Skip to content
files.co

Why Does My PDF Signature Show as Invalid or Not Verified?

A PDF you signed opens with a red 'signature invalid' banner. Here's what that warning actually means, the four usual causes, and how to check a document before it ever leaves your device.

DCDavid Carrero · · 6 min read

You open a signed PDF, and instead of a reassuring green checkmark you get a banner in red: “Signature is invalid” or “Signature not verified.” It’s an alarming thing to see on a contract, an invoice, or a report you were counting on. Before you assume the document was tampered with, it’s worth knowing that this warning has a handful of ordinary, non-sinister causes, and only one of them is actually a red flag.

What the warning is really checking

A digital signature isn’t a picture of someone’s name pasted onto a page. It’s cryptography: a certificate tied to the signer’s identity, combined with a mathematical fingerprint of the exact file contents at the moment of signing. When a PDF viewer checks a signature, it’s really asking two separate questions:

  1. Has the file changed since it was signed? The viewer recalculates the fingerprint and compares it to the one baked in. Any difference, even a single byte, breaks the match.
  2. Do I trust the certificate that signed it? The viewer checks whether the certificate was issued by an authority it recognizes, and whether that certificate is still valid.

A “invalid” or “not verified” message means one of those two checks failed, and they fail for very different reasons.

The four usual suspects

1. The file was edited after signing. This is the integrity check catching something real. Adding a page, flattening a form field, even re-saving the PDF from certain editors can quietly rewrite the file and break the signature’s fingerprint. If this happens on a document you know hasn’t been altered by anyone with bad intent, it usually means a tool in the chain (a printer driver, a scanner’s “optimize” pass, an overzealous compressor) resaved the file. The fix isn’t to ignore the warning, it’s to go back to the original signed copy and stop it from being touched again.

2. The certificate isn’t in the viewer’s trust list. Plenty of legitimate signatures, especially self-signed ones or certificates from smaller, region-specific authorities, aren’t in the default trust store of whatever PDF reader you’re using. The signature can be mathematically perfect and the file completely untouched, but the viewer still shows a warning because it doesn’t recognize who issued the certificate. This is common with internal company certificates and with countries that have their own accredited signing authorities.

3. The certificate expired. Certificates have a shelf life. If a document was signed years ago and the certificate has since expired, some viewers flag the signature as invalid even though it was perfectly valid at signing time, unless the software checks the timestamp against when the signature was actually applied rather than today’s date.

4. The document has more than one signature layer, and one of them changed. If a form gets signed, then someone fills in an additional field afterward, the later edit can invalidate the earlier signature while leaving the newer one intact. Viewers sometimes show a confusing mixed status in this case.

How to check it yourself before it becomes a problem

If you’re the one sending a signed PDF, don’t just trust that it looks fine on your screen. A few habits catch problems early:

  • Sign last, not first. Add your signature after all other edits, merges, or reordering are finished. Signing, then editing, is the single most common way to accidentally invalidate your own signature.
  • Avoid re-processing a signed file. Once it’s signed, treat it as final. Don’t run it back through a compressor or an image converter “just to shrink it” — that resave is exactly what breaks the fingerprint.
  • If you also need to lock it down, protect after signing. Adding a password with a protect PDF step uses AES encryption to restrict access, and encrypting a file changes its bytes. Do this after signing so the signature isn’t affected by a step that comes later, or confirm your workflow signs on top of the already-encrypted version consistently.
  • Open the certificate details, not just the summary badge. Most readers let you click into the signature panel to see exactly which check failed: integrity or trust. That distinction tells you whether you have a real problem or just an unrecognized issuer.

Do this without handing the file to anyone

None of this requires uploading a sensitive contract anywhere to get answered. Adding or checking a signature in your browser processes the file locally, on your own device, the PDF is read into memory, signed or verified, and never sent to a server. You can confirm that yourself by opening DevTools (F12), watching the Network tab, and seeing nothing happen when you sign. For a document with legal or financial weight, that’s worth more than a green checkmark: it means the only copy that ever left your hands is the one you meant to send.

Explore by category