Sun, Jul 12, 2026NY 8:00 PM EDTLA 5:00 PM PDTLON 1:00 AM GMT+1PAR 2:00 AM GMT+2DXB 4:00 AM GMT+4SIN 8:00 AM GMT+8TOK 9:00 AM GMT+9SYD 10:00 AM GMT+10UTC 12:00 AM UTCPayment alerts updated guide pathsScam watch official links firstConsumer alertsSupport-scam watchMoney help deskHow-to guides
Strangely Useful

Payment problems, online safety, browser privacy, AI tools, and everyday tech choices.

Browse the site
Topic hubsFake support guideWrong Cash App paymentLatest storiesTopicsPayment helpSearch
All sections
Internet & CultureTech & AISecurity & TrustPractical TechnologyMoney & PaymentsBrowser & PrivacyAI ToolsSoftware & ServicesInternet Culture & Everyday WorkflowsHidden HistoryUseful ThingsEntertainmentQuizzesAboutHow we workHow guides are madeFollow by RSS
AI Tools - story

A Deepfake Detector Score Is a Lead, Not a Verdict

Preserve the original, verify the exact claim and source, check provenance, and use a detector only when its medium and evaluation conditions fit the file.

By Strangely Useful EditorsReviewed by the Strangely Useful AI Tools deskPublished July 12, 2026Updated August 22, 20266 sources7 min read
Quick answer

Verify a deepfake claim by preserving the original, checking source and context, validating provenance, and matching detector evidence to the exact medium.

A media file is checked against its source, provenance, and a bounded detector signal
A detector result is one documented signal beside source, context, provenance, and stakes. Illustration by Strangely Useful.
In this story7 sectionsStart with the claim, not the pixelsPreserve the original before testingFind the authoritative original and full contextRead provenance as provenance, not truthDecide whether a detector fits this fileRecord the detector signal so someone else can reproduce itUse a bounded conclusion

Do not decide that a recording is real or fake from one detector score. First preserve the best original, identify the exact claim being made, and find the earliest authoritative source and full context. A detector can add one bounded signal only when it was evaluated on the same kind of media and manipulation you are examining.

If an urgent voice note or video asks for money, a password, a recovery code, or a changed payment destination, stop. Contact the person or organization through a phone number, account, or in-person route you already trust. Do that independent check before uploading the file, replying, or sending anything.

Start with the claim, not the pixels

Separate what the media shows from what the post claims
QuestionWhat to write downWhy it matters
What is the exact claim?Who supposedly spoke or appeared, what supposedly happened, where, and whenAn authentic clip can still carry a false date, location, identity, translation, or caption
What is the source?The account, URL, post time, filename, and the earliest version you can locateReposts remove context and often recompress or crop the file
What decision depends on it?Share, payment, account access, employment, election, safety, legal, or no immediate actionHigher stakes require stronger evidence and qualified review

Use the viral-claim verification guide for the broader source-checking method. The deepfake-specific job begins after the claim and source have been made explicit.

Preserve the original before testing

  1. Save the highest-quality version you can lawfully obtain. Keep its original filename and do not edit it.
  2. Record the source URL, account, acquisition date and time, file size, and a cryptographic hash when the decision is consequential.
  3. Work on a copy. Messaging, screen recording, cropping, transcoding, noise removal, and social-platform downloads can change the features a detector reads.
  4. Do not upload private, abusive, medical, identity, or investigation evidence to an unknown detector. Read its retention and reuse terms or use an approved forensic environment.

For capture and chain-of-custody details, use the separate guide to take screenshots that preserve evidence. A screenshot can document a post, but it is not a substitute for the original audio, image, or video file.

Find the authoritative original and full context

  1. Search the quoted words and event. Look for a complete recording from the speaker, venue, broadcaster, public body, or another accountable source.
  2. Run reverse image searches on useful frames. Extract clear frames from different moments, then search more than one frame. A match may reveal an older video, a different location, or the uncropped source.
  3. Compare the whole scene. Check preceding and following speech, camera angle, weather, signage, audience response, audio track, and published schedule.
  4. Check whether the claimed person confirms or denies it. Treat a denial as another source to evaluate, not automatic proof by itself.

Dubbing, compression, frame interpolation, unstable connections, and editing can create lip-sync or visual oddities in authentic media. Conversely, clean-looking media can still be synthetic. Visual intuition alone is not a reliable final test.

Read provenance as provenance, not truth

C2PA Content Credentials can bind signed assertions about an asset's source and edit history to that asset. The current C2PA specification says the system should not decide whether provenance is “good” or “bad”; it validates whether assertions are associated with the asset, correctly formed, and tamper-evident.

  1. Validate the credential rather than trusting a badge or screenshot of one.
  2. Read who signed it, which asset it covers, which actions are asserted, and whether validation reports errors.
  3. Compare the signer and asserted history with the claim you are investigating.

A valid credential can support a source-and-history statement; it does not prove that the depicted event, caption, or speaker's words are true. Missing credentials do not prove a file is fake because credentials may never have been added or may be stripped during distribution. C2PA's security and harms guidance also documents threats, privacy risks, and unequal access that implementations must consider.

