What does verifying a video mean in 2026?

Verifying a video means answering three separate questions: is this file the one I think it is (integrity), where and when did it first appear and what did it originally show (provenance and context), and have the pixels or the audio been generated or altered (authenticity). In 2026 each question has new tools. Provenance has a cryptographic layer: C2PA Content Credentials version 2.4 (April 2026) defines how a signed manifest is bound to an MP4, and Sony's PXW-Z300 camcorder signs video at capture C2PA spec 2.4 (Apr 2026); CAI (18 Jan 2026). Platforms read those credentials: YouTube's "Captured with a camera" disclosure covers unedited footage from C2PA 2.1-or-later devices, and TikTok auto-labels AI content from Content Credentials YouTube Help, camera disclosure (read Oct 2026); TikTok Newsroom (9 May 2024). Generators mark their output: SynthID sits in every frame of Veo video and can be checked in the Gemini app, and Sora embedded C2PA metadata and a visible watermark until it was withdrawn on 26 April 2026 DeepMind (14 May 2024); Google (18 Dec 2025); OpenAI (30 Sep 2025).

None of that replaces the older craft. Most misleading videos are real footage with a false caption, caught fastest by reverse-searching keyframes; most files have been through a platform re-encode that strips metadata and credentials, so absence of a signal is normal for a genuine clip; and detectors that score "fake probability" lost roughly half their discriminative power on deepfakes actually circulating in 2024 Deepfake-Eval-2024, arXiv (Mar 2025). This guide takes each layer in turn, says what it can and cannot prove, and ends with a twelve-step workflow and a worked example.

2.4C2PA specification version, April 2026, with MP4 box-hash bindings
2.1+C2PA version YouTube requires for its "Captured with a camera" disclosure
−50%AUC drop for open-source video deepfake detectors on in-the-wild 2024 clips
90 sMaximum clip length the Gemini app will check for SynthID
2 Aug 2026EU AI Act Article 50 marking and deepfake-disclosure duties enforceable
25.4%Detector accuracy lost when a deepfake is re-filmed off a screen (Moiré)

Video verification at a glance

StepTool (free unless noted)What it can establishWhat it cannot
Hash the fileVideo Forensics Studio, Evidence Logger, sha256sumThat the file you analysed is the file you received; lets anyone re-check laterAnything about authenticity; a hash of a fake is still a hash
Check provenanceContent Credentials Verify, YouTube/TikTok labels, the studio's C2PA-box checkA valid credential ties the file to a signer and records declared edits or AI useAbsence proves nothing; most platforms re-encode and drop the manifest
Check for a watermarkGemini app (SynthID), SynthID Detector portalWhether Google AI produced or edited part of the clip (segments reported)Non-Google generators; clips cropped from the original; it is one vendor's marker
Find the earliest copyInVID-WeVerify keyframes + Google Lens / Yandex / BingEarlier uploads, original context, a different caption or dateA clip with no prior online life (fresh footage and fresh fakes both return nothing)
Read the containerffprobe, MediaInfo, the studio's container auditWhich software wrote the file, when, codecs, edit lists, device and GPS atoms if presentFields are editable and usually rewritten by platforms
Temporal and frame checksVideo Forensics Studio (frame difference, motion, flicker, duplicates; per-frame ELA/noise/grid)Where to look: cuts, inserted or frozen frames, a frame that differs from its neighboursProof of editing or of authenticity; compression erases traces
AI detector scoreStudio optional on-device model; commercial servicesA second opinion on sampled framesA verdict; in-the-wild accuracy is far below benchmark figures
GeolocateGeolocation OSINT, satellite and street imageryWhere the camera stood, by matching fixed featuresWhen it was filmed, or who filmed it
ChronolocateSunCalc-style shadow tools, Weather Chronolocation, Street View historyA date or time window consistent with shadows, weather, signageAn exact timestamp; needs daylight or datable features
Audio checksAudio Transcriber, AI Voice Detection, Voice Print MatcherWhat is said, whether the voice resembles a reference speaker, synthetic-speech leadsSpeaker identity as legal proof; detector scores are leads
DocumentReport Builder, studio PDF/JSON reportA reproducible record of hashes, findings and sourcesNothing by itself; it records the work

Which signals are proof and which are only leads?

The single most useful habit in video verification is to sort every observation into "proof", "lead" or "noise" before you write a conclusion. The forensic community's own guidance is blunt about it: the SWGDE best-practice document for digital video authentication says that "not all tests will be applicable in each case, nor shall any single analysis be individually relied upon", and asks examiners to evaluate a file's originality before any other analysis SWGDE 23-V-001 (Mar 2024). The table ranks the common observations.

