Synthetic media

Is That Profile Photo AI-Generated?

Almost every answer online hands you the same list — count the fingers, check the teeth, look at the earrings — and that list was written against a generation of image tools that has already been replaced. Repeating it does something worse than nothing: it teaches you to read a clean image as a real one. This page sets out the checks that have actually held up, what a Content Credential can and cannot settle, what independent testing found when it ran real photographs through the leading detectors, and why the question you can genuinely answer is not “was this picture made by a machine” but “should I trust this account”.

Not a licensed private investigation agency We do not publish verdicts about strangers Purpose recorded before anything is searched
6 of 20Award-winning real photographs one detector called AI-generated
40%Authentic news photos another detector flagged as synthetic in a 2026 audit
35 of 45Images where at least one of five detectors disagreed with the rest
ZeroDetector verdicts we will treat as proof a person is not real

The short version

Inspecting the picture is the weakest test available to you, and it is the only one most guides teach. A visual artifact is worth something when you find one and worth nothing when you do not — which is precisely backwards from how people use it, because the reassuring case is the clean image. Two checks outrank every pixel-level tell. The first is provenance: where this image has appeared before, and whether it carries signed Content Credentials describing how it was made. The second is context: whether the account holding the photo has a history, a name that resolves anywhere, and any connection to a real person you could reach through a channel you chose. Detectors are a fourth-place input at best. Independent testing has repeatedly caught them calling genuine photographs fake, including award-winning press photography, and five leading tools disagreed with each other on most of the images in a 2026 audit. And you almost never need to win the argument you think you are having. You are not required to prove an image is synthetic. You are deciding whether to trust an account, send money, or let someone into your life — and that decision can be made confidently without ever settling the question about the picture.

The checks that survived, in about a minute

A short walk through the same order the page below argues for: provenance, then context, then artifacts, then — a long way behind — whatever a detector says.

Before you accuse anyone

The tells you were taught are the wrong half of the test

Not because they never worked. Because of what people do with them when they find nothing.

The canon is familiar enough to recite: hands with the wrong number of fingers, teeth that merge into a single ridge, an earring on one side and something else on the other, a face too symmetrical to be a face. That list is not fiction, and it is not even especially old. The FBI’s own public advisory on generative AI and financial fraud, Alert Number I-120324-PSA of December 3, 2024, tells the public to look for distorted hands or feet, unrealistic teeth or eyes, indistinct or irregular faces, unrealistic accessories such as glasses or jewelry, and inaccurate shadows. That advisory is a genuine federal warning and it says what it says.

The problem is not that the list is wrong. It is that the list is asymmetric, and nobody tells you which direction it runs. Finding one of those artifacts is real information: an image with a six-fingered hand was almost certainly generated, and no honest reading gets you around that. Finding none of them is not information at all. It tells you the image was made by a tool good enough to avoid the failure modes you happen to know about, or that it was cropped tightly enough to hide them, or that the person who chose the photo discarded four earlier attempts with mangled hands. A clean result is compatible with a real photograph and equally compatible with a competent fake, and the whole reason people run these checks is to feel better about the clean result.

The second problem is that “AI” is not one thing whose weaknesses you can memorize. Which artifacts a picture carries is a property of the specific model that made it, and models are replaced constantly by ones trained partly to fix whatever the last one got caught on. Any fixed checklist is therefore dated from the moment it is published, and the ones circulating now were written against tools that were current when they were written. That is why this page does not give you a numbered list of tells: a list is exactly the wrong shape for a target that moves.

What has held up longest is not a list of body parts but a single principle about where generation is hard. A model rendering one object in isolation has an easy job; a model keeping a whole scene consistent with itself has a hard one. So the details that tend to survive longest are the ones that have to agree with something else in the frame: lettering on a sign or a shirt that has to spell an actual word, a reflection in a window or a pair of glasses that has to correspond to what is in front of it, a piece of jewelry or a strap that has to be the same object where it disappears behind a shoulder and where it comes back out, the boundary where fine hair meets a background that has to be resolved consistently at every strand. Treat those as slightly better places to look than fingers, treat them as improving away too, and never treat their absence as a finding. That single paragraph is the entire honest yield of visual inspection. Everything else on this page outranks it.

