Skip to content

What is a digital signature? Definition, examples and how it works

A digital signature is a cryptographic method that proves a document came from a specific signer and has not changed since. Most people searching for the term actually need an electronic signature, and the difference decides which tool you should be using.

Comparisons11 min read
Two plain brass keys and a blank deep blue wax seal resting on folded cream paper, lit from one side on a terracotta-orange wooden surface.

A digital signature is a cryptographic method of signing a document that proves two things at once: that the document came from the holder of one specific private key, and that not a single byte of it has changed since it was signed. It is produced by hashing the document and signing that hash with a private key, and it is checked with the matching public key.

Most people who search for this term are about to sign a contract, and what they need is an electronic signature, which is a broader legal category. The two are not interchangeable, and the difference decides what you should be buying. This article covers the definition, how the cryptography works, what a digital signature looks like in practice, whether it is legally binding, how to create one, and when you genuinely need one.

Digital signature definition

A digital signature is an electronic signature that uses public-key cryptography to bind a signer's identity and a document's exact contents together, so that any later change to the document invalidates the signature. The machinery behind it is a public key infrastructure (PKI): a certificate authority vouches for the link between a person or organisation and a public key, and issues a certificate saying so. The standards you will see named are X.509 for the certificate format, PAdES for signatures embedded in PDFs, and RSA or ECDSA for the signing operation itself.

In plain English: signing reduces the file to a short fingerprint, then locks that fingerprint with a key only you hold. Anyone can unlock the fingerprint with your public key and recompute the file's fingerprint themselves. If the two match, the file is intact and it was signed by whoever held your private key.

A digital signature is designed to guarantee three properties:

  • Authentication. The signature could only have been produced by the holder of one specific private key, and a certificate ties that key to a named person or organisation.
  • Integrity. The signature covers a hash of the document. Change a comma and the recomputed hash no longer matches, so verification fails.
  • Non-repudiation. The signer cannot easily deny signing, because nobody else should have been able to produce that signature.

Non-repudiation is the property worth being careful about. It holds only for as long as the private key stayed under the signer's control. A key copied off an unlocked laptop produces signatures that are cryptographically perfect and evidentially worthless, which is exactly why higher-assurance signing keeps the key on a smart card or hardware token rather than in a file on a disk.

Digital signature vs electronic signature: what is the difference?

An electronic signature is a legal category; a digital signature is a technology. Every digital signature is an electronic signature, but most electronic signatures are not digital signatures. An electronic signature is any electronic sound, symbol or process attached to a record and adopted with the intent to sign it. A digital signature is one particular way of producing one, using a key pair and a certificate.

 Electronic signatureDigital signature
What it isA legal category covering any electronic act of signingA cryptographic technique using a key pair and a certificate
What it provesIntent to sign, supported by the record around itThat a named key holder signed, and the bytes are unchanged
TechnologyVaries: typed name, drawn mark, click to accept, hashing, audit logPublic-key cryptography, X.509 certificate, PKI
What the signer doesTypes, draws or clicksUnlocks a certificate or digital ID, usually with a PIN or token
Who vouches for identityThe provider's record of the transactionA certificate authority
Typical useContracts, NDAs, offer letters, leases, invoicesGovernment filings, code signing, signed email, EU qualified signatures
Legal frameworkESIGN and UETA in the US; simple or advanced under eIDASThe same laws, plus the certificate requirements for eIDAS qualified

The distinction is worth getting right because it changes what you buy. Most commercial agreements in the United States and much of Europe are signed with an electronic signature backed by a document hash and an audit trail rather than a certificate. That is what closeit.fast produces: a sealed PDF, a SHA-256 hash of it, and a timestamped record of who was sent the document, when they opened it and when they signed. It is an electronic-signature service, not a certificate authority, and it does not issue digital certificates.

Certificate-based digital signatures earn their extra cost in a narrower set of cases: a government portal that accepts nothing else, a counterparty whose system validates certificates, software or email being signed, or a European transaction that specifically calls for a qualified signature. The three eIDAS tiers are the clearest map of where that line falls, and we set them out in simple, advanced, qualified: which one your document needs.

How does a digital signature work?