ObservationSignal strengthWhy
Valid C2PA manifest signed by a camera maker, pixels unchanged since signingStrong positiveCryptographic binding to a signer and to the content; still check who the signer is and what the manifest declares
Earlier copy of the same footage found online with a different date or placeStrong negative for the claimed contextRecycled footage is the most common "fake video"; the pixels may be real but the caption is not
SynthID or C2PA record that says "generated by AI"Strong that AI was involvedA positive marker from the generator itself; the clip may still contain real material
Shadows, weather, signage and landmarks all agree with the claimed place and timeModerate positiveHard to fake consistently, but a careful fabricator can stage them
FFmpeg or editor encoder string, zeroed timestamps, missing audio trackWeakSays the file was re-written by software, which every platform download also does
Spike in frame-to-frame difference; run of duplicate framesWeakScene cuts, fast motion and tripod shots produce the same patterns
Per-frame ELA or noise hot spotWeakVideo compression is harsher than JPEG; edges and text glow regardless
AI detector says 80% fakeWeak aloneOpen-source video detectors lost about half their AUC on 2024 in-the-wild deepfakes
No metadata, no credential, no watermarkNo signalThis is what almost every real video looks like after one platform round-trip

Two consequences follow. A positive provenance record (a valid credential, a generator's watermark, an earlier copy) outweighs any number of pixel-level anomalies, because it is a statement by someone who was there rather than an inference from compression artefacts. And the only honest conclusion from a clean, metadata-free, detector-neutral file is "no evidence either way".

How do C2PA Content Credentials work for video?

A Content Credential is a signed manifest that records who created a file, with what, and which edits were applied. The C2PA 2.4 specification (April 2026) handles video through the ISO Base Media File Format: for a monolithic MP4 "a hard binding optimized for the box-based format (called BMFF-based hash assertions) may be used instead" of a byte-range hash, fragmented MP4 carries chunk-specific hashing, and a separate chapter covers live video segments C2PA spec 2.4 (Apr 2026). If any hashed box changes after signing, validation fails. The Content Authenticity Initiative counted more than 6,000 members and a Conformance Program in January 2026 and singled out "the release of Sony's PXW-Z300 video camera, which brings Content Credentials directly into high-end video capture" CAI (18 Jan 2026).

On the capture side, Sony says its cameras "can now embed C2PA provenance into both image and video files"; the PXW-Z300 is joined by the Alpha 1 II, Alpha 9 III, FX3 and FX30, with the Alpha 7R V, Alpha 7 IV, Alpha 1 and Alpha 7S III scheduled later, and Sony's verification service for news organisations is paid and adds proprietary 3D-depth metadata on top of the C2PA signature Sony Professional (read Oct 2026); Newsshooter (30 Oct 2025). Sony also notes that its free default certificate "does not guarantee the validity of the C2PA signature", so the signer's certificate matters as much as the presence of a manifest Sony Professional (read Oct 2026).

On the platform side, YouTube places a "Captured with a camera" line in the "How this content was made" section of the expanded description when the upload carries metadata from "tools with built-in C2PA support (version 2.1 or higher)" and "must also not have edits to sound or visuals"; YouTube adds that "if it's missing, it doesn't mean the content has modified audio or visuals" YouTube Help, camera disclosure (read Oct 2026); YouTube Help, disclosures (read Oct 2026). The label was introduced in October 2024 Gigazine (16 Oct 2024). TikTok announced in May 2024 that it was "becoming the first video sharing platform to implement their Content Credentials technology", using the metadata to label AI-generated content made elsewhere and attaching credentials to downloaded TikTok videos TikTok Newsroom (9 May 2024).

How to check. Upload the original file to the official verifier at verify.contentauthenticity.org, or, for Google's implementation, to the Gemini app, which the help page says offers Content Credentials verification on the web and Android Gemini Help (read Oct 2026). Our Video Forensics Studio reports whether an MP4 contains a C2PA box but does not validate the signature chain, which needs the trust list; the C2PA and AI provenance hub explains what a valid, invalid or missing result means. The limit is structural: a screen recording, a messaging-app forward or a platform re-encode produces a new file with no manifest at all.

Can you detect AI-generated video from SynthID or Sora marks?

Sometimes, and only for the generators that mark their output. Google DeepMind's SynthID for video "builds upon our image and audio watermarking method to include all frames in generated videos", embedding "a watermark directly into the pixels of every video frame"; all Veo output on VideoFX has been watermarked since May 2024 DeepMind (14 May 2024). Google says the video watermark "is designed to stand up to modifications like cropping, adding filters, changing frame rates, or lossy compression", launched a SynthID Detector portal in 2025 that is expanding "to everyone", and says the detector covers partners "including OpenAI, NVIDIA, Kakao, and soon, Apple" DeepMind SynthID (read Oct 2026). The practical route is the Gemini app: upload a clip (100 MB or less, under 90 seconds, about ten video checks per 24 hours) and ask "Is this AI-generated?"; the answer names the segments where a watermark was found, for example in the audio but not the visuals Gemini Help (read Oct 2026); Google (18 Dec 2025). The help page is explicit that "Gemini can currently only recognize content created by Google AI tools", so a negative result rules out one family of generators, not AI Gemini Help (read Oct 2026).

