DeepFake Check
Back to Blog
DeepCheckAI Team 5 min read

How to Verify Content Credentials Before Trusting a Media File

Save the file and define the question

Content Credentials can record where a digital asset came from and what happened to it. Before checking one, preserve the exact file you received and write down the question you need to answer. You may be trying to identify the signer, check whether the recorded history is intact, find a stated edit, or decide whether the event shown is real. A credential can inform the first three questions. The last one needs evidence outside the credential.

C2PA calls this recorded history provenance. A Content Credential, also called a C2PA Manifest, is cryptographically bound to an asset and contains signed assertions. Keeping the original file matters because a screenshot, exported copy, or platform download may not have the same connection to a manifest as the file you intended to inspect. Record the filename, where you obtained it, and which copy you opened. This record is a practical review method proposed here, not a C2PA requirement.

Check how the manifest was found

Open the file in an application that supports Content Credentials. First record whether the application found a manifest and how it was associated with the asset. C2PA allows a manifest to be embedded in the file or linked externally through a soft binding. Its explainer gives invisible watermarks and fingerprint lookup as examples of soft-binding methods. Finding an external record therefore does not mean the manifest was stored inside the file.

Next, copy the verification result in the tool's own terms. The C2PA explainer describes checks for whether the manifest is well formed, has remained intact, is associated with the underlying asset, and was signed by an implementation linked to a known trust list. Do not compress several checks into a vague note such as “verified.” Record each result separately, including any result the application could not determine.

A failed or unavailable check has a narrower meaning than “fake.” It tells you which part of the provenance record could not be validated through that application. Preserve the message and continue with source and context checks rather than inventing a cause.

Read assertions without strengthening them

A valid connection is only the start of the review. Read the assertions that the application displays. They may describe origin, creation information, modifications, tools, AI use, or ingredients used to make the asset. Different credentials can contain different fields, so an absent field should remain “not stated” unless another record supplies it.

Use a simple table with four columns: assertion, exact value, verification result, and unresolved question. Copy names, dates, tool labels, and editing actions as shown. If the record says that an action occurred, do not turn that into a claim about why it occurred or whether the final scene is truthful. If an assertion names a publisher or tool, check whether that identity is the one you expected from the publication context.

C2PA does not guarantee that every statement inside an assertion is factually correct. Verification can show that signed provenance data has a valid structure and connection; it does not independently confirm the real-world claim attached to the media.

Keep provenance and truth in separate notes

C2PA explicitly says Content Credentials do not judge whether provenance data is good or bad or whether content is true. Keep two conclusions instead of one. The provenance conclusion should state what record was found, which checks passed, and what the assertions said. The content conclusion should state what independent reporting, original publication context, or other evidence establishes about the depicted event.

The same separation applies when no credential is found. C2PA adoption is opt-in, so absence does not prove that a file is synthetic, altered, or deceptive. It only means this review did not obtain provenance through that channel. Note the application and file checked, then continue with source, context, and forensic review.

Add detection as a separate risk signal

A saved image, video, audio file, or text can be checked with DeepFakeCheck for a probabilistic risk signal. That result does not validate a C2PA signature, identify a signer, retrieve a missing manifest, or prove that an event happened. Attach the result to the exact copy analyzed and keep it separate from the credential table.

Automated analysis can produce false positives and false negatives. A false positive may flag authentic media, while a false negative may miss synthetic or manipulated media. A high-risk result supports further investigation; a low-risk result does not authenticate the file. If provenance and detection appear to conflict, preserve both results and investigate the source and context instead of forcing them into one verdict.

Finish the review with a short evidence log: file checked, manifest discovery method, verification results, assertions relied on, unknowns, independent context checks, detector result if used, and the decision that followed. Another reviewer should be able to see which conclusion came from which evidence.

Sources

  • C2PA, “C2PA Explainer”: https://spec.c2pa.org/specifications/specifications/2.2/explainer/Explainer.html

Suspect an image might be AI-generated?

Use our advanced deepfake detection tool to analyze images with high precision.

Analyze Image Now