How to Verify a PDF, Document or Leaked File
Check provenance, version, metadata, internal consistency and corroboration before treating a document as authentic or complete.
Separate authenticity from interpretation
A document can be genuine and still be misunderstood. Before asking what a PDF proves, ask two different questions: is this the document it claims to be, and if so, what does its procedural role actually mean? A real draft is not a final policy. A genuine complaint is not a finding. A legitimate spreadsheet can contain estimates rather than audited figures. Keeping authenticity and interpretation separate prevents one successful check from smuggling in a much larger conclusion.
Write down the exact claim attached to the file. “This memo exists” is narrower than “this memo proves the agency adopted the proposal.” The attached claim tells you which properties matter: issuer, date, version, recipient, signature, page completeness, attachments, or later superseding action. Without that target, document checking becomes a collection of trivia.
Build a provenance chain
Start with where the file came from, not what the filename says. Record the page that linked it, the domain hosting it, the publication date, and any visible document identifier. Search that identifier independently. For government material, look for the same number in an agenda, docket, report index or official repository. For corporate material, compare the file with investor-relations pages, regulatory filings or a newsroom archive.
Mirrors are useful discovery aids, especially when an original link is dead, but a mirror should not silently become the authority. If only a mirror survives, preserve the mirror URL and look for independent references that describe the same file. Two sites copying one upload are not two independent confirmations.
Use metadata as a clue, not a verdict
PDF properties can reveal creation software, creation time, modification time, producer and embedded fonts. Those fields can help identify inconsistencies, but they are easy to change and can also be rewritten by ordinary workflows such as scanning, optimization, digital signing or document-management software. A surprising timestamp is a lead to investigate, not proof of forgery.
Visual consistency is often more useful than raw metadata. Compare page numbering, headers, footers, logos, typography, signature blocks, exhibit labels and cross-references. If page 12 refers to an Appendix B that is missing, the file may be incomplete even if every visible page is genuine.
Check internal and external consistency
Documents contain claims that can be tested against other records. Dates should align with meeting calendars, officeholders, contract periods and cited statutes. Totals should reconcile with subtotals. A quoted policy should match the version effective on the stated date. These checks can expose both fabricated documents and authentic documents presented with the wrong context.
Search a distinctive eight-to-twelve-word phrase from the body. Exact phrase matches can locate earlier copies, official notices, court filings or reporting that quotes the same passage. If the phrase appears only in reposts that all point back to one anonymous upload, corroboration remains weak.
Know when verification stops
Some files cannot be conclusively authenticated from the public web. Scans may strip metadata, redactions may hide signatures, and leaked material may lack an official publication path. In those cases, state a bounded result: the text is consistent with known records, or the file cannot be independently authenticated. Avoid turning absence of disproof into confirmation.
High-stakes material needs a higher threshold. A document alleging criminal conduct, election manipulation, medical harm or national-security activity should be supported by primary records or multiple independent authoritative sources before it is presented as established fact.
Document verification checklist
- Record the original landing page and direct file URL.
- Identify issuer, date, version, document number and page count.
- Check whether appendices, exhibits or signature pages are missing.
- Compare the file with an official index, docket or repository.
- Inspect metadata but do not treat it as conclusive.
- Test at least two internal facts against independent records.
- Search a distinctive phrase for earlier or authoritative copies.
- State clearly what remains unauthenticated or procedurally uncertain.
Related tool:source comparison worksheet•claim evidence checker.
Worked example: a report circulating without its cover page
Suppose a 34-page PDF appears on social media and is described as a final government audit. The first visible page begins at page 3, the filename is generic, and there is no signature block. Search a distinctive sentence from the document and the report number printed in its footer. If an agency index reveals a 41-page final report with the same number, compare the section headings and page sequence. You may discover that the viral copy is an earlier draft or an excerpt missing the executive summary and appendices.
That difference can change meaning. A draft may list preliminary exceptions that were resolved before publication, while an excerpt may omit a methodology section explaining that a number is an estimate. Authentication therefore includes completeness. A real fragment should not be presented as the complete record.
A compact evidence note for documents
When you finish, record four lines: what the file is, where the authoritative copy was found, what specific passage supports the claim, and what limitation remains. That note is intentionally short enough to reuse in reporting without losing the verification trail. If you cannot identify an authoritative copy, say so and lower the confidence of any conclusion that depends on the file.