Where the picture came from beats what it looks like

Two provenance checks, one very old and one very new. Both answer better questions than your eyes do.

Start with the oldest check there is, because it is still the most decisive one available to a member of the public. Run the image backwards and see where else it lives. The Federal Trade Commission puts this in its standing consumer advice on romance scams, telling readers to do a reverse image search of the person’s profile picture and check whether it is associated with another name or with details that do not match up. When that search returns the same face attached to a different name, or to eleven different names, you are finished. You have not proved anything about how the image was made and you do not need to: you have proved the account is not who it says it is, which is the only thing you were actually trying to establish. The mechanics of running that search well — which engines see what, how to crop, why the first page is often the wrong page — are set out in our guide to reverse image search as an identification tool.

Now the hard part, and the reason so much published advice on this topic quietly fails: an empty result means almost nothing. The reasoning people apply is that a real person’s photo would turn up somewhere, so silence implies synthesis. It does not. A synthetic face is unique by construction and will return nothing, but so will a real photograph taken last month on a private phone by someone who has never posted it anywhere, which describes an enormous number of perfectly genuine profile pictures. It will also return nothing if the image was cropped, recompressed, mirrored or passed through a filter on the way to the profile, all of which routinely defeat matching. An empty reverse search is weak evidence pointing in both directions at once, and reading it as a verdict is how a real person gets called a bot.

Content Credentials: what they actually are

The newer answer is provenance metadata carried inside the file itself. The Coalition for Content Provenance and Authenticity publishes an open specification, and Content Credentials is the user-facing name for what it produces: a cryptographically signed record bound to the image, listing assertions about how it was made — what tool created it, what edits were applied, and whether generative AI was involved. A growing number of cameras, editing tools and generation services write one, and viewer tools exist that will read it back out.

Read the specification’s own limitations before you lean on it, because they are unusually candid and they change how you should use it. The C2PA explainer states that Content Credentials do not make value judgments about whether the provenance data is true, only whether it is well-formed, untampered, and signed by someone on a known trust list. It says in terms that provenance information alone cannot tell you whether content is true, accurate or factual, and that the standard is not a cure-all. Its FAQ answers “can the provenance metadata be removed?” with a flat yes — which is why the specification adds what it calls durable Content Credentials, pairing the cryptographic binding with watermarking and fingerprinting so a credential can still be found after the metadata is stripped. And the core specification, by design, does not address the identity of the humans behind a piece of content at all.

Three practical consequences follow, and they are the ones no ranking page on this query states. The absence of a Content Credential proves nothing whatsoever — most images ever taken have none, platforms have historically stripped metadata on upload, and it is removable on purpose. The presence of one proves narrower things than it looks like it proves: that a signer on a trust list attested to a history, not that the photograph depicts a real human being, and not who that human being is. But a credential that says “generated with AI” is close to conclusive in the one direction that matters here, and it costs you thirty seconds to check. Look for it. Never conclude from its absence.

That split is not an implementation detail; it is how the field is organized. The National Institute of Standards and Technology’s overview of this problem, Reducing Risks Posed by Synthetic Content, published November 20, 2024, catalogs authenticating content and tracking its provenance, labeling synthetic content through techniques such as watermarking, and detecting synthetic content as three separate families of technical approach. They are separate because they answer different questions and fail in different ways. A page that blends them into one instruction to “check if it’s AI” is describing a capability that does not exist as a single thing.

The detector question, answered with numbers

Every tool in this category publishes an accuracy figure. Every one of those figures was produced by the company selling the tool.

We are not going to name or link a detector, and the reason is not squeamishness. Sending a reader to a tool implies the tool answers the question, and the independent testing says it frequently does not — in the direction that hurts an innocent person.

