Someone shows you a photo with a timestamp and a location and treats it as settled. It is not settled. Every field in that block can be rewritten in about ten seconds with a free tool, and nothing in the file records that it happened.
This matters because metadata gets used as proof in insurance claims, rental disputes, workplace investigations and family arguments, usually by people who have no idea how editable it is. Here is what photo metadata is genuinely worth.
Can EXIF data be faked, and how easily?
Yes, completely, and the barrier is close to zero.
Command-line tools have been rewriting these fields for over twenty years. Phone apps do it through a form. Any field you can read, you can change: shutter time, camera model, serial number, coordinates, the lot. Copying an entire metadata block from one photo onto another is a single command.
There is no signature over standard EXIF and no checksum protecting it. The format was designed in the 1990s so cameras could record settings for photographers, not so courts could verify anything. Expecting tamper resistance from it is expecting a feature nobody built.
The limits of EXIF forensics, stated plainly
Specialists do get useful signals from image files, but not from reading the fields at face value. They look for disagreement between independent parts of the file.
A JPEG's compression signature carries traces of the software that produced it, and that can contradict the claimed camera. Field ordering within the metadata block differs between manufacturers, so a Canon body that lays out its data the way a phone editor does is worth a second look. The embedded thumbnail sometimes lags behind an edit. Quantisation tables can be compared against known camera profiles.
Every one of these is circumstantial, and a careful forger defeats all of them by re-saving the file through something that produces consistent output. The honest summary is that forensic analysis can sometimes raise questions about a file and can almost never answer them from the file alone.
If you want to see the fields for yourself before deciding what they are worth, our photo metadata reader shows the full set without uploading anything.
How a C2PA content credentials check differs
Content credentials are the serious attempt to fix this, and they work on a completely different principle.
Instead of storing unprotected fields, C2PA records a signed manifest describing how an image was created and what was done to it, cryptographically bound to the image data. Alter the picture or the record and the signature no longer validates. Some recent cameras write credentials at capture, and several major editors add entries when they modify a file.
Two caveats keep this from being the answer people want. Coverage is thin — most photos in the world carry no credentials at all, and their absence means nothing. And a manifest can simply be stripped, at which point you have an ordinary image with no provenance rather than a file that announces it was tampered with.
We read and report what a file contains. We do not verify signatures or claim a file is authentic, because doing that properly requires trust infrastructure we are not in a position to operate.
AI generated image metadata is not a detector
The hope is understandable: if generators tag their output, checking the tag identifies synthetic images. It does not work, for three reasons.
First, tags are removable by anyone, and removing metadata is a one-click operation on any tool including ours. Second, a screenshot of a generated image carries no trace of its origin, and screenshotting is the most common way these images travel. Third, most images with no metadata are simply photographs that went through a platform, so treating an empty block as evidence of AI generation produces constant false positives.
Conversely, an AI image can be given a full and entirely plausible camera metadata block in seconds. So the presence of convincing EXIF is not evidence a photo is real, and the absence of generator tags is not evidence it is not synthetic. Detection has to work on the pixels, and that is a hard and separate problem.
How to verify a photo is real, in practice
Provenance beats metadata every time. The questions worth asking are about the file's journey, not its fields.
Where did you get it, and from whom directly? Does an original exist, and can the person who took it produce it? Is there a RAW file alongside the JPEG, which is much more work to fake convincingly? Are there other photos from the same session showing the same scene from different angles? Does anything outside the image corroborate the claim — a receipt, a message, a witness, a second photo from a different device?
A reverse image search is often the fastest single check, because it catches the most common case by far: an old photo being presented as new. That is a far more frequent problem than a carefully forged metadata block.
Coordinates deserve the same scepticism as everything else, and they are the field people lean on hardest. Our GPS reader shows what a file claims about where it was taken, which is a useful starting point and not a conclusion. Note also that we will not estimate a location from the picture itself — that is a surveillance capability, and building it is a different decision from reading a field.
When metadata does help, it is as a consistency check on a story you already have. Coordinates that match where someone says they were, a timestamp that fits the sequence, a camera model that matches the phone they own. Agreement is mild support. Disagreement is worth asking about. Neither settles anything.
If a photo might matter later
Handle the file, not the metadata. Keep the original exactly as it came off the device, and work on copies. Do not send it through a messaging app, because that produces a re-encoded version with the fields stripped and no way to recover them.
Back it up somewhere with its own timestamps, note where it came from at the time rather than months later, and keep the RAW file if there is one. If you are on the other side of this and about to share a photo publicly, remember that everything above cuts both ways — stripping the metadata protects you and also removes your own record. Decide which you need before you click.
The uncomfortable summary
Photo metadata proves very little on its own. It is a useful record for photographers, a real privacy risk for everyone, and weak evidence for anybody.
Most tools in this space imply the opposite, because a viewer that says "here is where this was taken" sounds more impressive than one that says "here is what this file claims". We would rather say the second thing. If you want the background on what the fields are, our guide to EXIF data covers them, and what platforms strip on upload explains why so many files arrive with nothing left to trust.