OpenAI's Sora took the belt-and-braces approach: "every video generated with Sora includes both visible and invisible provenance signals", "at launch, all outputs carry a visible watermark", and "all Sora videos also embed C2PA metadata" OpenAI (30 Sep 2025). Within a week of the Sora 2 launch, 404 Media found half a dozen sites that "seamlessly removed the watermark from the video in a matter of seconds" 404 Media (7 Oct 2025). The product itself is now history: OpenAI announced on 24 March 2026 that it was "saying goodbye to the Sora app", the app closed on 26 April 2026 and the API was scheduled to follow on 24 September 2026 TechCrunch (24 Mar 2026); Wikipedia, Sora (Oct 2026); OpenAI (30 Sep 2025). Clips from late 2025 and early 2026 still circulate, so the moving Sora watermark and its manifest remain worth looking for, and their absence worth nothing.

Regulation is pushing more generators to mark output. Under Article 50 of the EU AI Act, providers of generative systems must ensure outputs are "marked in a machine-readable format" and deployers must disclose deepfakes; the obligations became enforceable on 2 August 2026, systems already on the market have until 2 December 2026 for the marking duty, and the Commission's transparency Code of Practice combines signed metadata with imperceptible watermarking Faegre Drinker (30 Jul 2026). More clips will carry a marker over time; a marker is still a vendor statement that can be stripped, and a clean clip from a non-compliant tool looks like any other.

Reverse search is the step that catches the most fakes for the least effort, because the commonest manipulation is an old video with a new caption. Search engines index images, not video, so you search frames. The InVID-WeVerify browser plugin automates this: its Keyframes tab takes a YouTube, Twitter, Facebook, Dailymotion or Dropbox link, or an uploaded file, and segments it into "the real video keyframes that differ from the thumbnails served by Youtube or Facebook"; a left click searches a keyframe on Google and a right-click menu offers Yandex, TinEye, Bing and Baidu InVID project (2019); Amnesty Citizen Evidence Lab (11 Dec 2019). AFP Medialab maintains it (version 0.75, September 2021; Chrome, Edge and Opera), and some advanced tools call external servers and require registration WeVerify (Sep 2021). The Amnesty Evidence Lab's walkthrough notes that the YouTube Thumbnails tab, which fires the four YouTube thumbnails at Google, Bing, TinEye and Yandex in parallel, "is very fast and efficient if a user needs to find out whether a YouTube video has been published before" Amnesty Citizen Evidence Lab (11 Dec 2019).

Without the plugin, export frames yourself (our studio's "Export this frame" button saves a native-resolution PNG with its SHA-256; ffmpeg can dump keyframes) and use each engine's own image-search entry point. Google's help page describes clicking the Search-by-image icon and either uploading a file or pasting a URL in the "Paste image link" field Google Search Help (read Oct 2026). Yandex's help page says to click the image-search button, then drag a file, pick one, paste from the clipboard, or "enter the image address in the search bar and click Search", and its results show "which sites have the same image" and other sizes Yandex Help (read Oct 2026). Bing Visual Search accepts "Paste image or URL", drag-and-drop or a photo Microsoft Bing (read Oct 2026). Search several distinctive frames, not the title card. In our experience Yandex is stronger for faces and for Eastern European sources and Google Lens for objects and places (a practitioner's note, not a measured result). Record the earliest dated hit, the uploader and the caption, then compare them with the claim.

This proves that the footage existed earlier, elsewhere or in another context. It cannot prove that a clip with no hits is new or genuine: fresh footage and a fresh fake both return nothing, and a mirrored or cropped copy can defeat exact-feature matching. Our Video OSINT page collects the download, frame and platform pivots used in this step.

What does container metadata tell you about a video file?

A video file is a container (MP4, MOV, WebM, MKV) wrapped around compressed streams, and the container records how it was written. ffprobe "gathers information from multimedia streams and prints it in human- and machine-readable fashion"; -show_format prints the container, -show_streams each stream, -show_frames per-frame data, and -output_format json gives a parseable record for your report FFmpeg docs (read Oct 2026). MediaInfo presents "a convenient unified display of the most relevant technical and tag data for video and audio files", including writing application and library, format profile and date, on every desktop and mobile platform under a BSD-style licence MediaArea (read Oct 2026). The atoms a phone writes differ from those written by editors, messaging apps and social networks, which is the basis of container-structure analysis to "detect possible attacks against MP4, MOV, and 3GP format videos that affect their integrity and authenticity" arXiv 2402.06661 (Feb 2024); Magnet Verify productises the idea with a signature database (see the software comparison).

The Video Forensics Studio reads the same bytes in the browser and turns them into findings in plain language. For MP4/MOV it parses the ftyp brand, mvhd creation and modification times, per-track tkhd and mdhd, stsd codecs, stts frame timing, stss keyframes, elst edit lists, udta/ilst tags (the ©too encoder string, ©xyz GPS, device make and model), the XMP and C2PA boxes and the top-level box order; for WebM/Matroska the Info, Tracks and Tags elements. It flags encoder strings that match editors, platforms and generative-video services, zeroed (1904) timestamps, fast-start layout, fragmented files, edit lists, irregular frame timing, missing audio and video/audio length mismatches, as documented on the methods page. Each is reported as a lead with its usual explanation, never as a verdict.

