Blog Guides 6 min read

How to Verify if a Photo Is Real: 6-Step Workflow

A viral photo hits your feed. Is it real, edited, or AI-generated? Here's the exact workflow — six steps, six tools, each catching something the others miss.

Flowchart showing a 6-step photo verification workflow from metadata to forensic analysis

Why You Need a Workflow, Not Just a Tool

No single check can tell you if a photo is real. Metadata can be faked. AI detectors have false positives. ELA degrades after re-saves. Every technique has blind spots — and skilled manipulators know what they are.

Try it free: Authenticity Checker — Run automated verification on suspect photos. Runs in your browser, no signup needed.

A structured workflow solves this by running independent tests that target different types of evidence. Each step either builds confidence or raises a specific red flag. A photo that passes all six has strong credibility. A photo that fails any single step deserves closer scrutiny.

Five of the six steps run in your browser — no uploads, no account. The one exception is Step 3: the AI Detector's metadata pass is free and local, but its pixel-level Deep Check runs on our server. Here are the six steps.

Step 1 — Automated Authenticity Check

Start with the Authenticity Checker. It runs metadata consistency analysis, software signature detection, compression pattern review, and thumbnail comparison in a single automated pass. You get a composite authenticity score plus specific flags for any anomalies detected.

What to look for: a high score with no flags means the photo shows characteristics consistent with an unmodified camera original. A low score or specific flags (missing metadata, editing software detected, compression inconsistency) tell you where to dig deeper.

Time: ~5 seconds.

Step 2 — Metadata Inspection

Open the EXIF Checker and read the metadata manually. The automated check catches patterns, but human inspection catches context.

Camera model: is it a real camera? Does it match what the source claims? A "Canon EOS R5" file from someone claiming to use an iPhone is inconsistent.

Software tag: does it say "Adobe Photoshop" or "GIMP"? That means the photo was edited. The question is whether the edit was routine (crop, exposure) or substantive (object removal, compositing).

Timestamps: is the date plausible? A photo claiming to show yesterday's event but timestamped three months ago needs explanation.

GPS coordinates: do they match the claimed location? Drop them into a map. A photo "from Paris" with GPS coordinates in Shanghai is immediately suspect.

Missing metadata: no EXIF at all? The image was likely processed through a tool that strips metadata — social media, messaging apps, screenshot, or deliberate removal. Not suspicious by itself, but it removes one verification layer. Check our guide on EXIF, XMP, and IPTC metadata for what each field means.

Time: ~30 seconds.

Begin the 6-step workflow with an automated authenticity check — metadata, compression, and software analysis in one pass.

Start Verification →

Step 3 — AI Generation Detection

Run the image through the AI Detector. It analyzes texture patterns, noise characteristics, and structural features to determine whether the image was generated by tools like DALL-E, Midjourney, or Stable Diffusion.

What to look for: a high AI probability score (above 70%) is a strong signal the image is synthetic. A low score (below 30%) suggests a real photograph. Scores in between require additional verification. Heavily compressed or screenshot images may produce unreliable scores.

Important: AI detection catches fully generated images. It's less reliable for AI-edited real photos (inpainting, face swaps, background replacement). For those, Steps 4 and 5 are more effective. See our guide on detecting AI-generated images.

Time: ~10 seconds.

Step 4 — Compression Forensics (ELA + JPEG Ghosts)

This step targets local edits — pasted objects, cloned regions, composited elements. Run two complementary tests:

Error Level Analysis re-saves the JPEG and measures how much each region changes. In an unedited photo, all regions show similar error levels. Edited regions glow differently because they have a different compression history. Read our full ELA explainer for interpretation guidance.

JPEG Ghost Analysis sweeps across quality levels to find regions that were originally saved at a different JPEG quality. If someone spliced content from a quality-75 source into a quality-92 photo, the ghost scan lights up the spliced region. See our guide on how JPEG ghosts expose edits.

What to look for: uniform ELA output = consistent compression = likely unedited. Bright patches = compression anomalies = possible editing. Ghost regions at a different quality level = likely splicing.

