QuickBooks Payroll lives inside the accounting software that millions of American small businesses already run, so its stubs are everywhere in rental and lending files—and they are frequently the plainest documents in the stack. A genuine QuickBooks stub may have no logo, minimal formatting, and a bare tabular layout that looks like something anyone could have typed. That plainness is a trap in both directions: reviewers who equate plain with fake will wrongly burden legitimate applicants who work for small shops, while reviewers who equate plain with harmless forget that simple layouts are also the easiest to counterfeit. The discriminating evidence is arithmetic and cross-document consistency, not visual sophistication.
Keep the standard two cautions close. A stub that reconciles perfectly is not proven genuine—simple formats make internally consistent fabrication easier, which raises rather than lowers the value of source verification for material decisions. And a stub that looks homemade is not thereby fraudulent: a five-person business running QuickBooks Payroll produces exactly such documents every payday. The employer here is typically small enough to answer a phone, which makes independent verification unusually practical. The checks below assume nothing about branding and everything about how real payroll numbers behave.
A polished pay stub is not proof of authenticity. Unusual metadata is not proof of fraud. Every signal here is a reason to ask a better question—never a verdict.
What a genuine QuickBooks Payroll pay stub typically contains
QuickBooks Payroll output varies with product version and employer settings, and legitimately spans plain to very plain, so treat these as commonly observed traits rather than requirements. With so little visual signal available, internal numeric consistency and agreement with outside documents do nearly all the verification work:
- The employer's name and address typically appear at the top in simple text, frequently without any QuickBooks or Intuit branding; the employee's name and masked identifiers sit nearby.
- The pay period is stated as an explicit date range with a separate pay date, and small-employer cadences—weekly or biweekly especially—repeat consistently across stubs.
- Hourly earnings rows list rate, hours, and an amount equal to rate times hours; overtime and bonus items occupy their own labeled rows rather than being folded into base pay.
- Taxes are itemized on separate lines—federal income tax, Social Security, Medicare, and state lines where applicable—apart from voluntary deductions like health premiums.
- Current and year-to-date figures are paired for earnings, taxes, and deductions, with YTD amounts scaled sensibly to the pay date's position in the year.
- Net pay is stated and equals gross minus all itemized taxes and deductions, sometimes with a check number when the employer prints physical checks.
- Stubs generated digitally are typically text-layer PDFs even when visually spare; an image-only file indicates printing and rescanning or reconstruction, which removes several checks below.
Field-level checks anyone can run
1. Request the original file, not a re-capture
Ask the applicant for the stub as originally produced—downloaded from an employee portal where the employer's QuickBooks setup offers one, or the original PDF the employer emailed. Photos of printed stubs surrender the text layer that most of these checks depend on. Never ask for anyone's QuickBooks login.
2. Hash the submission immediately
Record a SHA-256 fingerprint of the exact file on receipt so later disputes about which version you reviewed are settled by the digest. Ocolta's free scanner does this locally in the browser as part of its scan.
3. Force the net-pay equation to balance
Gross minus itemized taxes minus itemized deductions must equal stated net exactly. Because QuickBooks stubs are visually simple, this equation is often the only internal structure available—work it to the cent and record the result rather than judging plausibility by eye.
4. Multiply every rate-and-hours pair
Each hourly row's rate times hours must equal its printed amount, with overtime carrying a sensible premium. On a plain stub these multiplications are your sharpest instrument: a failed product identifies the exact figure that needs explaining.
5. Chain YTD values across periods
Ask for two or three consecutive stubs. Every year-to-date figure must equal the previous stub's YTD plus the current amount, and YTD can never decrease during a year. A single stub's YTD gross should also roughly match pay periods elapsed by the pay date.
6. Sanity-check statutory withholding
Social Security commonly withholds 6.2% of Social Security taxable wages up to the annual wage base, Medicare 1.45%. QuickBooks Payroll computes these automatically, so gross deviations are notable—but pre-tax deductions legitimately reduce taxable bases, so anchor calculations to the stub's own wage figures where shown.
7. Verify cadence against bank deposits
Small employers on QuickBooks commonly pay weekly or biweekly. The stub dates should march on that rhythm, and any submitted bank statement should show matching net-amount deposits at matching intervals. Cadence mismatches between stub and statement are among the most concrete discrepancies available.