What metadata can prove is bounded by one fact: every platform re-encodes. Magnet Forensics traced a YouTube upload through "a new HEVC video encoded into a MOV container" and then a lower-resolution AVC streaming copy, the one a downloader fetches; platforms "do not delete specific metadata values" but write new files in which GPS and software versions are gone and an encoder tag is added Magnet Forensics (2 Jan 2024). So a transcoder string on a downloaded clip is expected, a phone make and GPS atom on one is odd, and only a camera-original file with intact device atoms, consistent timestamps and a C2PA manifest lets metadata support authenticity. Ask for the original.

What can temporal and frame artefacts prove?

Video has a dimension a photo lacks: time. Edits that are invisible in any one frame leave a rhythm break across frames. The studio samples 24, 48 or 96 frames at even intervals and plots four things: mean absolute luminance difference between consecutive samples (spikes beyond mean + 2.5 standard deviations are flagged as possible cuts or inserts), block-matching motion magnitude (8 px blocks, ±2 px search; spikes as possible warps), mean luminance over time (flicker in relit or synthesised regions), and near-duplicate frames (mean difference below 1.2; runs flagged as frozen or looped). On any frame the charts single out, it runs the per-frame passes shared with the Photo Forensics Studio: Error Level Analysis at a chosen quality, a Laplacian noise residual and 8×8 block-grid energy, all documented with thresholds on the methods page.

What these can prove is narrow and useful: that something changes at a particular moment, and roughly where in the frame. An inserted shot shows as a difference spike without a motion spike; a looped crowd as duplicate runs far apart; a face-swap often as motion and flicker anomalies confined to one region, which the per-frame noise map localises. What they cannot prove is editing or authenticity: cuts, pans and auto-exposure produce the same spikes, tripod shots duplicate frames naturally, and platform-bitrate compression erases or invents ELA and noise differences, which is why the methods page labels the per-frame passes "supporting context only". The studio is sampled, not frame-accurate, and sees decoded frames only, so a single inserted frame between samples and codec-level traces (GOP structure, quantisation, motion vectors, double-compression signatures) are out of reach; those need Amped FIVE-class desktop tools.

The optional AI detector deserves its own warning. Deepfake-Eval-2024, a benchmark of 45 hours of video, 56.5 hours of audio and 1,975 images actually circulated in 2024, found open-source detectors' "AUC decreasing by 50% for video" compared with academic benchmarks, and that commercial models, while better, "do not yet reach the accuracy of deepfake forensic analysts" Deepfake-Eval-2024, arXiv (Mar 2025). A second study found that simply re-filming a deepfake from a screen, which adds Moiré patterns, "degrade[s] performance by as much as 25.4%", and that the obvious fix, demoiréing, made things worse arXiv 2510.23225 (Oct 2025). The studio's detector is off by default, runs on your device, and is reported as one voice among several for exactly these reasons.

How do you geolocate and chronolocate a video?

If the footage is real, the next question is whether it shows the place and time claimed. Geolocation matches fixed features (a minaret, a road junction, a skyline, a shop sign) against satellite, aerial and street-level imagery; Eliot Higgins' account of verifying Libyan and Ukrainian footage describes matching "a mosque's minaret, dome, and a nearby wall to satellite imagery" and mapping the street pattern of a town from a clip Verification Handbook (2015). Video helps because the camera moves: pause at several points, note every permanent feature and sketch their relative positions before opening a map. Our Geolocation OSINT page turns coordinates or a place into pre-filled pivots across more than twenty mapping, satellite and street-view services, and the geolocation guide covers the method in depth.

Chronolocation fixes the time. Shadows are the classic cue: with a candidate location and date, SunCalc gives the sun's azimuth and elevation, so shadow direction and length either fit the claimed time or do not; Higgins used it to put a Buk launcher in Torez at about 12:30 local time Verification Handbook (2015), and Bellingcat's Youri van der Weide inverted the method, using a known time and the sun's position over the sea to work out which way a camera faced and so where in Lisbon it stood Bellingcat (3 Dec 2020). Where there is no sun, "any aspect of a source image could be of use, provided that it has changed over time": banners, scaffolding, graffiti and shopfronts, dated against Street View history, event calendars and archived posts, narrowed one Istanbul photo to a three-week window in 2016 Bellingcat (8 May 2023). Weather is a third cue: rain, snow, wet ground or an on-screen weather widget can be compared with recorded conditions, and our Weather Chronolocation tool ranks major cities whose recorded weather matched a given temperature and local time, using the Open-Meteo archive back to 1940. These checks prove consistency, not identity: treat agreement as a moderate positive and disagreement as a strong lead.

What should you check in the audio track?

