Digital Signatures

Digital vs Electronic Signatures: The Complete Guide

10 min read
By
Digital vs Electronic Signatures: The Complete Guide

NovelCrypt

The terms "electronic signature" and "digital signature" are used interchangeably by most people, including by software vendors who should know better. They are not the same thing. One is a legal concept. The other is a cryptographic technology. Confusing them leads to signing documents that look secure but provide no actual tamper protection, or to over-engineering simple agreements with cryptographic signatures that recipients cannot verify.

The Taxonomy

There are three categories you need to understand, each more specific than the last:

Electronic signature — the broadest legal category. Any electronic indication of intent to agree to a document qualifies. This includes a typed name at the bottom of an email, a clicked "I agree" checkbox, a drawn signature on a touchscreen, or a scanned image of a handwritten signature pasted into a PDF.

Digital signature — a cryptographic subset of electronic signatures. A digital signature uses public-key cryptography (typically RSA or ECDSA) to create a mathematical proof that a specific key signed a specific document at a specific time, and that the document has not been altered since.

Qualified electronic signature — a legally defined subcategory of digital signatures under the EU eIDAS Regulation. A QES requires a cryptographic digital signature created using a qualified signature creation device and backed by a qualified certificate from an accredited trust service provider who has verified the signer identity through a rigorous process.

Think of it as concentric circles: all qualified electronic signatures are digital signatures, and all digital signatures are electronic signatures. But a typed name in an email is an electronic signature that is neither digital nor qualified.

Comparison Table

| Property | Electronic Signature | Digital Signature | Qualified Electronic Signature | | --- | --- | --- | --- | | Technical mechanism | Any electronic indication | Public-key cryptography | PKC + qualified device + qualified certificate | | Tamper detection | No | Yes (cryptographic) | Yes (cryptographic) | | Identity verification | Varies (often none) | Certificate-based | In-person or equivalent identity proofing | | Legal weight | Basic (most contracts) | Enhanced (presumed authentic) | Equivalent to handwritten (EU) | | Audit trail | Limited | Cryptographic proof | Full chain of trust | | Cost | Free to low | Low (self-signed) to moderate (CA-issued) | Higher (qualified provider fees) | | Regulatory acceptance | Most everyday contracts | Regulated industries, cross-border | All EU transactions, highest assurance |

How Digital Signatures Work

A digital signature is created through a specific cryptographic process that provides three guarantees: authenticity (the signer holds the private key), integrity (the document has not been altered), and non-repudiation (the signer cannot deny having signed).

### The Signing Process

1. The signing software computes a cryptographic hash of the document. This is a fixed-length fingerprint of the document content. Common hash algorithms include SHA-256 and SHA-384. Even a single-bit change in the document produces a completely different hash. 2. The hash is encrypted (or signed) using the signer private key. For RSA, this means applying the RSA signing operation to the hash. For ECDSA, it means generating a signature pair (r, s) using the private key and the hash. 3. The signature and the signer certificate (which contains their public key and identity information) are embedded in the document or transmitted alongside it.

### The Verification Process

1. The verification software extracts the signature and the signer certificate from the document. 2. It computes a fresh hash of the received document content. 3. It uses the public key from the signer certificate to verify the signature against the freshly computed hash. 4. If the hashes match, the signature is valid — the document has not been altered since signing, and the signer holds the private key corresponding to the certificate. 5. The software also checks the certificate chain (is the certificate issued by a trusted certificate authority?), expiration date, and revocation status.

You can perform this process yourself using the digital signer tool, which handles key generation, signing, and verification entirely in your browser. The underlying mathematics is explained in our RSA encryption guide, since RSA signing and RSA encryption use the same mathematical operation in different directions.

How to Verify a Digital Signature Step by Step

Verification depends on the file format and the tool you are using, but the logical steps are the same regardless:

### Step 1: Open the Document in a Compatible Viewer

For PDFs, open the document in Adobe Acrobat Reader or a compatible PDF viewer. Click the signature panel. The viewer will display the validation status, the signer name, the signing time, and the certificate details. For signing PDFs without Adobe, browser-based tools can verify signatures as well.

### Step 2: Check the Signature Validity

The viewer will report one of several states:

Signature valid — the document has not been altered, the certificate is trusted, and the certificate chain is intact.

Signature invalid — the document was modified after signing. This is a serious red flag. Do not trust the document.

Signature cannot be verified — the verification software cannot find the signer certificate or cannot build a trust chain to a known certificate authority. This does not necessarily mean the document was tampered with, but it does mean you cannot confirm who signed it.

Signature unknown — the certificate is not in your trust store. You need to add the signer certificate to your trusted certificates to verify.

### Step 3: Inspect the Certificate Details

Check who issued the certificate (the certificate authority), when it expires, and whether it has been revoked. A certificate from a recognized CA (DigiCert, GlobalSign, Entrust) provides stronger assurance than a self-signed certificate. Check the signature algorithm — SHA-256 or SHA-384 with RSA-2048 or ECDSA P-256 is current. SHA-1 or RSA-1024 should be treated as deprecated.

### Step 4: Check for Document Modifications After Signing

Some PDF viewers distinguish between changes to the signed content (which invalidate the signature) and changes to the document after signing (which may be allowed depending on the signature permissions). Look for annotations or form fields filled after the signature was applied — these may be legitimate or may represent an attempt to modify the agreement.

