrl/⌘+V) or press to choose a file
JPEG, PNG, WebP, GIF, AVIF/HEIC where your browser decodes them. Save the image from the post at the largest size available.
Fetch asks that host for the file (sends a normal request; many hosts block it).

How do you check if a photo is real? To check whether a photo is real, work through seven steps and record each one: hash the exact file you received, look for C2PA Content Credentials, read the metadata, find the earliest copy online, run forensic tests, test the scene against the claimed place and time, and only then write a conclusion. This workbench runs all seven in your browser, using the same engines as our Photo Forensics Studio and C2PA Inspector, and produces one evidence report. Most images that circulate with a false claim are genuine pictures with a wrong caption, so the earliest copy and the context usually decide the case; pixel forensics rarely does on its own.

How do you verify an image found on social media?

Start by keeping the exact file and a record of where it came from: the post URL, the account, when you found it and what it claims. Then move from the cheap, decisive checks to the expensive, uncertain ones. Reverse image search and an archive check come early because a recycled picture with a new caption is common and quick to expose. The InVID-WeVerify plugin, maintained by AFP Medialab, bundles this kind of reverse search for journalists InVID project (2019); WeVerify (Sep 2021). Geolocation and chronolocation test the claim itself: Eliot Higgins describes comparing “the position of the minaret, the dome and a nearby wall” with satellite imagery, and using SunCalc to put a scene at about 12:30 local time Verification Handbook (2015). Forensic analysis of the pixels comes later, as one input among several.

What does each step prove — and what can’t it?

StepWhat it checksWhat it can proveWhat it can’t
1. IntakeWhere and when you found it, who posted it, what it claims; SHA-256 and pHash of the fileThat every later check refers to this exact file; pHash finds resized near-copiesAnything about whether the image is genuine — a hash of a fake is still a hash
2. Provenance (C2PA)Embedded Content Credentials: signature, content hash, signer, declared edits and AI source typeIf valid: the file is unchanged since the signer signed it, and what the signer declaredThat the scene is true; who the signer really is (trust list not checked here); absence proves nothing
3. MetadataCamera, software, timestamps and offsets, GPS (south/west handled), stripped EXIFContradictions worth chasing (editor signature, date far from the claim)Metadata is editable, and most social uploads have none
4. Earliest copyReverse image search in URL or upload mode, archive check of the post, a log of copies with datesAn earlier copy with a different date or place disproves the claimed contextNot finding one does not prove this is the original
5. ForensicsELA, JPEG ghost, copy-move, noise, gradient, bit planes, thumbnail checkTwo or more independent methods agreeing on one region is strong evidence of editingA clean result is not authenticity; recompression erases traces; no reliable AI detector
6. ContextPlace, shadows and weather, language of signs, landmarks, the posterSeveral permanent features matched to imagery place the cameraCareful staging; shadow timing is approximate
7. ConclusionOne of four verdicts plus a written summaryA documented, repeatable chain of reasoningMore certainty than the weakest step supports

Which results are proof and which are only signals?

Forensic best practice is explicit that no single test decides a case: the SWGDE video-authentication guidance says “nor shall any single analysis be individually relied upon” SWGDE 23-V-001 (Mar 2024). The workbench therefore keeps three classes apart. Proof-grade results settle one question: a C2PA hard binding lets a validator ensure “that the asset has not been modified” since signing C2PA spec 2.4 (Apr 2026); an earlier copy with a different date disproves the claimed context; several permanent features matched to imagery place the camera. Signals are leads: forensic hot spots, editing-software tags, timestamps, weather that fits. No signal is the commonest outcome: no metadata and no credential. The C2PA specification itself says it should not judge whether provenance data is “good” or “bad” C2PA spec 2.4 (Apr 2026), so a valid credential tells you who signed the file and what they declared, not whether the scene is true.

Why is EXIF missing from most social media photos?

