Docento.app
Person signing a paper document with a pen
All Posts

PDF Signature Shows 'Invalid' or 'Validity Unknown'? What It Means and How to Fix It

By The Docento.app TeamPublished 3 min read
Sign or fill out your PDF now — Free, no sign-up, 100% private — files never leave your device.Open the editor

You open a signed contract and see a red cross or a yellow warning: "At least one signature is invalid", "Signature validity is UNKNOWN", or "The document has been altered since it was signed". It looks alarming. Often it is a trust or settings issue, not tampering. Here is how to tell the difference.

First: what kind of signature is it?

The messages only apply to digital signatures, which use certificates. A drawn or typed signature image has no validity status at all. See digital signatures vs electronic signatures.

Open the Signatures panel in your reader to see each signature's details.

"Validity unknown" (yellow)

The signature is mathematically intact, but your reader cannot confirm the signer's identity because it does not trust the certificate.

Common causes:

  • The certificate was issued by an authority your reader does not trust by default, such as a company's internal certificate authority.
  • The certificate is self-signed.
  • Your reader could not check revocation status (offline, firewall).

What to do: check the certificate details (issuer, name). If you expected this signer and verify with them, you can add their certificate to your trusted identities. In Acrobat, enabling trust of the European Union Trusted Lists (EUTL) and the Adobe Approved Trust List (AATL) resolves many cases for qualified certificates.

"Document altered since signed" (red)

The file content changed after signing. This can mean tampering, but also:

  • Someone added comments, form data or another signature in a way that was not allowed by the signer's permissions.
  • The file was re-saved by a tool that rewrote the PDF structure (some editors, compressors and "print to PDF" do this).
  • The file was converted, for example to PDF/A, after signing.

What to do: ask the sender for the original signed file, received directly from the signing platform. Compare versions. See how to detect tampered PDFs.

"Certificate expired" or "revoked"

An expired certificate at the time of verification is fine if the signature was made while it was valid and includes a trusted timestamp. Without a timestamp, readers may warn. A revoked certificate is more serious: the signer's key may have been compromised. See long-term validation and PDF timestamps.

Avoid breaking signatures yourself

Once a PDF is digitally signed:

  • Do not edit, compress, merge, or re-save it in an editor.
  • Do not "print to PDF". It creates an unsigned copy.
  • Add your own signature only in a signature field, using software that supports incremental saving. See PDF incremental updates explained.

If you need to annotate, make a separate copy and keep the signed original untouched. Browser editors such as Docento.app are fine for marking up that copy.

When to worry

Treat the warning seriously if: the signer's name does not match who you expected, the document's content looks different from what was agreed, or the sender cannot provide an unaltered original. Verify through a separate channel before acting on the document.

Takeaway

Yellow usually means "I do not know this signer"; red usually means "this file changed". Check the signature details, get the original from the source, and avoid re-saving signed files. For a full walkthrough, see how to verify a digital signature in a PDF.

Sign or fill out your PDF now

Free, no sign-up, 100% private — files never leave your device.

Open the editor

Related Posts