Skip to main content
← Back to blog

How we created a fake screenshot in minutes

Thousands of screenshots circulate online every day, treated as evidence in media stories, workplace disputes and public arguments. But a screenshot is only an image — and any image can be edited. Here is how easily, what can still be detected, and what to do instead.

Screenshots Manipulation Digital evidence ~12 min read

The basic problem

Every day, thousands of screenshots circulate online. They capture posts, private messages, payment confirmations, order details and conversations, and they move faster than anyone can check them.

They end up being treated as evidence — in newsrooms, in workplace disputes, in arguments between neighbours, and in court filings. Often they are the only thing anyone has, because the original was deleted within hours.

But a screenshot is only an image.

And like any other image, it can be edited. What makes this uncomfortable is not that manipulation is possible — everyone knows that in the abstract — but how little effort it takes.

The experiment: how we did it

We took a genuine page in an ordinary browser and produced a convincing fake of it. No image editor was involved, no specialist software, and no particular skill. The whole thing took under two minutes.

The method is this: open the page, open the browser's built-in developer tools, and edit the text directly in the rendered document. The browser re-renders the page with the changed text. Then take a screenshot in the normal way.

  • The result is a genuine screenshot — of a page that genuinely displayed those words at that moment
  • Every font, spacing, shadow and rounded corner is correct, because the browser drew them
  • There are no editing artefacts, because no image editing took place
  • Timestamps, usernames, follower counts and verification badges can all be altered the same way

This is the part that surprises people. The usual advice — look for blurry edges, mismatched fonts, uneven compression — assumes the fake was made in an image editor. A fake made through the browser leaves none of those traces, because at pixel level it is not a fake at all. It is an authentic capture of a manipulated page.

We are deliberately not publishing a step-by-step guide. The point is not to teach the technique, which is neither secret nor difficult, but to explain why the resulting image cannot be trusted on inspection alone.

What forensic examiners can — and cannot — detect

It is often assumed that an expert can simply determine whether an image was manipulated. Sometimes yes. Frequently not.

What can be detected

  • Fakes made in an image editor, which often leave inconsistent compression, mismatched noise patterns or edges that do not align
  • Metadata inconsistencies, where the file claims to have been produced by software or a device that does not match the content
  • Sloppy work: wrong font weights, incorrect line spacing, interface elements from the wrong version of an application
  • Content-level impossibilities, such as a timestamp that does not match how that platform actually displays times, or a feature that did not exist on that date

What cannot be reliably detected

  • A screenshot taken of a page manipulated in the browser, because the image itself is authentic
  • A photograph of a screen displaying manipulated content, which destroys most digital traces
  • Anything re-saved, re-compressed or passed through a messaging platform, which strips metadata and normalises compression

The last point matters more than it sounds. By the time a screenshot has been forwarded through a messaging app, posted to a platform and downloaded again, most of what an examiner might have used is gone — including from genuine images.

Detection cannot be relied on. Provenance can.

Practical checks before you believe a screenshot

None of these proves authenticity. Together they catch careless fakes, which is most of them, and they cost nothing.

  • **Ask for the original.** A genuine screenshot has a source: a live post, a message thread, an account. Someone who cannot or will not point to it is telling you something.
  • **Check the interface against the current version.** Platforms change their layout constantly. A fake often reproduces an older design, or mixes elements from different versions.
  • **Check how the platform actually renders time.** Relative times, absolute times, time zones and date formats differ by platform and by context, and are frequently wrong in fakes.
  • **Reverse image search it.** Widely shared fakes usually have a history, and often a debunking.
  • **Look for the account itself.** If the profile does not exist, was renamed, or has no trace of the content, that is significant.
  • **Consider who benefits.** Not a technical check, but the most reliable single indicator that something deserves scrutiny.

Treat all of this as triage rather than verification. It tells you when to be suspicious. It cannot tell you when to be confident.

The problem of digital trust

That does not mean every screenshot is fake. Most are perfectly genuine. It means that without verification, authenticity cannot be assumed — and that the asymmetry runs in an uncomfortable direction: producing a fake takes minutes, while disproving one can take weeks and may not succeed.

In practice this has consequences:

  • Reputational harm caused by manipulated content that spreads before anyone checks
  • Media stories built on unverified material
  • Complications in court proceedings, where the other side need only raise the possibility of manipulation
  • A second-order effect: genuine evidence dismissed because fakes are known to be easy

That last one is the most damaging. Once everyone knows screenshots can be faked, the honest party with a real screenshot is in the same position as the dishonest one.

Why a screenshot is often not enough as evidence

From a legal and practical perspective, a screenshot usually does not establish:

  • When it was actually created
  • Whether it matches what the source actually displayed
  • Whether it was modified afterwards
  • Whether it captures the full context rather than a convenient fragment
  • Where it came from at all — which page, which account, which moment

Its evidentiary value is therefore limited, particularly once the other side challenges its authenticity. In most European legal systems a court will still admit and weigh it, but a contested screenshot with nothing behind it carries little weight against a party willing to deny it.

The question in a dispute is rarely 'what does the image show'. It is 'how do we know'.

How to preserve digital content properly

The solution is not better inspection. It is capturing content in a way that makes later verification possible — recording not just what was displayed, but the circumstances under which it was recorded.

Such a record may include:

  • A cryptographic fingerprint (hash) of the content, so any later change is detectable
  • A verifiable timestamp from an independent third party, rather than the claim of whoever made the capture
  • The source address and the server's response, including the network layer
  • The page's underlying source code, not only its visual appearance
  • A documented method, so the process can be examined and repeated

The difference is fundamental. A screenshot asserts that something existed. A verifiable capture allows a third party to check that assertion without trusting the person who made it.