For tools that can sign and verify without uploading your documents, see our guide to free DocuSign alternatives.

Qualified Electronic Signatures Under eIDAS

The EU eIDAS Regulation (Regulation EU 910/2014, updated by EU 2024/1183) defines three levels of electronic signatures:

Simple Electronic Signature (SES) — any electronic indication of intent. A typed name, a clicked checkbox. Legally valid for most contracts but provides no inherent evidence of identity or integrity.

Advanced Electronic Signature (AdES) — a digital signature that is uniquely linked to the signer, capable of identifying the signer, created using data the signer controls, and linked to the document in a way that detects subsequent modifications. This is what most CA-issued digital signatures provide.

Qualified Electronic Signature (QES) — an AdES that is additionally created by a qualified signature creation device and backed by a qualified certificate. The signer identity must be verified in person or through an equivalent process by a qualified trust service provider. A QES has automatic legal equivalence to a handwritten signature across all EU member states and carries a presumption of authenticity that can only be rebutted with strong evidence.

The U.S. does not have an equivalent three-tier system. The ESIGN Act (2000) and UETA recognize electronic signatures broadly without distinguishing between cryptographic and non-cryptographic signatures. In practice, the legal weight of a U.S. electronic signature depends on the evidence supporting it — a cryptographically verified digital signature with a CA-issued certificate carries more weight in court than a typed name.

Common Verification Failures and What They Mean

Signature verification failed — the most alarming message. It means the cryptographic hash of the current document does not match the hash in the signature. The document was modified after signing. This could be malicious (someone altered the contract terms) or benign (someone added a comment annotation that the viewer counts as a modification). Check what changed before trusting or rejecting the document.

Certificate not trusted — the signer certificate was issued by a certificate authority that is not in your viewer trust store. This is common with self-signed certificates or certificates from regional CAs. You can add the certificate to your trust store, but only do this if you can verify the certificate through an out-of-band channel.

Certificate expired — the signing certificate has passed its validity period. This does not invalidate the signature itself (the signature was valid when created), but it means you cannot rely on the current certificate chain. Timestamps from a trusted timestamp authority can extend the validity of a signature beyond the certificate expiration date.

Certificate revoked — the certificate has been revoked by the issuing CA, possibly because the private key was compromised or the identity was fraudulent. Treat revoked certificates as untrustworthy regardless of when the signature was created.

Algorithm deprecated — the signature uses an algorithm that is no longer considered secure, such as SHA-1 or RSA-1024. The signature may still verify, but its security guarantees are weakened. Modern signatures should use SHA-256 or stronger with RSA-2048 or ECDSA P-256.

Which Do You Need

| Your Situation | What You Need | | --- | --- | | Signing a simple contract or NDA | Electronic signature (typed or drawn) | | Signing a legal document requiring tamper protection | Digital signature (CA-issued certificate) | | Signing documents for EU government or regulated industries | Qualified electronic signature | | Signing code or software releases | Digital signature (GPG or code signing certificate) | | Signing PDFs without installing software | Browser-based digital signer | | Verifying someone else signed a document you received | Hash verifier to check integrity |

For the legal dimensions of electronic signatures — which countries recognize them, which transactions require qualified signatures, and what the ESIGN Act covers — read our electronic signature legality guide.

The Bottom Line

An electronic signature is a legal intent. A digital signature is a cryptographic proof. A qualified electronic signature is a cryptographic proof with a legally certified identity behind it. Knowing which one you need depends on what you are signing, who needs to trust it, and what legal framework applies. When you need genuine tamper protection and identity assurance, use a digital signature backed by RSA encryption. When you just need evidence of agreement, an electronic signature is sufficient. The mistake to avoid is paying for a "digital signature" service that only applies a scanned image of your handwriting and calls it cryptographic.

Frequently Asked Questions

Is an electronic signature legally binding?

In most jurisdictions, yes. The U.S. ESIGN Act (2000) and the EU eIDAS Regulation (2016) both establish that electronic signatures have legal effect. However, the legal weight varies by type: a simple electronic signature (like a typed name) is valid for most contracts, while certain transactions require qualified electronic signatures with cryptographic backing and identity verification.

What is the difference between a digital signature and an electronic signature?

An electronic signature is a broad legal category that includes any electronic indication of intent to sign — a typed name, a clicked checkbox, a scanned image of a handwritten signature. A digital signature is a specific cryptographic mechanism that uses public-key cryptography to prove the signer identity and detect tampering. All digital signatures are electronic signatures, but not all electronic signatures are digital signatures.

What is a qualified electronic signature?

A qualified electronic signature (QES) is the highest trust level under the EU eIDAS Regulation. It requires a cryptographic digital signature created by a qualified electronic signature creation device, backed by a qualified certificate from a trusted service provider who has verified the signer identity in person or through equivalent means. A QES has the same legal standing as a handwritten signature across the EU.

Why does signature verification fail?

Digital signature verification fails when the document has been modified after signing, when the signing certificate has expired or been revoked, when the certificate chain is incomplete or untrusted, when the signature was created with an outdated algorithm (like SHA-1 or RSA-1024), or when the verification software cannot access the necessary trust anchors. Each failure has a different security implication.

Explore the Digital Signer Tool: Try it now

Try NovelCrypt Tools

Experience military-grade encryption for your sensitive data. Create self-destructing messages, encrypt files, or explore our experimental lab tools.

Explore NovelCrypt