Metadata is the first thing a reviewer looks at and the thing most often over-interpreted in both directions. One reviewer sees a bank’s name in the Producer field and stops checking. Another sees an editing tool and decides the case is closed. Both have converted a self-reported string into a conclusion about a person, and the string does not carry that weight.

What a producer string actually is

Every PDF can carry a small dictionary of document information: Creator, Producer, a creation date, a modification date. Nothing in the format verifies any of it. The fields are written by software, they can be set to arbitrary values, they can be copied from another file, they can be stripped, and they can be rewritten by any later tool that touches the document. They are a claim the file makes about itself.

A Producer field is testimony, not evidence. It tells you what the file says about its own history, in the same way a letterhead tells you what a letter says about its own origin.

This is why a clean result is worth so much less than it feels like. If the metadata names something plausible, all you have established is that whoever wrote the file last either was that software or wrote that string. Both possibilities produce identical bytes. There is no test in the file that distinguishes them.

What a general-purpose editor marker means

Ocolta’s scan flags a specific short list of general-purpose editing tools when the file names one: Canva, Photoshop, Illustrator, GIMP, Figma, Affinity, and LibreOffice Draw. The finding is worded as a question about origin — the software “can be legitimate, but should match the document’s expected origin” — and it is deliberately not worded as a finding about the sender, because the ordinary paths to that same marker are numerous:

None of that is exculpatory either. The marker is a legitimate reason to ask where the document came from. It is not a reason to characterize the document, and it never establishes intent.

The one metadata signal that carries real weight

There is a narrow exception, and it is narrow on purpose. Ocolta’s generator-signature list matches Producer and Creator metadata deterministically and has exactly two confidence levels. High confidence is reserved for metadata that names a document-generator tool in its own words — a Producer string containing something like “paystub maker” or “check stub generator.” Issuer-produced statements and payroll-platform stubs do not describe themselves that way, so when that fires it is close to self-evident.

Everything else in that list is medium confidence, and medium means context rather than concern. General HTML-to-PDF stacks — wkhtmltopdf, dompdf, TCPDF, mPDF, FPDF, jsPDF, WeasyPrint, PhantomJS, and headless Chromium — are what template-generator sites commonly render with, and they are also what an enormous number of entirely legitimate business systems render with. A medium match is always worded as a provenance question and never as an accusation.

Even the high-confidence case is not a verdict. Metadata can be inherited from honest reprocessing, and a match is a reason to confirm the document’s origin with the claimed issuer, not a conclusion that anyone fabricated anything.

Missing metadata is missing evidence

The third case is the one reviewers handle worst. A PDF with no Producer, no Creator, and no timestamps is not suspicious and not clean; it is silent. Scanners strip metadata. Print-to-PDF pipelines strip metadata. Privacy tools strip metadata on purpose, and so do some portals. Deliberate removal produces the same silence. There is no way to rank those from the file, and Ocolta reports it as what it is rather than converting an absence into a direction.

How to write the observation down

The whole discipline collapses into one habit: quote the field, then stop. Everything you add after the quotation is inference, and inference is what fails later when someone asks you to explain the decision.

  • Record the exact Producer and Creator strings rather than a paraphrase of them.
  • Record creation and modification timestamps and whether they are in a plausible order.
  • Ask whether the named software is plausible for the issuer the document claims.
  • List the benign paths that would produce the same metadata: export, print-to-PDF, scan, page combining, e-signature, portal re-processing, accessibility repair.
  • Treat absent metadata as absent evidence, not as a clean result.
  • Write the observation as a quotation of the field, never as a conclusion about a person.

Ocolta’s free PDF tamper checker captures exactly these fields — creator, producer, creation and modification timestamps, incremental revision pointers, embedded scripts and attachments, digital signature presence, and a SHA-256 fingerprint of the file — in your browser, with the benign causes printed next to each one. The file is never uploaded.

What to do when metadata cannot settle it

It usually cannot, which is the honest headline of this page. Metadata narrows the question and occasionally reframes it; the answer lives outside the file. Ask for evidence the sender does not author — a fresh download from the institution’s portal, a consumer-permissioned account connection, or authorized confirmation with the employer. The escalation ladder covers what to request and in what order.

What a document check is, and is not

Ocolta reports supported file observations and arithmetic relationships. It does not prove a document authentic or fraudulent, does not confirm identity, account ownership, employment, or issuer records, and does not return a fraud verdict. Review priority is not fraud probability. Ocolta supports document review; it is not an automatic approval, denial, tenant-screening, or adverse-action system. Apply a written policy with the same criteria to every applicant, keep “unable to determine” available as an outcome, and obtain legal review before a document finding contributes to an adverse decision.

Related guides