A digital signature is created in four steps: the document is hashed, the hash is signed with the signer's private key, the signature and the signer's certificate are attached to the document, and the recipient's software verifies the signature using the public key from that certificate.

  1. Hash the document. A hash function such as SHA-256 reduces the entire file to a short fixed-length fingerprint. The same file always produces the same fingerprint, and a file differing by one byte produces a completely different one.
  2. Sign the hash with the private key. The signer's software performs a private-key operation on that fingerprint, and the result is the signature. With RSA this is literally an encryption of the hash; with ECDSA it is a different operation that yields the same guarantee. The document itself is not encrypted, so a digitally signed PDF stays readable by anyone.
  3. Attach the signature and the certificate. Both are embedded into the file, which is what makes a signed PDF self-contained: everything needed to check it travels with it.
  4. Verify. The recipient's software recomputes the hash of the document it received, uses the public key from the certificate to recover the hash that was signed, and compares the two. It also checks that the certificate is unexpired, not revoked, and issued by an authority that machine already trusts.

What a digital signature certificate is, and who issues one

A digital signature certificate is an electronic credential binding a public key to a verified identity, issued by a certificate authority after some form of identity check. Adobe Acrobat calls the same thing a digital ID. The certificate is the part carrying the trust: the cryptography only proves that a key signed something, and the certificate is what says whose key it was.

What digital signature verification actually reports

When a PDF reader shows a green tick and the words "Signed and all signatures are valid", it is reporting two separate findings: the document has not changed since it was signed, and the signing certificate chains up to a root that reader trusts. The familiar warning that "at least one signature has problems" usually means the second check failed rather than the first, most often because the certificate is self-signed and no trust store recognises it.

That is the catch with a free digital signature certificate. A self-signed digital ID takes about a minute to create in Acrobat, and it will validate perfectly on the machine that made it and nowhere else, because no other machine has any reason to trust it. A certificate a recipient's software will accept has to come from an authority already in their trust store, and those are sold rather than given away.

A signature that validates only on the machine that produced it has proved something to exactly one person.

What does a digital signature look like? Four examples

A digital signature usually looks like nothing at all. It is data inside the file, not a picture on the page. What you actually see is your software's report on it: a banner across the top of a PDF, a signature panel naming the certificate and the signing time, or a small badge on an email. The handwritten-looking squiggle that often sits alongside it is a separate, purely cosmetic image and proves nothing on its own.

  • A PDF signed in Adobe Acrobat with a digital ID. The reader shows a signature banner and a panel naming the certificate holder and the time of signing.
  • A qualified electronic signature made with a national eID card. The signer inserts the card and enters a PIN, and the signing key never leaves the card.
  • A code-signing certificate on a software installer. This is why Windows shows a verified publisher name instead of "Unknown publisher" when you run an installer.
  • An S/MIME signed email. The mail client shows a seal or ribbon icon confirming the message came from that address and was not altered in transit.

Is a digital signature just typing your name?

No. Typing your name into a document involves no key pair and no certificate, so it is not a digital signature. It can still be a perfectly valid electronic signature, because ESIGN and UETA both turn on the intent to sign rather than on the form the signature takes. The difference is where the proof comes from. A typed name on its own carries none. A typed name captured by a signing service arrives with a record of the address the invitation was sent to, when it was opened, the IP address it was signed from, and a hash of the finished document, though it is worth reading what an emailed signing link does and does not prove before leaning on any of it.

Is a digital signature legally binding?

Yes. In the United States a digital signature is legally binding because it is a form of electronic signature, and the governing statutes are technology-neutral. 15 U.S.C. § 7001(a) provides that a signature may not be denied legal effect solely because it is electronic, and UETA § 7 says the same at state level. UETA has been adopted in 49 states plus the District of Columbia, Puerto Rico and the US Virgin Islands; New York is the sole holdout and applies its own Electronic Signatures and Records Act instead.

Neither statute rewards you for using cryptography. Both ask about intent to sign, consent to transact electronically, whether the signature is attributable to the person, and whether the record can be retained and reproduced. A certificate helps with attribution, and an audit trail addresses the same question by other means. When a signature is genuinely disputed, the argument is about attribution under UETA § 9 rather than about the algorithm, which is the subject of they say they never signed it.