Audio is edited more often than pixels, and is checked less often. Start by establishing what is said: the Audio and Video Transcriber runs Whisper in the browser and produces a timestamped transcript with speaker separation, so you can quote accurately and search for earlier uses of the same sentences. Then ask whether the voice is who it is said to be: the Voice Print Matcher compares two clips with a speaker-embedding model and returns a same-speaker similarity score, which is a useful lead and not an identification. Then ask whether the speech is synthetic: the AI Voice Detection hub collects the techniques and services for spotting generated speech, with the same caveat that applies to video detectors: Deepfake-Eval-2024 found open-source audio detectors fell to near-chance on in-the-wild 2024 clips Deepfake-Eval-2024, arXiv (Mar 2025).

Two structural checks cost nothing. Does the audio belong to the video? Lips that lead or lag speech, acoustics that do not match the visible room, and ambience that does not change when the camera turns suggest a replaced track; the studio flags a missing audio track and a video/audio length mismatch. And does the Gemini SynthID check find a watermark in the audio but not the visuals, as Google's own example shows? A real video with a generated voice-over is one of the commonest hybrid fakes Google (18 Dec 2025).

How do you hash a video and keep a chain of custody?

Before any analysis, compute a cryptographic hash of the exact bytes you received and write it down with the time, the source URL or sender, and how you obtained the file. The Video Forensics Studio computes SHA-256, SHA-1 and MD5 before it decodes anything, prints them on the report, and records the SHA-256 of every frame you export so an exported PNG can be tied back to this examination. The Evidence Logger keeps the running record: each entry carries a timestamp and a SHA-256, entries are chained so that an altered log can be detected with its Verify function, and the log exports as Markdown, CSV or JSON. The Report Builder assembles findings and sources into a shareable document. SWGDE's guidance adds a useful refinement: because platforms transcode, a hash of the decoded stream can be compared between a questioned file and a claimed duplicate even when the container hashes differ SWGDE 23-V-001 (Mar 2024).

Hashing proves identity, not authenticity: it lets a second examiner confirm they have the same file and shows your exhibit was not altered after logging. It is the step that makes the rest reproducible, which is why it comes first in the workflow.

What are the known limits of video verification?

  • Recompression erases traces. Re-encoded frames "will look very similar to the original video, but they are not exact duplicates" Magnet Forensics (2 Jan 2024); ELA, noise and grid analysis on a twice-compressed clip measure the last encoder, not the edit.
  • Platform re-encoding strips metadata and credentials. GPS, device atoms, software versions and C2PA manifests do not survive a round trip through a platform or messaging app unless it deliberately preserves them Magnet Forensics (2 Jan 2024); YouTube Help, camera disclosure (read Oct 2026).
  • Screen recordings and re-filming defeat everything at once. New container metadata, new compression, lost manifests, and Moiré patterns that cut detector accuracy by up to a quarter arXiv 2510.23225 (Oct 2025).
  • Watermarks and labels cover only their own ecosystem. SynthID answers only for Google AI; a Sora watermark could be removed in seconds; YouTube's camera label appears only when the creator opted into C2PA capture Gemini Help (read Oct 2026); 404 Media (7 Oct 2025); YouTube Help, camera disclosure (read Oct 2026).
  • Detectors generalise badly. Open-source models lose about half their AUC on in-the-wild material; commercial services do better but remain below human forensic analysts Deepfake-Eval-2024, arXiv (Mar 2025).
  • Sampling misses single frames. Browser tools, ours included, analyse sampled, decoded frames and cannot see codec-level structure; a one-frame insert between samples is invisible.
  • Authentic footage trips filters. Cuts, pans, exposure changes and tripod shots produce the same patterns as edits. A flag is a place to look, not a finding.

The honest answer is often "consistent with the claim, no evidence of manipulation, original file not available". Say that, rather than a confidence percentage no method here can support.

What is the 12-step video verification workflow?

  1. Preserve and hash. Save the file exactly as received, note the URL, sender, time and method, and record its SHA-256 in the Evidence Logger before you open it anywhere else.
  2. Get the best copy. Ask the uploader for the camera original. A platform download is the third-generation file; everything downstream is weaker for it.
  3. Read the claim. Write down exactly what the caption asserts: place, date, event, people. You are testing those statements, not "is this fake".
  4. Check provenance. Run the file through Content Credentials Verify, look for YouTube's "Captured with a camera" or TikTok's AI label on the original post, and note what the studio says about a C2PA box.
  5. Check for generator marks. Look for a visible watermark (corner logos, the moving Sora mark) and ask the Gemini app whether SynthID is present in the visuals or the audio.
  6. Pull keyframes and reverse-search them. Use InVID-WeVerify or export frames; search three or more distinctive frames on Google Lens, Yandex and Bing; record the earliest dated hit and its context.
  7. Audit the container. Run the studio's container audit or ffprobe/MediaInfo; note the encoder, timestamps, edit lists, tracks and anything inconsistent with the claimed device or workflow.
  8. Run the temporal checks. Look at the frame-difference, motion, flicker and duplicate charts; mark the moments that spike and decide whether a scene cut explains each one.
  9. Inspect flagged frames. Run per-frame ELA, noise and grid on the flagged frames and their neighbours; export any frame you will cite, with its hash.
  10. Geolocate and chronolocate. Match fixed features to imagery, test shadows against SunCalc for the claimed time, check weather and datable signage, and compare with the claim.
  11. Check the audio. Transcribe it, compare the voice with a reference if identity matters, run a synthetic-speech check, and test whether the track belongs to the pictures.
  12. Write it up. State what the claim was, what each check found, what it proves and what it cannot, and attach the hashes and sources. Use the studio report or the Report Builder, and say "not determined" where that is the truth.