For a deeper explanation of manifests, signatures, edits, and missing credentials, use the Content Credentials and C2PA guide.

Decide whether a detector fits this file

Fit checks before interpreting a detector result
Fit checkQuestion to answer
MediumWas the tool evaluated for image, video, audio, or text—the medium you actually have?
ManipulationDoes it target face swaps, lip sync, synthetic speech, fully generated media, edits, or the relevant technique?
ConditionsDo evaluation data include unfamiliar generators, recompression, cropping, noise, resolution, language, demographics, and platform processing like this file?
MetricDoes the publisher report false positives, false negatives, thresholds, calibration, and results on held-out data?
VersionCan you identify the exact model, service version, date, and settings used?

NIST's synthetic-content guidance describes detection as one family of techniques alongside provenance, labeling, watermarking, and human-assisted methods, each with limitations and tradeoffs. NIST OpenMFC evaluates media-forensics systems on defined tasks and datasets; its published program results are evidence about those tested conditions, not certification of every consumer detector or every new generator.

If the tool does not document a matching medium, manipulation, evaluation set, and metric, do not convert its output into an authenticity claim. “83% fake” may be a model score, a threshold output, or a user-interface label—not an 83% probability that the real-world claim is false.

Record the detector signal so someone else can reproduce it

  • Tool and provider
  • Model or service version and test date
  • Input copy hash, filename, medium, duration or dimensions, and any preprocessing
  • Selected task, threshold, settings, and documented evaluation conditions
  • Raw output, displayed label, and any warning or unsupported-format message

Running several opaque consumer tools is not independent confirmation when they may share training data, models, or failure modes. Agreement can justify more investigation; it does not turn correlated scores into proof.

Use a bounded conclusion

Labels that say only what the evidence supports
LabelUse it when
UnverifiedThe source or claim has not been independently confirmed
Source-context mismatchThe media is authentic or unresolved, but the date, location, identity, edit, or caption does not match the original context
Detector signal onlyA documented, reasonably matched detector produced a result, but source and forensic evidence do not justify an authenticity conclusion
Provenance validatedA Content Credential validates and supports a particular source or edit-history statement, without deciding the truth of the scene
Escalated for forensic reviewEmployment, election, fraud, safety, abuse, or legal consequences require a qualified examiner and documented chain of custody

Do not publish a consumer detector score as a headline or accuse a person of fabrication from a signal alone. If you must communicate before review finishes, say what is known, what remains unverified, which checks were performed, and what evidence would change the conclusion.

The useful sequence is: preserve the original, state the claim, locate source and context, validate available provenance, test only with a fit-for-purpose detector, record the exact run, independently verify urgent requests, and stop at the narrowest label the evidence supports.

Sources used6 sources checked for this guide
  1. Reducing Risks Posed by Synthetic Content: An Overview of Technical Approaches to Digital Content TransparencyNational Institute of Standards and Technologyofficial-publication - Retrieved Aug 22, 2026 - record checked

    Used forNIST describes automated content-based detection as one synthetic-content transparency technique alongside provenance, labeling, watermarking, and human-assisted methods, with limitations and tradeoffs.

  2. Open Media Forensics ChallengeNational Institute of Standards and Technologyofficial-publication - Retrieved Aug 22, 2026 - record checked

    Used forNIST OpenMFC evaluates media-forensics systems on specified tasks and datasets, so its results characterize submitted systems under those evaluation conditions rather than certifying all detectors.

  3. OpenMFC 2022 Evaluation ProgramNational Institute of Standards and Technologyofficial-publication - Retrieved Aug 22, 2026 - record checked

    Used forNIST OpenMFC evaluates media-forensics systems on specified tasks and datasets, so its results characterize submitted systems under those evaluation conditions rather than certifying all detectors.

  4. Content Credentials: C2PA Technical Specification 2.4Coalition for Content Provenance and Authenticityofficial-standard - Retrieved Aug 22, 2026 - record checked

    Used forThe C2PA 2.4 specification validates whether provenance assertions are associated with an asset, correctly formed, and tamper-evident without making a value judgment about whether provenance is good or bad. - A valid C2PA credential supports bounded source-and-history assertions but does not by itself establish the truth of a depicted event or accompanying caption.

  5. C2PA Security Considerations 2.4Coalition for Content Provenance and Authenticityofficial-standard - Retrieved Aug 22, 2026 - record checked

    Used forC2PA security guidance documents attacks that can strip manifests or abuse compromised signing keys, so validation and signer context remain necessary.

  6. C2PA Harms Modelling 2.4Coalition for Content Provenance and Authenticityofficial-standard - Retrieved Aug 22, 2026 - record checked

    Used forC2PA harms guidance identifies privacy, accessibility, surveillance, and unequal-access risks that implementations and users may need to consider.

Guide feedback

Was this guide useful?

No personal details are collected here. Use corrections for factual issues.