In the European Union, eIDAS defines three levels of electronic signature. A simple electronic signature cannot be denied legal effect merely for being electronic. An advanced signature must be uniquely linked to the signer and detect any later change to the data. Only a qualified signature, made with a certificate from a qualified trust service provider on a certified signing device, is given the equivalent legal effect of a handwritten signature by Article 25(2). Everything below that tier is still evidence, weighed like any other document.

A separate limit applies whatever technology you choose: wills, most family-law papers and a defined list of notices are excluded from electronic signing altogether by 15 U.S.C. § 7003. The full list of exclusions is worth checking before sending anything unusual.

How to create a digital signature

There are three practical routes, and the right one depends entirely on who has to accept the result.

  • Adobe Acrobat with a digital ID. Create a self-signed ID in a couple of minutes for internal use, or install one issued by a certificate authority, then use Certificates and Digitally Sign to draw the signature box onto the page. This is how most people first add a digital signature to a PDF.
  • A certificate from a certificate authority or national ID scheme. Necessary when the receiving party has to verify you against a trusted root. EU qualified trust service providers, national eID cards and government-licensed authorities all issue these, usually after an identity check and often on a hardware token.
  • An electronic-signature service, for ordinary agreements. Upload the document, place the fields, send each signer their own link, and the service returns a sealed PDF with a certificate of completion. With closeit.fast that is four steps and no certificate to buy, and every account gets one free envelope each month. See what it costs.

Hardware belongs in the same picture. A signature pad or signing tablet captures the shape and pressure of a handwritten stroke, which makes for a richer electronic signature but not a digital one. A USB crypto token or smart card holds a private key so that a certificate-based signature can be made without the key ever being copied onto the computer.

When do you actually need a certificate-based digital signature?

You need a certificate-based digital signature when a specific system, regulator or counterparty requires one, and almost never otherwise. The clear cases are:

  • A government portal or filing system that accepts only certificate-signed documents.
  • A counterparty whose policy or software validates certificates.
  • An EU transaction where a qualified electronic signature is specified.
  • Signing software or firmware, where code signing is the norm.
  • Signing email with S/MIME.

For the everyday agreement, a contract, an NDA, an offer letter, a lease, a bill of sale or a statement of work, an electronic signature with a proper evidence record is the standard and it is enforceable. What matters in a dispute is not the cipher. It is whether you can show who received the document, what they were shown, when they signed and that the file has not changed since, which is what a hash plus an audit trail gives you. You can check that hash yourself with one command, and our security page sets out what our own record does and does not establish.

Frequently asked questions

What is an example of a digital signature?

A PDF signed in Adobe Acrobat with a digital ID is the most common example: the file carries an embedded signature and certificate, and the reader displays a banner confirming the document has not changed since signing. Other everyday examples are a code-signing certificate on a software installer and an S/MIME signed email.

Is a digital signature just typing your name?

No. Typing your name involves no key pair and no certificate, so it is not a digital signature. It can still be a valid electronic signature under ESIGN and UETA, because those laws turn on the intent to sign rather than the form, but the proof then has to come from the record around the signature rather than from cryptography.

What is a digital signature certificate and how do I get one?

A digital signature certificate binds your public key to your verified identity and is issued by a certificate authority after an identity check. You obtain one by buying it from a commercial authority, or through a national eID scheme where one exists. Free self-signed certificates can be generated in Acrobat, but they will not validate on anyone else's machine.

How do I verify a digital signature on a PDF?

Open the file in a PDF reader and open its signature panel. The reader reports whether the document has changed since signing and whether the certificate chains to a trusted root. A warning that a signature has problems usually means the certificate is untrusted rather than that the document was altered.

Can I remove a digital signature from a PDF?

Yes, if you hold the file and are permitted to edit it, a PDF reader can clear a signature field, which removes the signature rather than forging a new one. Altering anything else in a signed document breaks the signature instead, which is the whole point of it being tamper-evident.

Try it on a real document

Everything described here is what closeit.fast does on every envelope, including on the free tier. Send one and read the trail it produces.

Start signing free

Your first envelope is three minutes away.

Upload a PDF, place the fields, send the links — and get back a sealed document with a certificate of completion attached to the end of it.

One free envelope every monthNo card, no sales call, no per-signature fee