Which video verification tools are free and which are paid?

Entries follow each product's public documentation; the comparison of Max Intel with Amped FIVE, Magnet Verify, InVID and MediaInfo is laid out feature by feature in Video Forensics Software Compared. Vendor accuracy claims are the vendor's.

ToolTypeWhat it does for videoCostBest for
Max Intel Video Forensics StudioBrowser, nothing uploadedSHA-256/SHA-1/MD5; MP4/MOV box and Matroska parsing with plain-language findings; frame difference, motion, flicker and duplicate detection over 24–96 sampled frames; per-frame ELA, noise, block grid; native-resolution frame export with SHA-256; printable PDF and JSON report; optional on-device AI detectorFreeFirst local triage and a documented report
Amped FIVEDesktop (workstation)Frame-accurate analysis, enhancement, stabilisation, measurement, codec-level structure, court-oriented reportsCommercial licenceLaboratory and courtroom work
Magnet VerifyDesktopCompares a file's internal structure with device and app signatures to judge whether it is an unedited originalCommercial licenceThe "is this the camera original?" question
InVID-WeVerify pluginBrowser extension (Chrome, Edge, Opera)Keyframe extraction from a URL or file, reverse search on Google, Yandex, Bing, TinEye, Baidu; YouTube/Facebook/Twitter metadata; some checks call a serverFreeFinding earlier copies and social context
MediaInfo / ffprobeDesktop, command lineEvery technical field: container, streams, codecs, encoded date, writing application and library; ffprobe -show_frames for per-frame dataFree, open sourceRaw technical metadata
Content Credentials VerifyWebReads and validates a C2PA manifest and shows declared edits, AI use and signerFreeProvenance check on an original file
Gemini app / SynthID DetectorWeb and mobileDetects Google's SynthID watermark in video and audio, reporting which segments carry it (100 MB, 90 s, about 10 video checks per 24 h)Free with Google accountRuling Google generators in or out
Sensity, Deepware and similarCloud serviceDeepfake classification; vendor-reported accuracy figuresPaid / limited freeA second opinion when the file may be uploaded

Free tools cover integrity, provenance, reverse search, metadata and triage; paid suites add frame-accurate and codec-level analysis, device signature databases, enhancement and courtroom reporting. For real stakes, use the free layer to decide whether an examiner is needed and to hand them a hashed file with a record of what you did.

Worked example: a flood video with the wrong city

Hypothetical example — constructed to illustrate the workflow; not a real case

A 41-second MP4 arrives by messaging app with the caption "Downtown Riverton under two metres of water this morning". The sender does not know who filmed it.

  1. Hash and log. SHA-256 recorded in the Evidence Logger at 08:12 with the sender's handle. File size 6.1 MB, 720×1280.
  2. Provenance. No C2PA box (studio), no credential (Verify). Expected for a forwarded clip; records nothing.
  3. Generator marks. No visible watermark. Gemini reports no SynthID in visuals or audio: rules out Google generators only.
  4. Keyframes. Three frames exported from the studio and searched. Yandex returns the same footage, same shop awning and bus-stop pole, on a regional news site dated 14 months earlier, captioned as a different city's river flood. Google Lens matches the awning logo to a chain that has no branch in Riverton.
  5. Container. Encoder string from a common transcoding library, creation time equal to the forward time, no audio track, single mdat, fast-start layout. All consistent with a messaging-app re-encode; proves nothing on its own.
  6. Temporal. One frame-difference spike at 0:27 without a motion spike. Per-frame noise map on 0:27 shows a uniform residual; a hard cut between two shots, not a splice within a frame.
  7. Chronolocation. Overcast, no shadows. Weather Chronolocation with the visible rain and a dashboard clock in one frame is inconclusive across several cities. Street View for the news site's city shows the same awning and pole; Street View for Riverton does not.
  8. Audio. No track to check; recorded as a limitation.
  9. Conclusion. Footage is authentic as far as examined but was first published 14 months earlier of a different city; the caption is false. Evidence: the earlier dated publication and two geolocated fixed features. Not determined: who filmed it, exact date of the original.

Note what did the work: a reverse search and two fixed features. The pixel checks confirmed a cut was a cut; the metadata said only that the file had been forwarded. That is the usual shape of a verification.

Sources

Every external source cited above, fetched and read on 7–8 October 2026. Dates in brackets are the publication date where the page gives one, otherwise the date read.