Take the most recent published audit. In a report titled Leading AI Image Detection Tools Mislead Online Users, Often Declaring Authentic Content Fake, published on May 8, 2026 by Isis Blachez, Sofia Rubinson and Ines Chomnalez, NewsGuard ran forty-five images — fifteen authentic news photographs, fifteen lightly edited versions and fifteen heavily manipulated ones — through five leading detection models in late April and early May of 2026. Across the five tools, authentic images were declared AI-generated 13.33 percent of the time. The worst performer, a tool that advertises “industry-leading accuracy” on its own website and claims 95.3 percent detection accuracy, called 6 of the 15 genuine photographs synthetic: a 40% false-positive rate on real press photography. A second tool got 3 of 15 wrong, a third got 1 wrong.

The two tools that produced no false positives were the worst at the opposite job. One correctly caught only 5 of the 15 heavily manipulated images, a 33 percent detection rate; the other caught 9. That is the shape of the whole category: a detector has a threshold, and moving it to stop misjudging real photographs necessarily makes it miss fakes. There is no setting at which it does both, which is why “which detector is best” is not a well-formed question. And the tools do not even agree on what they are looking at — in 35 of 45 images tested, at least one tool reached a different verdict from the rest. A reader who runs an image through several tools hoping for a consensus is more likely to end up with a split decision than a confirmation.

Nor is this new, or specific to one audit. In September 2023, the open-source research outlet Bellingcat published a test of a widely used detector and found that when it was given 20 photographs entered in a photography competition, it wrongly identified 6 of 20 as AI-generated and could not reach a determination on a seventh. Those were winners and honorable mentions from the 2022 and 2021 Canadian Photos of the Year contest run by Canadian Geographic magazine — in other words, exactly the sort of unusually sharp, high-resolution, striking image a detector is most likely to misread, and exactly the sort of photograph a real person might use as a profile picture. The same test found the reverse failure too: when ten AI-generated images were compressed before being submitted, seven came back labeled as human work, including every one of the seven photorealistic images in that set.

That last finding is the one to carry away, because it explains the mechanism. Detectors read faint statistical fingerprints left by the production process, and ordinary handling destroys or forges those fingerprints. A crop, a screenshot, a re-save, a platform’s automatic recompression, a light touch-up filter — each of these can strip the signature of a synthetic image or stamp noise onto a real one that the model reads as synthetic. A profile photograph has almost always been through several of those steps before you ever see it. You are handing the detector the worst possible input and then treating its answer as a result.

None of which makes the tools useless. A detector output is a weak signal that belongs in the same tier as a visual artifact: interesting when it fires, meaningless when it does not, and never sufficient on its own. Weigh it accordingly, and never repeat it to anyone as a finding about a person. The number of detector verdicts we will put our name to as proof that a person is not real is zero, and that is not caution for its own sake — it is what the numbers above require of anyone who has read them.

What each test actually settles and what it does not

Six checks, ranked by how much weight the result can carry. The third column is the one people skip.

The checkWhat a positive result establishesWhat a negative result establishes
Reverse image search finds the face elsewhereThe account is not who it claims to be, whoever made the imageStrongestAlmost nothing. Private photos, crops and recompression all return empty
Account history and contextA years-long trail of unremarkable ordinary activity is very hard to fake cheaplyA thin account is common among new, private and cautious users too
Content Credential says “AI-generated”Close to conclusive about the image, if the signature validatesNothing at all. The metadata is removable and most images never carried it
Live verification through a channel you choseStrong, and it tests the person rather than the pictureRefusal is a red flag but has innocent explanations
Structural artifact in the frameReal evidence of generation when you genuinely find oneNothing. Silence means the tool was good, or the crop was tight
Commercial AI detector scoreA weak input in both directions. Independent audits have measured false-positive rates on genuine photographs as high as 40%, and compression alone flipped 7 of 10 synthetic images to “human”. Treat it as one opinion among several, never as a verdict.

Read the table downward and a pattern shows up that is worth more than any individual row. Every check on it is strong in one direction and near-worthless in the other, and the direction that is worthless is the reassuring one. That asymmetry is the actual structure of this problem, and it is why a stack of clean results never adds up to confidence. It is also why our own records research work is organized around establishing who exists rather than around adjudicating images.

