← All articles
ValidationQES

How to Verify an Electronic Signature on a Document

Ways to check a QES on a document: online validation services, built-in EDM checks, and how to read the verification results.

July 30, 2026·5 min read

You have received a document signed with a qualified electronic signature (QES) — an act, a contract or an order. Before acting on it, it is worth making sure the signature is genuine, the certificate is valid, and the file has not been altered since signing. Here is how to do that in a few minutes and how to read the verification results.

Why verify a signature at all

An electronic signature is not a picture of a scrawl — it is cryptographic data that can be verified objectively. Verification answers three questions at once:

  • Who signed. The signature is unambiguously linked to the certificate of a specific person or organization — you see the full name, the company and its registration code.
  • Whether the document was altered. If even a single character in the file was changed after signing, verification will detect it — this is the key advantage of a QES over a handwritten signature.
  • When it was signed and whether the certificate was valid. A timestamp fixes the moment of signing, and verification confirms that at that moment the certificate was neither expired nor revoked.

For an accountant or a lawyer this is basic hygiene: an unverified signature on a primary accounting document or a contract is a potential dispute waiting to happen.

Option 1: the state online verification service

Ukraine has an official state service for verifying electronic signatures — it is maintained by the central certification authority, and a similar check is available in the Diia ecosystem. The mechanics are simple:

  1. Open the verification service in your browser.
  2. Upload the signed file (plus the separate signature file, if the signature is detached).
  3. Get a verification report: who signed, when, with which certificate, and whether the document is intact.

This method is universal and free: it works with any file regardless of which system it was signed in. The downside is that everything is manual — each document has to be uploaded separately, and you have to store the report yourself.

Option 2: built-in verification in an e-document system

If you exchange documents through an electronic document management system, verification happens automatically. In eObig the signature status is visible right on the document: the system validates every applied QES on its own and shows who signed, when, and whether the certificate is valid. The platform's cryptographic core has a positive expert opinion from the State Service of Special Communications (SSSCIP), so its results can be trusted just like the state service.

This is convenient in day-to-day flow: when a counterparty returns a signed act via online document exchange, you do not need to upload anything anywhere — the signature status is already on screen, and the signed original lands in the electronic archive together with the full action history.

How to read the verification results

A typical verification report contains several blocks. Here is what each of them means:

What is checkedWhat a positive result means
Document integrityThe file was not modified after the signature was applied
SignerThe person/organization is identified: name, company, registration code
Certificate validityThe certificate was valid at the moment of signing: not expired and not revoked
Time of signingThe moment the signature was applied is fixed by a timestamp
Signature typeThe signature is qualified (QES), i.e. equal to a handwritten one

If every item is green, the document can be treated as a legally full-fledged original. For more on the legal side, see the article on the legal force of an electronic signature.

Why a signature may "fail verification"

A negative result does not always mean forgery. The most common causes are mundane:

  • The file was changed after signing. For example, the document was re-saved, converted to another format, or "touched up" before sending. That breaks the signature.
  • The wrong file is being verified. If the signature is detached (a separate file) and only the document — or a mismatched pair of files — was uploaded.
  • The certificate is expired or revoked. Keys are issued for a limited term; a signature made with an expired key is invalid.
  • The signature is not qualified. A facsimile or a pasted image is not a signature — only a cryptographic signature passes verification.
  • A technical format issue. More rarely, old or non-standard signature formats are simply not supported by a given service.

If verification fails, do not counter-sign the document and do not book it into your records. Ask the counterparty to send a correct signed original; inside an e-document system this situation is almost impossible, because validation happens at the moment the signature is applied.

Key Takeaways

  • Signature verification confirms three things: who signed, when, and whether the document was altered.
  • One-off checks are easy via the state online service; for everyday flow, use the built-in validation of an e-document system.
  • In eObig the status of every signature is visible right on the document, with no manual uploads.
  • A "failed verification" most often means a modified file or an expired certificate, not forgery.
  • An unverified signature on a contract or a primary document is an avoidable risk that takes a minute to eliminate.

Want signatures verified automatically and signing done right in the browser? Start for free at portal.eobig.com or book a demo — we will show how it works on your own documents.

Sign your first document today

No card, in a minute.