  1. C2PA Technical Specification 2.4 (April 2026) — https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html
  2. Content Authenticity Initiative — The State of Content Authenticity in 2026 (18 Jan 2026) — https://contentauthenticity.org/blog/the-state-of-content-authenticity-in-2026
  3. Content Credentials — Wikipedia (read 8 Oct 2026) — https://en.wikipedia.org/wiki/Content_Credentials
  4. Sony Professional — Authenticity Solutions (read 8 Oct 2026) — https://pro.sony/en_BE/authenticity
  5. Newsshooter — Sony expands video authenticity verification (30 Oct 2025) — https://www.newsshooter.com/2025/10/30/sony-expands-its-comprehensive-video-authenticity-verification-for-news-media-with-support-for-more-cameras/
  6. YouTube Help — "Captured with a camera" disclosure (read 8 Oct 2026) — https://support.google.com/youtube/answer/15446725
  7. YouTube Help — "How this content was made" disclosures (read 8 Oct 2026) — https://support.google.com/youtube/answer/15447836
  8. Gigazine — YouTube introduces camera label (16 Oct 2024) — https://www.gigazine.net/gsc_news/en/20241016-youtube-c2pa-captured-with-a-camera
  9. TikTok Newsroom — Content Credentials and AI labels (9 May 2024) — https://newsroom.tiktok.com/en-us/partnering-with-our-industry-to-advance-ai-transparency-and-literacy
  10. Content Credentials Verify (official verifier) — https://verify.contentauthenticity.org/
  11. Google DeepMind — Watermarking AI-generated text and video with SynthID (14 May 2024) — https://deepmind.google/discover/blog/watermarking-ai-generated-text-and-video-with-synthid
  12. Google DeepMind — SynthID (read 8 Oct 2026) — https://deepmind.google/models/synthid/
  13. Gemini Apps Help — Verify AI-generated images, videos and audio (read 8 Oct 2026) — https://support.google.com/gemini/answer/16722517
  14. Google — Verify Google AI videos in the Gemini app (18 Dec 2025) — https://blog.google/innovation-and-ai/products/verify-google-ai-videos-gemini-app/
  15. OpenAI — Launching Sora responsibly (30 Sep 2025; shutdown notice added 2026) — https://openai.com/index/launching-sora-responsibly/
  16. Sora (text-to-video model) — Wikipedia (read 8 Oct 2026) — https://en.wikipedia.org/wiki/Sora_(text-to-video_model)
  17. TechCrunch — OpenAI is shutting down the Sora app (24 Mar 2026) — https://techcrunch.com/2026/03/24/openais-sora-was-the-creepiest-app-on-your-phone-now-its-shutting-down/
  18. 404 Media — Sora 2 watermark removers flood the web (7 Oct 2025) — https://www.404media.co/sora-2-watermark-removers-flood-the-web
  19. Faegre Drinker — EU AI Act Article 50 transparency code and guidelines (30 Jul 2026) — https://www.faegredrinker.com/en/insights/publications/2026/7/eu-ai-act-commission-confirms-transparency-code-of-practice-as-adequate-and-publishes-final-version-of-its-guidelines-on-transparency-obligations
  20. InVID project — Verification Plugin (v0.71, 7 Jun 2019) — https://www.invid-project.eu/tools-and-services/invid-verification-plugin/
  21. WeVerify — InVID-WeVerify verification plugin 0.75 (Sep 2021) — https://weverify.eu/verification-plugin/
  22. Amnesty Citizen Evidence Lab — How to use InVID-WeVerify (11 Dec 2019) — https://citizenevidence.org/2019/12/11/how-to-use-invid-the-swiss-army-knife-of-digital-verification/
  23. Google Search Help — Search with an image on Google (read 8 Oct 2026) — https://support.google.com/websearch/answer/1325808
  24. Yandex Images Help — Search by image (read 8 Oct 2026) — https://yandex.com/support/images/en/loaded-image
  25. Microsoft — Bing Visual Search (read 8 Oct 2026) — https://explore.microsoft.com/en-us/bing/visual-search
  26. FFmpeg — ffprobe documentation (read 8 Oct 2026) — https://ffmpeg.org/ffprobe.html
  27. MediaArea — MediaInfo (read 8 Oct 2026) — https://mediaarea.net/en/MediaInfo
  28. arXiv 2402.06661 — Authentication and integrity of smartphone videos through container structure analysis (5 Feb 2024) — https://arxiv.org/abs/2402.06661
  29. Magnet Forensics — Understanding metadata removal on social media (2 Jan 2024) — https://www.magnetforensics.com/blog/getting-to-the-source-understanding-metadata-removal-on-social-media/
  30. arXiv 2503.02857 — Deepfake-Eval-2024: an in-the-wild benchmark (4 Mar 2025) — https://arxiv.org/abs/2503.02857
  31. arXiv 2510.23225 — Through the Lens: deepfake detectors against Moiré distortions (27 Oct 2025) — https://arxiv.org/abs/2510.23225
  32. Verification Handbook for Investigative Reporting, ch. 6 — Eliot Higgins (15 Apr 2015) — https://verificationhandbook.com/book2/chapter6.php
  33. Bellingcat — Using the sun and the shadows for geolocation (3 Dec 2020) — https://www.bellingcat.com/resources/2020/12/03/using-the-sun-and-the-shadows-for-geolocation/
  34. Bellingcat — Chronolocation: determining when a photo was taken (8 May 2023) — https://www.bellingcat.com/resources/2023/05/08/chronolocation-determining-when-a-photo-was-taken-using-facebook-google-street-view-and-assorted-tiny-details/
  35. SWGDE 23-V-001 — Best Practices for Digital Video Authentication v1.2 (7 Mar 2024) — https://www.swgde.org/documents/published-complete-listing/23-v-001-best-practices-for-digital-video-authentication/

For still images and keyframes, the Image Verification Workbench runs the same proof-versus-signal workflow and exports a report.