Caveat: both techniques degrade after multiple re-saves. Social media images are often too heavily recompressed for reliable ELA/ghost analysis.

Time: ~30 seconds for both.

Step 5 — Thumbnail Mismatch

Run the Thumbnail Scanner. Camera-original JPEGs embed a tiny preview image (160×120) at capture time. If the main image was edited but the thumbnail wasn't regenerated, the two won't match — and the thumbnail shows the original unedited scene.

What to look for: matching thumbnail = no modification detected (or the editor regenerated it). Mismatching thumbnail = the photo was definitely modified, and you can see what the original looked like. No thumbnail = image lacks EXIF data (web download, social media, screenshot). Learn more: What Is an EXIF Thumbnail?

Time: ~5 seconds.

Step 6 — Hash and Record

Compute a SHA-256 hash of the image file. This creates a unique fingerprint of the file in its current state. If you're documenting your analysis — for journalism, legal proceedings, or internal records — the hash establishes exactly which file you examined and confirms it hasn't changed since your analysis.

When this matters most: forensic investigations, legal evidence, insurance claim reviews, journalistic fact-checking — any context where you may need to prove later that the file you analyzed is the same file in question. See our guide on file hashes and integrity verification.

Time: ~3 seconds.

🔍 Pro tip

For batch triage, the Batch Scanner runs Steps 1, 2, 3, and 6 across up to 50 images at once. Flag the suspicious ones, then run Steps 4 and 5 individually on flagged images only. See our batch scanning guide.

Interpreting Results

All steps pass: the photo shows strong characteristics of an unmodified camera original. Consistent metadata, clean compression, matching thumbnail, no AI signals. This is the highest confidence level available from automated analysis.

One step fails: investigate the specific failure. A missing thumbnail isn't alarming — it might be a web download. An editing software tag isn't deceptive — photographers routinely process their images. Context matters. But if the specific failure contradicts the photo's claimed origin, that's a genuine red flag.

Multiple steps fail: significant concern. When metadata is inconsistent, ELA shows compression anomalies, and the thumbnail doesn't match, the evidence strongly suggests manipulation. The specific pattern of failures often reveals what kind of manipulation occurred.

No metadata at all: the image has been processed through a metadata-stripping pipeline (social media, messaging, screenshot). Steps 1, 2, and 5 are largely neutralized. You're limited to Steps 3 and 4 (AI detection and compression forensics), which reduces confidence. Try to obtain the original file.

Common Questions

How long does full verification take? A basic check (authenticity + metadata) takes under 30 seconds. The full 6-step workflow takes 2–5 minutes per image. Batch scanning processes 50 images in about a minute for initial triage.

Can I verify social media photos? Partially. Platforms strip metadata and recompress, removing most forensic signals. AI detection and visual inspection still work. For reliable verification, request the original file.

What if it passes all steps? Strong forensic credibility — consistent metadata, clean compression, matching thumbnail, no AI signals. But no workflow guarantees absolute authenticity. Multiple passing results across independent techniques provide the highest confidence.

Are these tools free? Yes, with one exception. EXIF Checker, Authenticity Checker, ELA Scanner, JPEG Ghost Scanner and Thumbnail Scanner are free, need no account and run in your browser. The AI Detector's Deep Check is the exception: it runs on our server, so that image is uploaded, checked and then deleted. It has a free daily allowance and costs credits beyond it.

Can I automate this for many images? The Batch Scanner handles triage across 50 images. Individual forensic checks (ELA, ghosts, thumbnails) run per image. Use batch for breadth, individual tools for depth.

Trust, but Verify

Six steps, six independent checks, each targeting a different type of evidence. The whole workflow takes under five minutes, and runs in your browser apart from the Deep Check in Step 3, which runs on our server. It won't catch everything — no system can — but it catches the vast majority of casual manipulation, AI generation, and metadata inconsistency. Start with the Authenticity Checker and work through the steps. For the full forensic toolkit, see our complete guide to image forensics.

Start Verification
Share:
S

Scanly.co — 92 free image analysis tools

Photo forensics, metadata, privacy, OCR, and utilities. All client-side.

Advertisement