How to tell if a photo has been edited
Everybody tells you to check whether Software says Photoshop. That is the weakest signal in the file, and there are three better ones sitting beside it.
Look at what the file says about itself, and look at it in three places rather than one. The advice you will find everywhere — open the properties and see whether the software field names an editor — is one string that any metadata stripper removes in a single pass, and it tells you nothing about what was done. The three signals worth having are the edit history XMP records, the disagreement between the file's three different dates, and an embedded thumbnail whose shape no longer matches the picture. CLOAK reads all three in your browser, and TAMPER looks at the pixels for the separate question of where something was changed. Neither gives a verdict, for a reason set out at the bottom of this page.
Signal one: the edit history, written down in order
Software that handles photographs writes an XMP packet into the file, and inside it Adobe's applications keep xmpMM:History: a list of what happened to this image, in order. Each entry names an action, the software agent that performed it, and the time. A photo that was created by a camera, saved once and then converted says exactly that, with three timestamps:
| When | Action | By |
|---|---|---|
| 2024-03-11 09:14:02 | created | Camera |
| 2026-09-21 17:40:00 | saved | Adobe Photoshop 26.0 |
| 2026-09-21 17:45:30 | converted | Adobe Photoshop 26.0 |
That is a different class of answer from "the software field says Photoshop". It is a sequence, with times, and it survives in files whose owners have no idea it is there because nothing in any editor's interface shows it to them.
Three more fields sit beside it and are worth as much. xmpMM:DocumentID identifies the document; xmpMM:InstanceID identifies this particular saved copy of it; xmpMM:OriginalDocumentID points back at what it was derived from. Two files that share an original document id came from the same source picture, whatever has been done to either of them since — which is how a set of images can be tied together even when nothing visible connects them.
Signal two: the three dates, and what it means when they disagree
A photograph carries more than one time, and they are answering different questions:
| Field | What it means |
|---|---|
DateTimeOriginal | EXIF. When the shutter fired. Written once, by the camera |
DateTime | EXIF. When the file was last written. Updated by whatever saved it last |
xmp:ModifyDate | XMP. When the software last changed the image |
On a photograph straight off a camera these agree, or the later two are absent. When the capture date is two years before the modification date, the file was opened and written again in between. That is not proof of a meaningful edit — rotating a picture, or exporting it at a smaller size, moves the same dates as removing somebody from it — but it is a fact about the file rather than an impression, and it is the question worth asking next.
Signal three: the thumbnail that no longer matches
The EXIF block usually holds a small complete JPEG, written by the camera at the moment of capture. An editor that crops or paints over the visible image is not obliged to redraw it, and when it does not, the file carries the earlier frame. If the thumbnail is a different shape from the photograph, the picture was reshaped after that thumbnail was made.
CLOAK shows the thumbnail as a picture beside the photo rather than telling you one exists, so the comparison is yours to make. Why a cropped photo still shows what you cropped out goes through where it lives in the file and what the shape test cannot catch.
What error level analysis is actually worth
Somewhere on every list of methods is error level analysis: re-save the image at a known quality, subtract it from the original, and look at where the difference is largest. It is usually presented as a test that proves manipulation, and it is not one.
What it highlights is variation in how heavily different parts of the picture have been compressed. Pasted-in content can produce that. So can a sharpening pass, a region of flat sky, a watermark, text, a second save at a different quality, or a resize. Reading the output takes training and a known-good comparison, and a bright patch is a place to look rather than a finding. TAMPER will draw you the map, in your browser, and says in its own words that it produces places to look and never a verdict. That is the right posture and it is worth insisting on, because a confident misreading of an error level map looks exactly like a finding — a coloured picture with bright patches on it — and the people most likely to act on one are the least equipped to read it.
When none of this tells you anything
This is the part the listicles leave out, and it matters more than any of the three signals.
- A file with no metadata proves nothing. The major social networks strip metadata on upload, as do most chat applications and any deliberate cleaning pass — including the one on this site. A photograph that arrived through Instagram has no history, no dates and no thumbnail, and is no more suspicious for it than any other.
- A screenshot of a photograph carries none of it either, and is trivially easy to take. So is a re-encode. Anybody trying to hide an edit clears all three signals in about four seconds.
- The history records what software recorded. An editor that does not write XMP leaves none, and the packet can be edited like any other part of the file.
- None of this looks at the picture. Metadata cannot tell you whether the content is true. A completely unedited photograph can be staged, mislabelled, or taken somewhere other than where it is claimed.
So the honest shape of the answer is asymmetric: the signals above can show you that a file was changed, sometimes in detail. None of them can show you that it was not.
What this is and is not
CLOAK reads the EXIF, the XMP, the edit history and the embedded thumbnail out of a JPEG or a PNG in your browser, and shows you each of them. TAMPER does the pixel-level checks on the same file. Nothing is uploaded, and both work with your connection off.
Neither is a forensic report and neither will give you a verdict, because a verdict from either would be dishonest. What they give you is the same material a trained examiner would start from, which on most files settles the question and on a prepared file settles nothing.
Questions people ask about How to tell if a photo has been edited
Is checking whether Software says Photoshop enough?
It is the weakest signal in the file. One string, removed by any metadata stripper in a single pass, and it says nothing about what was actually done. Three better ones sit beside it: the edit history XMP records, the disagreement between the file's three dates, and an embedded thumbnail whose shape no longer matches the picture.
What is an edit history and where is it kept?
In the XMP packet, under xmpMM:History. Adobe's applications write a list of what happened to the image, in order, and each entry names an action, the software agent that performed it and the time. A photo created by a camera, saved once and then converted says exactly that with three timestamps. Nothing in an editor's interface shows it, so it survives in files whose owners have no idea it is there.
What are DocumentID and InstanceID for?
xmpMM:DocumentID identifies the document, xmpMM:InstanceID identifies this particular saved copy of it, and xmpMM:OriginalDocumentID points back at what it was derived from. Two files sharing an original document id came from the same source picture, whatever has happened to either since, which is how a set of images can be tied together when nothing visible connects them.
Why does a photo have three different dates?
Because they answer different questions. EXIF DateTimeOriginal is when the shutter fired and is written once. EXIF DateTime is when the file was last written, updated by whatever saved it last. xmp:ModifyDate is when software last changed the image. On a photo straight off a camera they agree or the later two are absent; a capture date two years before the modification date means the file was opened and written again in between.
Does a date disagreement prove the picture was altered?
No. Rotating a photo, or exporting it smaller, moves the same dates as removing somebody from it. What it gives you is a fact about the file rather than an impression, and the question worth asking next.
Is error level analysis proof of manipulation?
No, and it is routinely presented as though it were. What it highlights is variation in how heavily parts of the picture have been compressed, and pasted-in content produces that — so do sharpening, flat sky, a watermark, text, a resize and a second save at a different quality. Reading it takes training and a known-good comparison. TAMPER will draw the map and says in its own words that it produces places to look and never a verdict.
The file has no metadata at all. Is that suspicious?
No. The major social networks strip metadata on upload, as do most chat apps and any deliberate cleaning pass. A photograph that arrived through Instagram has no history, no dates and no thumbnail, and is no more suspicious than any other. A screenshot carries none of it either, and takes four seconds.
So can I ever prove a photo has not been edited?
Not with any of this. The shape of the answer is asymmetric: these signals can show that a file was changed, sometimes in detail, and none of them can show that it was not. Metadata also says nothing about whether the content is true — a completely unedited photograph can be staged, mislabelled, or taken somewhere other than where it is claimed.