8. Track check numbers where present
Employers who print physical checks through QuickBooks produce check numbers that should advance across consecutive pay dates. Duplicated or regressing numbers merit a question. Direct-deposit stubs may lack numbers entirely, which is unremarkable.
9. Examine figures under heavy zoom
Magnify net pay, gross, and YTD lines to 400%. Even on a plain stub, edited digits tend to betray baseline drift, weight differences, or broken column alignment against surrounding numbers set by the same software in one pass.
10. Corroborate the employer's existence and identity
Match the employer name and address against the application and against independent sources—state business registries, the company's website, a map listing. Any EIN shown should fit the XX-XXXXXXX pattern. For very small employers, a brief verification call is often the fastest decisive step available.
11. Review metadata with small-business tolerance
Check creator and producer fields and modification timestamps. QuickBooks-generated PDFs pass through email, printers, and scanners in small businesses constantly, so anomalies are common and innocent; use them to justify requesting the original file rather than to conclude anything.
12. Interrogate uniformly round numbers
Automated payroll leaves odd cents behind—percentage taxes guarantee it. A QuickBooks-attributed stub where every line lands on whole dollars looks more like hand-typed template output than software-computed payroll. Round numbers are not disqualifying, but they earn a request for corroboration.
What Ocolta’s free scan checks automatically
Several of the checks above are mechanical, and mechanical work belongs to software. Ocolta’s free Integrity Scan runs entirely in your browser—the file never leaves your device—and reports the supported signals it can actually observe: whether the declared file type matches its binary signature, which software the PDF says created and produced it, creation and modification timestamps, incremental revision pointers, embedded scripts or attachments, and a SHA-256 fingerprint of the exact file you reviewed. For paystubs it also recomputes the core arithmetic—gross pay minus deductions against net pay—and explains benign causes to consider for each observation. The PDF tamper checker runs the structural subset on any PDF. Every result keeps “unable to determine” on the table; the scan never claims a pay stub is authentic or fraudulent.
When to escalate beyond file review
File review on a plain stub answers less than usual, so escalate sooner. Use an authorized employment-verification service where the employer participates, or place a documented call using a phone number you located independently—registry, website, directory—never the number printed on the stub. Small QuickBooks-using employers rarely appear in automated verification databases, which makes the direct, well-documented call the workhorse. Maintain a written policy, apply the same steps and thresholds to every applicant, and have counsel review before document findings support any adverse action.
When the file itself deserves a deeper look before you escalate externally, Ocolta’s AI Deep Review ($5 per document, no subscription) asks a model to organize fraud-risk and AI-generation indicators—evidence locations, confidence, benign explanations, limitations, and next checks. It reports observations, not verdicts, and it can return “unable to determine.” See pricing for 5-review and 25-review packs.
Frequently asked questions
Can Ocolta tell me whether a QuickBooks Payroll stub is fake?
No tool can. Ocolta's free scan works locally in your browser, checking structure, metadata, revision history, and the stub's math—net reconciliation, rate-times-hours, YTD chaining—and reports observations with an explicit unable-to-determine outcome. It never pronounces a stub genuine or forged, and it does not contact Intuit or the employer.
What single check should I run first?
The net-pay and YTD recomputation: gross minus every itemized tax and deduction must equal net, and year-to-date columns must exceed current amounts in proportion to the pay date's month. On a plain QuickBooks stub this arithmetic is the densest evidence the document offers, and it takes about two minutes.
The stub is extremely plain, with no logo. Is that a red flag?
No. Genuine QuickBooks Payroll stubs are commonly minimal—small employers print bare tabular output with no branding at all. Plainness is weak evidence in both directions, since simple layouts are also easiest to imitate. Ignore polish entirely and weigh the arithmetic, cross-document consistency, and independent employer verification instead.
Is missing or odd metadata proof of a fake QuickBooks stub?
No. Small-business documents lead rough lives: emailed, printed, rescanned, and merged, with metadata rewritten at every step. Odd creator fields or late modification dates justify asking for the originally generated file, and nothing more. Clean metadata likewise proves nothing, since it can be curated deliberately.
Do not tell an applicant that a document is “fake” based on file review alone. State the observation, request the same follow-up your written policy requires in comparable cases, apply consistent criteria to every applicant, and preserve an unable-to-determine outcome. Obtain legal review before using document findings in an adverse decision.