This website uses cookies

Read our Privacy policy and Terms of use for more information.

AI-assisted content
 
Guide
GDE-004
 
 
Topic
Source verification
 
 
Domain
Humint
 
 
Last updated
June 2026

01

What it is

Source verification is the practice of independently confirming that a contact is who they claim to be, using open-source methods that do not rely on the source's own account. It is distinct from content verification, which asks whether the information is accurate. Both are necessary. Neither substitutes for the other.

Source verification is distinct from content verification. Content verification asks whether a claim, document, or piece of footage is accurate. Source verification asks whether the person behind the claim is who they say they are. Both are necessary, but they require different workflows. A source can provide accurate information while misrepresenting their identity, or can hold genuine credentials while providing false information. The two checks must be run independently.

OSINT-based source verification focuses on what is publicly verifiable: does the claimed identity have a digital footprint consistent with the claimed role and history? Does the contact method the source used match identifiers linked to that identity? Are there signs that the identity was constructed recently or artificially? None of these checks replace direct corroboration, but they establish a baseline of digital depth that distinguishes a genuine long-standing identity from a purpose-built persona.

There is a third check that sits between the two, which most source verification guides do not address: what happens when a source passes all identity checks but their information does not corroborate independently? A verified identity with non-corroborating information is still a problem. This guide covers all three layers.

 

When to use this guide

  • Verifying the identity of an unsolicited contact or whistleblower before engaging further.
  • Checking whether a claimed employer, role, or credential is verifiable through public records.
  • Assessing whether a profile photo, email address, or social media account is authentic or purpose-built.
  • Determining whether a source who passes identity checks is providing information that holds up under independent corroboration.

02

How to verify a source: the OSINT workflow

A five-step workflow from initial digital footprint assessment through employer verification, cross-platform identity mapping, photo analysis, and information corroboration.

The following tools are used across the steps below. All are free unless noted.

LinkedIn: Professional network. The primary platform for verifying claimed employment history, role, employer, and professional tenure. Profile existence, connection count, endorsements, and post history all contribute to digital depth assessment. Free to view public profiles.

Wayback Machine: Internet Archive's web capture service. Used to confirm whether a claimed employer's website, staff page, or publication byline existed at the point the source claims to have held the role. Free.

WhatsMyName: Cross-platform username search tool. Used to map the source's claimed username or handle across platforms and assess consistency and age of accounts. Free.

Have I Been Pwned: Breach notification service. Used to assess the age and digital depth of a contact email address, and to identify which platforms the address has been registered on over time. Free.

Google Reverse Image Search: Checks whether a profile photo has appeared elsewhere online under a different name, or is sourced from a stock image library. A key tool for detecting fabricated personas. Free.

 

Before you begin

Run identity checks and information checks separately. Confirming a source's identity does not confirm their information is accurate. A sophisticated deception may use a genuine identity to deliver false information. Complete the identity verification workflow in this guide, then run an independent corroboration check on the information itself before proceeding to publication.

Do not alert the source. Verification queries using the tools in this guide are passive and do not alert the source. Direct contact with a claimed employer (to confirm employment) should only be made through the employer's published main switchboard number, not through contact details provided by the source.

The method
01
Assess digital depth
Goal · Establish whether the claimed identity has a consistent public record across time and platform

Search the source's claimed name on LinkedIn. Note the profile creation date where visible, connection count, number of endorsements, post history, and the consistency of the career narrative. A profile with no connections, no endorsements, and no post history that was created recently is a thin digital footprint regardless of how detailed the bio is. Run the contact email address through Have I Been Pwned to assess how many breach records it appears in and which platforms the address has been registered on over time. A primary email address in use for five or more years will typically appear in multiple breach datasets.

02
Verify the claimed employer independently
Goal · Confirm the employer exists, the role is plausible, and the source's name appears in the employer's own public record

Check the claimed employer's own website, any published staff directory, or relevant professional or regulatory register for the source's name, independently of the LinkedIn entry. Use the Wayback Machine to confirm the employer's staff page or the source's byline existed during the period they claim to have worked there. Call the employer's main switchboard and ask to be connected to the source by name. A genuine employee will either be connectable or will be known to the switchboard operator as currently unreachable; a fabricated identity will often not be recognised at all.

03
Map the identity across platforms
Goal · Confirm the claimed identity is consistently represented across multiple independent platforms

Run the source's claimed username or email handle through WhatsMyName to identify accounts on other platforms. Look for consistency of biographical detail, profile photos, and posting history across platforms. A genuine long-standing identity tends to have presence on multiple platforms with consistent biographical detail. A purpose-built persona tends to be concentrated on one or two platforms with thin or inconsistent cross-platform representation. For the email address component of this check, see the email OSINT guide for the full enumeration and infrastructure workflow.

