Security
How to verify a DocuSign or Adobe Acrobat Sign document
Check the completed PDF itself for the platform's digital signature: when it is intact, the document has not changed since the service sealed it. Then read the certificate of completion (DocuSign) or audit report (Acrobat Sign) for who signed, when and how they were authenticated. Remember the handwritten-looking signatures inside are pictures. The proof is the platform's seal plus its record.
A document signed through DocuSign or Adobe Acrobat Sign has a very particular structure, and knowing it makes verification much easier. The signatures you see on the pages (cursive names, drawn scribbles, initials) are not where the proof lives. The proof is a digital seal the platform adds when everyone has finished, plus the platform's own record of what happened.
The short answer
- Check the platform's digital signature on the final PDF. When a DocuSign envelope or Acrobat Sign agreement is completed, the service seals the final PDF with its own certificate. If that seal is intact, the document has not changed since completion.
- Read the record of what happened. DocuSign attaches or offers a Certificate of Completion; Acrobat Sign produces an Audit Report. They list the signers, the times, the email addresses and the authentication used.
- Match the IDs. A DocuSign envelope ID usually appears in the page header; an Acrobat Sign transaction ID appears in the audit report. The IDs on the pages and in the record should match.
Why the signatures on the page are not the proof
When someone "signs" in DocuSign or Acrobat Sign, they usually pick a font-style signature, draw one, or upload an image. That mark is placed on the page as a picture. It records intent, and the platform records who made it and when: but the mark itself is not a cryptographic signature.
So if you upload a completed DocuSign document to Verify PDF Signature, do not expect to see one signature per signer. Typically you will see the platform's signature (issued to the service provider, not to the individual signers) and possibly some or all of the on-page marks reported as signature images. That is normal and correct.
Some configurations are different: both services can offer certificate-based signing for individual signers (for example where a jurisdiction or a contract requires an advanced or qualified signature). In that case you will see a signature for each such signer too.
Step 1: check the seal on the completed PDF
Upload the file exactly as it was downloaded from the platform or received by email to Verify PDF Signature. You are looking for:
- A digital signature from the platform. Open Certificate details to see who it was issued to and by whom.
- Signature: Valid: nothing in the sealed document has changed.
- No changes after signing, or only expected ones. If the result says the file was changed after its last signature, read the list: an added page or text box after completion is a red flag.
In Adobe Acrobat or Reader, the same seal appears in the Signature Panel; for these services it is often a certification signature, shown with a blue ribbon.
If the checker finds no digital signature at all, the file is not the platform's final output. It may have been printed to PDF, scanned, flattened, merged with other files or re-saved. Any of which strips the seal. Ask for the original download.
Step 2: read the Certificate of Completion or Audit Report
DocuSign
The Certificate of Completion summarises the envelope: its ID, the sender, each signer's name and email, the events (sent, viewed, signed) with timestamps, IP addresses, and the authentication method used for each signer. It may be appended to the document or provided as a separate PDF, depending on the sender's settings.
Most completed DocuSign pages carry a small header such as "Docusign Envelope ID:" followed by a long identifier. That ID should match the one on the certificate.
Adobe Acrobat Sign
The Audit Report records the agreement's history: who created it, when each participant viewed and signed it, their email addresses, and IP information. It carries a transaction ID, and senders can choose to print that ID and the document name in the footer of every page. Acrobat Sign has a verification page where a transaction ID can be checked: a valid ID returns a green confirmation banner, an unknown one a red banner. Whether the green banner also links to the audit report for someone outside the sender's account depends on the sender's account settings. In some agreements, clicking a signature field opens that verification page directly, but as with any link inside a document, check the address it opens is really Adobe's before trusting the result.
Step 3: if you are a party, check inside the platform
If you sent or signed the document, the strongest check is to log in to your own account and open the envelope or agreement there. The platform's copy is the reference; compare it to the PDF you were given. For DocuSign, you can search your account for the envelope ID.
If you are a third party (a bank, landlord or employer receiving a DocuSign document from someone else) you usually cannot see inside their account. Rely on the seal plus the certificate or audit report, and if the document matters, ask the sender to have the platform email it to you directly.
What each piece proves
| Evidence | What it proves | What it does not prove |
|---|---|---|
| Platform's digital seal intact | The PDF has not changed since the service completed it | That the signers are who they say |
| Certificate of Completion / Audit Report | Which email addresses signed, when, and how they authenticated | That the person behind an email address is who the name says |
| Envelope / transaction ID match | The pages and the record belong together | Anything on its own. IDs can be copied |
| On-page signature marks | Where each person agreed | Nothing cryptographic; they are pictures |
A key point: by default, many e-signature workflows authenticate signers by email access only. Senders can add stronger checks (an access code, SMS, or identity verification) and the certificate or audit report will say which were used. For high-value documents, that line is worth reading.
Red flags
- No digital seal on something presented as the final platform download.
- Changes after the seal: especially pages or text boxes.
- Envelope ID missing, or different between pages and certificate.
- A certificate of completion that is itself only an image attached to a document that has no seal.
- Signer emails that don't fit: a company director "signing" from a free webmail address, or a lookalike domain.
The same logic for other platforms
Most e-signature services follow the same pattern: marks on the page, a platform seal on the final file, and an audit trail. KovaPDF's own Request Signatures works this way too. Signers sign in their browser, and everyone receives the completed PDF with a certificate of completion. Whatever the platform, verify the seal first and read the record second.
Common questions
How do I know a DocuSign document is real?
Check that the completed PDF carries an intact digital signature from the platform, that nothing was added after it, and that the envelope ID on the pages matches the Certificate of Completion. If you sent or signed it, you can also find the envelope in your own account.
Why does the checker show only one signature when three people signed?
Because the individual signatures on the pages are usually pictures, while the digital signature is the platform's seal on the finished document. The platform's record (the certificate of completion or audit report) shows each signer.
The DocuSign PDF shows no digital signature. Is it fake?
Not necessarily, but it is not the platform's final output as downloaded. Printing, scanning, flattening, merging or re-saving removes the seal. Ask for the original file, or ask the sender to have the platform send it to you.
What is the Certificate of Completion?
DocuSign's summary of the envelope: its ID, each signer's name and email, the time of each event, IP addresses and the authentication method used. It may be attached to the document or provided separately.
Can I verify an Adobe Acrobat Sign agreement if I am not the sender?
You can always check the seal on the PDF and read its audit report if you were given it. Acrobat Sign also has a transaction-ID verification page; how much it shows to outsiders depends on the sender's account settings.
Does an e-signature prove the signer's identity?
It proves what the platform checked, by default often access to an email address. Stronger options such as SMS codes or identity verification are listed in the audit record when used.