The picture is the wrong question and the account is the right one

You are not obliged to win the argument about the image. You get to change which argument you are having.

Notice what you are actually deciding. Nobody arrives at this question out of curiosity about image synthesis. They arrive because someone has been messaging them for three weeks, or a job offer came through a profile with two connections, or a seller wants a deposit, or a relative has met somebody they will not stop talking about. The real question is whether to trust an account. Proving the photograph is synthetic is one route to answering that, and it happens to be the hardest, slowest and least reliable route available. There are easier ones, and they do not require you to be right about pixels.

An account is a much bigger surface than a picture, and it is far more expensive to fake convincingly. A generated face costs nothing and takes seconds. Six years of dull, low-engagement, inconsistent, real activity — a tagged photo from someone else’s wedding, a complaint about a local road closure, a review of a hardware store, an argument in a hobby group in 2021 — costs an operator far more than the account is worth. So the strongest tell available to you usually is not on the face at all. It is that the photograph is the single most polished thing about the profile, and that everything behind it is thin, recent, or absent.

The specific things worth checking, in the order they take least effort: whether the name resolves to anything outside the platform; whether the account has any history that predates its contact with you; whether the connections are mutual and plausible rather than a wall of accounts with the same shape; whether the stated employer, unit, school or license is one you can confirm from a source the person did not give you; and whether the account will do anything at all in real time that it did not schedule. Our page on confirming that someone you met online is a real person works through that sequence in practice, and the account-level version of the synthetic-profile problem is covered separately in our guide to detecting an AI-generated fake profile.

Where the answer is “this is a scam”, stop investigating and start reporting

For a large share of the people reading this, the image question is a detour from a fraud that is already in progress. The FBI’s advisory on generative AI in financial fraud describes exactly this pattern: criminals create realistic images for fictitious social media profiles used in romance schemes, confidence fraud and investment fraud, and produce photographs to share in private messages specifically to convince a victim they are speaking to a real person. The advisory also notes, correctly, that making or distributing synthetic content is not itself illegal — which is a useful reminder that the offense you care about is the fraud, not the picture.

If money has been requested or sent, the picture has stopped mattering. The FTC’s bottom line on romance scams is unambiguous: never send money or gifts to a sweetheart you have not met in person. Report the fraud to the Federal Trade Commission at ReportFraud.ftc.gov and to the FBI’s Internet Crime Complaint Center at IC3.gov, and do it even if the amount feels too small to bother with and even if you are embarrassed, because these complaints are how patterns across many victims get linked. If you paid by gift card, wire transfer, card or cryptocurrency, contact that company or your bank first and tell them you paid a scammer. Where the photographs turn out to belong to a real person whose pictures were taken and reused — a different and very common case — our page on tracing a scammer who is using somebody else’s photographs covers what can and cannot be established from there.

Six ways a photo check reaches the wrong answer

Three of these clear a fraudster. Three of them convict somebody real. The second three are the ones nobody writes about.

The clean checklist that proved nothing

Hands correct, teeth correct, earrings matched, no warping anywhere. Every item on the list came back clean, so the account was trusted — when all the list established was that the image came from a tool that no longer makes those mistakes.

The compressed fake that read as human

The image was screenshotted and reposted before it reached the detector. Bellingcat’s test found seven of ten compressed synthetic images came back labeled as human work — every photorealistic one in the set. Ordinary handling erased the fingerprint the tool was looking for.

The missing credential read as a confession

No Content Credential was found, so the image was treated as suspect. Provenance metadata is removable by design, platforms have long stripped it on upload, and the overwhelming majority of photographs ever taken never carried one. Absence is the default state, not a signal.

The good photographer flagged as a machine

A sharp, well-lit, high-resolution portrait is precisely the kind of image detectors misread. In one published test, 6 of 20 award-winning contest photographs were called AI-generated. The person in that photograph is real and has no way to appeal the verdict.

The empty search that condemned a private person

Nothing came back from the reverse search, and silence was read as synthesis. The photo was taken last spring on a phone and posted nowhere else. Being absent from the indexed internet is a choice millions of people make deliberately, and several of them have good reasons.