04
Analyse the profile photo
Goal · Determine whether the profile photo depicts a real person or is AI-generated or borrowed from another source

Run the profile photo through Google Reverse Image Search. A photo that returns matches on stock image sites or under a different name is a strong fabrication indicator. Note that AI-generated profile photos are unique images and will return no reverse image search hits; a clean result does not confirm authenticity. FotoForensics and its error level analysis method are built to catch recompression artefacts from splicing and editing on a genuine photo, not to detect AI generation, so an ELA scan is a manipulation check, not an AI-generation test. There is no reliable free consumer tool for detecting AI-generated images; treat a clean scan of any kind as inconclusive rather than as confirmation. Examine the photo directly for common AI artefacts instead: background inconsistencies, mismatched or distorted accessories, asymmetric facial features, and unnatural hair or skin texture at the edges of the frame. For deeper facial comparison methodology, see IDN-001.

05
Test the information independently
Goal · Determine whether the source's information holds up under independent corroboration before proceeding to publication

A source who passes all identity checks but provides information that cannot be independently corroborated is not a verified source in the publication sense. Seek at least one independent confirmation of the core claim from a source who is not connected to the first: a second source, a document, a public record, or a piece of observable evidence. If the information is internally consistent but fails to corroborate, document that explicitly in your verification record. Publication on the basis of a single unverifiable source should be a deliberate editorial decision with a named editor, not a default outcome.

03

What to watch for in source verification

Common false positives, evidentiary traps, and chain of custody requirements specific to source verification.

Confusing digital depth with identity confirmation: A source with a long-established LinkedIn profile, a consistent email history, and multiple platform accounts is not thereby confirmed as the person they claim to be. Digital depth confirms the identity exists and has been maintained over time; it does not confirm the person contacting you controls that identity. A sophisticated actor can build or acquire an aged, deep identity specifically for deception. Verifying check: Treat digital depth as a necessary but insufficient condition. Supplement with at least one independent off-platform confirmation: a phone call to the claimed employer's main switchboard asking to be connected to the source by name, or corroboration from a trusted colleague who knows the source directly.

Accepting LinkedIn self-description as verification: LinkedIn profiles are self-authored and unverified by the platform. An employer name on a LinkedIn profile confirms nothing about whether the source works there. Verifying check: Check the claimed employer's own website, any published staff directory, or regulatory register for the source's name independently of the LinkedIn entry.

Reverse image search false negatives for AI-generated photos: AI-generated profile photos are unique images and will not return reverse image search hits because they have never been published before. A clean reverse image search result does not confirm a photo depicts a real person. Verifying check: Examine the photo for AI generation artefacts: background inconsistencies, mismatched or distorted accessories, asymmetric facial features, and unnatural hair or skin texture at the edges of the frame. If in doubt, note the possibility in your verification record and seek an alternative corroboration method.

Treating absence of evidence as evidence of fabrication: Some genuine sources have minimal digital footprints. Older professionals, people from privacy-conscious backgrounds, or individuals in sensitive roles may have deliberately limited their online presence. A thin digital footprint is a flag warranting further investigation, not a conclusion. Verifying check: Assess the footprint relative to the claimed role. A claimed senior executive at a publicly listed company with no verifiable public presence is a stronger flag than a claimed mid-level civil servant with limited social media activity.

Verified identity does not mean verified information: This is the most common gap in source verification practice. A source who passes all identity checks can still provide false, misleading, or selectively accurate information. Verifying check: Run identity verification and information corroboration as separate workflows. Do not treat a completed identity check as grounds for reduced rigour on the information itself. If the information does not corroborate independently, document that explicitly and treat it as an editorial decision, not a verification status.

Chain of custody: Source verification records are themselves sensitive documents. Retain them carefully and limit access.

  1. Document every check run: the tool used, the query submitted, the result, and the timestamp.

  2. Screenshot every positive result from LinkedIn, HIBP, WhatsMyName, and reverse image searches with the URL and timestamp visible.

  3. Archive the claimed employer's staff page via the Wayback Machine at the time of verification and record the capture URL.

  4. Record the overall verification assessment in writing: confirmed, partially confirmed, unverified, or flagged, with the specific grounds for each.

  5. Store verification records separately from story files and restrict access to essential personnel only.

04

Go deeper

Each reference card used in this guide is available individually in the archive. Every card covers the full workflow, key queries, OPSEC controls, false positives, and chain of custody requirements for the technique.

HUM-001

HUM-001

Human intelligence sourcing to evidentiary standard.

LinkedIn, Hunter.io, and Maltego. Map proximity, verify identity, and make initial contact without compromising the source.

READ CARD →
IDN-001

IDN-001

Reverse image search and facial comparison.

Google Images, TinEye, and Yandex. Multi-engine reverse search, ExifTool metadata extraction, and corroborated identity chain.

READ CARD →
SOC-001

SOC-001

Social media account verification for investigators.

Botometer, Social Blade, and Wayback Machine. Grade account identity from claimed to corroborated with cross-platform archive checks.

READ CARD →
AIO-001

AIO-001

Cross-platform username attribution with AI.

AI-assisted matching across platforms to corroborate a claimed identity beyond a single username check.

READ CARD →

Related guides

GDE-002 Telegram OSINT: investigate channels, groups and users

GDE-005 Email OSINT: trace an address to accounts and infrastructure

Evidentiary standard

Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.

About Signal & Shadow

Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.