Frequently Asked Questions

How can I tell if a video is AI-generated?

There is no single test. Check for a generator's own marker first: a visible watermark, a C2PA manifest that declares AI generation (Content Credentials Verify), or Google's SynthID watermark via the Gemini app, which only recognises Google AI. Then reverse-search keyframes for an earlier or original version, audit the container for a generative-video encoder string, and run temporal and per-frame checks for warping, flicker and region-specific noise. Treat any AI-detector percentage as one opinion: open-source video detectors lost about half their AUC on real 2024 deepfakes. If nothing turns up, the honest result is "no evidence either way", not "real".

What is the best free tool to verify a video?

Use several, because they answer different questions. The InVID-WeVerify browser plugin is the fastest way to pull keyframes and reverse-search them on Google, Yandex, Bing and TinEye. Max Intel's Video Forensics Studio hashes the file, audits the MP4/MOV or WebM container, runs temporal and per-frame checks and writes an evidence report, all in the browser. ffprobe and MediaInfo give every technical field. Content Credentials Verify reads C2PA manifests and the Gemini app checks for SynthID. All are free.

Does YouTube's "Captured with a camera" label prove a video is real?

It is a strong positive signal, not absolute proof. YouTube applies it when the upload carries Content Credentials from a device or app with C2PA 2.1 or later support and the content has no edits to sound or visuals; it appears in the "How this content was made" section of the expanded description. YouTube itself says a missing label does not mean the video was edited, because it only appears when the creator used C2PA-capable capture tools. Also consider who the signer is and what the manifest declares.

Can metadata prove when and where a video was filmed?

Only on a camera-original file, and only as a claim by the device. Creation times, device make and model and GPS atoms are written by the recording app, can be edited, and are discarded when a platform or messaging app re-encodes the file. A downloaded clip normally shows the platform's encoder and the download date instead. Treat metadata as a lead to corroborate with geolocation, shadows, weather and an earlier publication, not as proof.

How do I reverse search a video?

Search engines index images, so you search frames. Extract keyframes with the InVID-WeVerify plugin or by exporting frames from the Video Forensics Studio or ffmpeg, then submit them to Google Lens (upload or "Paste image link"), Yandex Images (upload, clipboard or image address in the search bar) and Bing Visual Search (paste image or URL). Search three or more distinctive frames from different parts of the clip, record the earliest dated result and compare its caption with the claim you are checking.

Do Sora videos still have a watermark?

Sora videos generated while the product existed carried a visible moving watermark and embedded C2PA metadata, according to OpenAI. 404 Media showed in October 2025 that websites could strip the visible watermark in seconds, and OpenAI withdrew the Sora app on 26 April 2026 with the API scheduled to close on 24 September 2026. Older Sora clips are still circulating, so the watermark and manifest are worth looking for, but their absence proves nothing.

What is SynthID and can it detect any AI video?

SynthID is Google DeepMind's imperceptible watermark, embedded in every frame of video generated by Veo (and in Google-generated audio and images). You can check a clip of up to 90 seconds and 100 MB in the Gemini app by uploading it and asking whether it was made with Google AI; the answer names the segments where the watermark was found. It detects only content made or edited by Google's tools, so a negative result does not mean the video is human-made.

What is the difference between a signal and proof in video verification?

A signal is an observation consistent with manipulation or authenticity that other things could also explain: an FFmpeg encoder string, a frame-difference spike, an ELA hot spot, a detector score. Proof is a statement that ties the file to a fact independently: a valid Content Credential from a known signer, an earlier dated publication of the same footage, or fixed features that geolocate the scene. The SWGDE best-practice document for video authentication says no single analysis should be relied on individually; write your conclusion from the proofs and list the signals as what they are.

Can a screen recording of a video be verified?

Only partly. A screen recording is a new file: its container metadata describes the recording app, its compression history starts afresh, any C2PA manifest is gone, and Moiré patterns from re-filming a screen cut deepfake-detector accuracy by up to about a quarter. What still works is the content: keyframe reverse search, geolocation, chronolocation from shadows, weather and signage, and audio transcription. Ask for the original file whenever you can.

Is the Video Forensics Studio uploading my video?

No. Hashing, container parsing, frame sampling, the temporal and per-frame analyses and the report are all computed in your browser tab; the optional AI detector downloads a model once and runs on your device too. You can confirm this in the browser's network panel. Only analyse footage you have the right to, and remember that a flag from the studio is a place to look, not an accusation.