What makes a record verifiable

Three properties do the work, and each addresses a different way of doubting.

  • **Integrity** — the record cannot have been altered since it was made. A cryptographic hash establishes this: change a single byte and the fingerprint no longer matches.
  • **Time** — the record existed at a specific moment. This has to come from someone independent. A timestamp you generate yourself proves nothing, which is why qualified timestamping providers exist and why their role is regulated.
  • **Independence** — verification must not depend on the goodwill of the party presenting the evidence, or on the continued existence of the company that produced it. If checking the record requires asking the vendor, it is not really verifiable.

In the European Union this last point has a legal dimension. Under the eIDAS Regulation, a qualified electronic timestamp carries a presumption as to the accuracy of the time and the integrity of the data — which shifts who has to prove what.

What to do if a fake screenshot is being used against you

This is an increasingly common situation and the instinct — to argue about the image — is usually the wrong starting point.

  • **Capture the fake itself**, wherever it is being shared, before it is deleted. You will need to show what was circulated, not describe it.
  • **Capture the genuine content** it purports to show, if it still exists, in a verifiable form. This is the strongest response available.
  • **Preserve your own records**: the real message thread, the real post, account data you can export from the platform.
  • **Request your data from the platform.** Under GDPR Article 15 you can obtain the personal data an organisation holds about you, which for messaging services can include the actual message history.
  • **Do not engage with the substance publicly** before you have the record. Arguing about what a screenshot really said, without being able to show it, tends to reinforce the fake.

The asymmetry described earlier can be reversed here. The party with a verifiable capture of the genuine content is in a materially different position from the party asserting that an image is false.

Technology for verifiable evidence

As digital content increasingly ends up in disputes, tools have emerged that create records designed to be checked rather than trusted. What distinguishes them is not image quality but what surrounds the image.

GetProofAnchor is one such tool: it captures online content together with the data needed to verify it later — a cryptographic fingerprint, a qualified electronic timestamp under eIDAS, the source address and network response, and a documented method. Verification is possible with an open tool, without our involvement, and remains possible if we cease to exist.

The goal is not to decide what is true. The goal is to make truth verifiable.

Conclusion

A screenshot is a fast and practical way to capture what is on a screen, and most screenshots are honest. But in an age where a convincing fake takes two minutes and no expertise, an image alone can no longer settle a question that someone is motivated to dispute.

The response is not to become better at spotting fakes, because the good ones cannot be spotted. It is to change what is captured: if digital content is meant to serve as evidence, its origin, integrity and time must be demonstrable by someone other than the person presenting it.

That is where the future of digital evidence lies — not in inspecting images more closely, but in recording them in a way that makes inspection unnecessary.

From a quick screenshot to verifiable evidence

Send us the address and we capture the page, post or conversation with a qualified electronic timestamp — typically within 60 minutes. You get a record that can be verified by anyone, including years later and without our involvement.

One-off, from €49. No account, no subscription. Not legal advice — admissibility depends on jurisdiction and circumstances.

Frequently asked questions

How easy is it really to fake a screenshot?

Minutes, with no special tools. Open the page, edit the text directly using the browser's built-in developer tools, and take the screenshot normally. The result is pixel-perfect because the browser rendered it — every font, shadow and rounded corner is correct, and there are no editing artefacts, because no image editing took place. This is why courts are right to treat uncorroborated screenshots with caution.

Can experts detect a faked screenshot?

Sometimes. Fakes made in an image editor often leave inconsistent compression, mismatched noise or misaligned edges, and metadata may contradict the content. But a fake produced through the browser leaves none of those traces, because the image is an authentic capture of a genuinely rendered — if manipulated — page. Re-saving, forwarding through messaging apps or photographing a screen removes most remaining traces, including from genuine images. Detection cannot be relied upon.

How can I tell if a screenshot is real?

You usually cannot be certain from the image alone, but several checks catch careless fakes: ask for the original source and see whether it exists; compare the interface against the platform's current design, since fakes often reproduce older layouts; check how that platform actually renders times and dates; reverse image search it, as widely shared fakes often have a debunking history; and look for the account itself. Treat this as triage — it tells you when to be suspicious, not when to be confident.

Are screenshots accepted as evidence in court?

In most European legal systems a screenshot will be admitted and then weighed, rather than excluded outright. The problem is the weight it carries once challenged. A screenshot on its own does not establish when it was made, whether it matches what the source displayed, or whether it was altered afterwards — so a party willing to dispute it can do so cheaply. Records with a verifiable timestamp and cryptographic integrity are in a materially different position.

What should I do if someone is using a fake screenshot against me?

Capture the fake itself wherever it is circulating, before it is deleted — you will need to show what was shared rather than describe it. Then capture the genuine content it purports to show, if it still exists, in a verifiable form; this is the strongest available response. Preserve your own records and consider requesting your data from the platform under GDPR Article 15, which for messaging services can include the actual message history. Avoid arguing publicly about what the content really said before you can show it.

What makes a capture verifiable rather than just a picture?

Three things. Integrity: a cryptographic hash of the content, so any subsequent change is detectable. Time: a timestamp from an independent third party rather than the claim of whoever made the capture — under the eIDAS Regulation, a qualified electronic timestamp carries a presumption as to the accuracy of the time and the integrity of the data. And independence: verification must not require the cooperation of the party presenting the evidence, or the continued existence of the company that produced it.