Platforms generally do not keep the file you upload. Magnet Forensics describes the process as “the creation of new media files, not the retention of a submitted file with deleted data”, and notes that tags such as GPS coordinates and software versions may be left out of the new file Magnet Forensics (2 Jan 2024). So an image saved from a post usually has no camera, time or GPS data, and that absence says nothing about authenticity. When metadata is present, the workbench flags an editor in the Software tag, a capture date far from the claimed date, camera and GPS clocks that disagree, and missing time-zone offsets; south and west coordinates are converted to negative decimals before they are mapped.

How do you check the time and place a photo claims?

Shadows give the sun’s direction and height, which can be compared with the sun’s position for the claimed place and time; Bellingcat has also run the method in reverse, using a known time to work out where a camera stood Bellingcat (3 Dec 2020). When there is no sun, things that change over time — banners, scaffolding, shopfronts — can narrow a date Bellingcat (8 May 2023). The workbench passes GPS coordinates to Geolocation OSINT, can fetch the recorded weather for a place and hour from Open-Meteo if you choose to, and links to Weather Chronolocation for weather-widget screenshots.

Is anything uploaded?

No. The page hashes and analyses the file in your browser with the same engines as the Photo Forensics Studio and the C2PA Inspector. The case lives in this browser’s local storage until you export it. Only actions you click contact another site, and each says so beside its button: fetching an image URL, the weather lookup, and reverse-search or archive links. For a trust-list-backed credential verdict you can upload the file yourself to Content Credentials Verify Content Credentials Verify.

Image verification — frequently asked questions

How do I check if a photo is real?

Work in order: hash the file, check for C2PA Content Credentials, read the metadata, search for the earliest copy, run forensic tests, then test the scene against the claimed place and time and write a conclusion. Most misleading images are real photos with a false caption, so the earliest copy and the context checks decide more cases than pixel analysis does.

Is my image uploaded anywhere?

No. Hashing, the C2PA check, metadata reading and the forensic passes run in your browser and the image is not uploaded. Only three optional actions contact another site, each when you click it: fetching an image URL you typed, the Open-Meteo weather lookup (sends coordinates and a date), and reverse-search or archive links (send the URL to that service).

Why does the photo have no EXIF data?

Images downloaded from social networks and messaging apps usually have no camera, time or GPS tags because the platform creates a new file when you upload. Missing EXIF is normal for a reposted image and is not a sign of manipulation; it simply means metadata cannot help with that copy.

What does a valid C2PA Content Credentials result mean?

It means the manifest signature verifies and the file has not changed since it was signed, so the declared creator tool, edits and AI source type are what the signer recorded. It does not prove the scene is true, and this tool does not check the signer against the C2PA trust list; use the official verifier for that. No credential proves nothing, because most cameras and platforms do not add or keep one.

Can this tool tell if an image is AI-generated?

Only from evidence the file carries: a C2PA or IPTC digital source type that declares algorithmic or AI media, generator tags, or a near-zero noise floor. There is no reliable pixel-level detector for modern generators, so a missing marker does not mean the image is real.

What is the difference between proof and a signal?

Proof settles a question on its own: a valid credential ties the file to its signer, an earlier copy with a different date disproves the claimed context, and several permanent features matched to imagery place the camera. Signals are leads: forensic hot spots, editing-software tags, timestamps, or weather that fits. A conclusion needs proof or several independent signals pointing the same way.

How do I find the earliest copy of an image?

Run reverse image searches on several engines, because each indexes different sites, sort results by date where the engine allows it, and check the post URL in the Wayback Machine. Record every copy with its date; the workbench marks the earliest and compares it with the claimed date. Not finding an older copy does not prove the one you have is the original.

Can I save a case and continue later or share the report?

Yes. The case is saved automatically in this browser, and you can export it as JSON and import it later or on another computer. The image itself is not stored, so re-attach the same file to re-run automatic checks; its SHA-256 is compared with the record. The report prints to PDF and can be copied as a Markdown summary.

Sources

Engines: forensic passes and metadata from the Max Intel forensics engine (methods & limitations); C2PA parsing and verification from the Max Intel C2PA Inspector engine; recorded weather from Open-Meteo when you request it.