A drawn signature added to a PDF with our Sign PDF tool made the file 399 bytes bigger. That is the whole of it: a few curves drawn in the page’s content, the same kind of instructions that draw a line under a heading. Nothing in the file says who drew them, when, or whether the page has changed since. A certificate-based digital signature is built to say exactly those things, and it works in a different part of the file altogether.
What our tool writes into the PDF
On 24 September 2026 we signed a one-page memo three ways in Chromium 153 and listed the objects in each saved file with pdf-lib, against the same memo saved with no signature.
| What we placed | Bytes added | New objects | Signature field or byte range |
|---|---|---|---|
| Drawn signature | 399 | 3 content streams (the curves, plus save and restore of the drawing state) | None |
| A signature picture, 900 × 220 pixels | 8,014 | The picture, its transparency mask and content streams | None |
| Today’s date as text | 450 | Content streams and a reference to the built-in Helvetica font | None |
None of the three files had a form field of the signature type, a /ByteRange, a certificate or an AcroForm dictionary. To a PDF reader, our signature is part of the page’s drawing, no different from the printed name beneath it. Anyone with a PDF editor can move it, copy it to another document or delete it. That is also true of a signature you print, sign in ink and scan, which is what our tool replaces: a picture of your signature on the page.
What a certificate signature adds
The PDF standard, ISO 32000-1, describes a digital signature in section 12.8 as something that “may be used to authenticate the identity of a user and the document’s contents”. The signing app computes a digest of the file’s bytes, listed in a ByteRange entry that should cover the entire file except the signature value itself, and stores it signed with the signer’s private key. A reader checks it by computing the digest again; in the standard’s words, “differences in the digest values indicate that modifications have been made since the document was signed”. The signature lives in a signature field, with the signer’s certificate and optionally a time, a reason and a place.
A certificate signature can also be invisible. It proves who signed and that the bytes haven’t changed, which a drawn one can’t, and a drawn one shows a reader where someone signed, which a certificate signature doesn’t have to.
Why signing an already signed PDF breaks it
The standard notes that when a signed PDF is changed by adding to the end of the file, an incremental update, the signed bytes stay intact and the earlier state can be recreated. Our tools don’t save that way; they write a fresh file, which also lets them strip the hidden details. Every byte range in the old signature then points at the wrong bytes. So when a PDF you open already carries a signature, the tool says so before you save. We tested that warning on a PDF with a signature field we built ourselves, not on a real signed contract.
If you need to add your name to a PDF that someone has already signed with a certificate, ask them how they want it done. When a document asks you to print it, sign it and send it back, a drawn signature puts the same mark on the page without the printer.