The avatar that was protection, not deception

An account using an illustration, a stylized portrait or a generated face instead of a real photograph was assumed to be hiding something. Sometimes it is hiding from someone. A person who cannot safely publish their face is not the same as a person impersonating one.

How we handle a suspect image

The order matters more than any single step, because the cheap checks answer the real question and the expensive ones usually do not.

1

Write down what a “yes” would change

Before anything is examined, we record what decision is waiting on the answer and what you would do differently either way. A surprising share of these requests turn out not to need the image resolved at all, and saying so on day one is cheaper than being thorough about the wrong question.

2

Chase provenance, not appearance

Where the image has appeared before, under what names, in what order, and whether the file carries signed provenance metadata. A hit here ends the matter without anyone having to characterize the picture. A miss is logged as a miss, never as a result.

3

Test the account against records, not against instinct

Does the claimed name, employer, license, business or address correspond to anything in the public record? This is ordinary records research, it is what we are actually good at, and it answers the trust question whether or not the photograph is ever explained.

4

Report the uncertainty at full strength

Where the evidence does not reach a conclusion, the finding says so and names what would settle it. We do not round an inability to verify up to a determination that a person is fabricated, because somebody real is on the other end of that sentence often enough to matter.

The refusals this page is built on

A method that teaches strangers to declare each other fake will produce false accusations against real people. That is a property of the method, not a misuse of it, and it has to be designed for.

We research public records for a living. We are not a licensed private investigation agency, nobody here holds an investigator’s license, and everything on this page is general information about how these checks behave rather than advice on your situation. It is certainly not legal advice: whether a suspicion about an account is a basis for reporting it, terminating a relationship, refusing a transaction or contacting anyone is a question for a lawyer, not for a research page. Every engagement begins with a stated lawful purpose recorded before any work starts: confirming a counterparty before a payment, verifying a person named in a document you already hold, identifying who is behind a fraud you have already suffered. We work from public records and lawfully licensed data. We do not obtain the contents of anyone’s bank, card or brokerage accounts, live device location, call detail records, or the contents of anyone’s communications, and no purpose converts any of that into something we can lawfully reach.

We do not pretext, and on this subject the temptation is specific and strong. The fastest way to test whether an account belongs to a real person is to become a plausible stranger it would want to talk to: a matching profile, a fake recruiter, a mutual acquaintance, a returning caller. We will not do that, we will not build an account to bait a video call, and we will not ask you to do either on our behalf. Beyond the ethics of it, a confirmation obtained by deceiving somebody is worthless the moment anyone asks how it was obtained — and if the account turned out to be a real person, you have deceived a real person in order to accuse them.

We will not hand you an accusation

This is the boundary that most matters on this page, and it is a limit on the method rather than a caveat about it. The measured false-positive rates set out above are not a rounding error: a 40% false-positive rate on genuine press photography, and 6 of 20 award-winning contest photographs called synthetic, are what the honest state of the art looks like. Applied at the scale of the internet, a public that has been taught to run these tests and announce the results will accuse an enormous number of real people of being fake — disproportionately those who are photogenic, well-photographed, new to a platform, or simply private. So we will tell you what we found, what it supports and what it does not, and where the evidence stops we will say it stopped. What we will not do is put our name to “this person does not exist” on the strength of an image, and we would ask you not to publish that sentence about a stranger either. An accusation of being fake is close to impossible to disprove and it does not come with a correction notice. If you are on the receiving end of one, our page on finding out who is impersonating you online covers the adjacent problem of your own photographs being used by somebody else.

The safety decline, written for this specific fact pattern

An account using a synthetic or non-photographic face is very often somebody protecting themselves, and this page could be read as a tool for finding them. People who have left an abusive partner, who are enrolled in a state address confidentiality program, who have a protective order, who are transitioning, who have a stalker, who work in a job that attracts harassment, or who simply have decided their face is not the internet’s business, frequently choose an avatar precisely so they can stay reachable to the people who matter without being findable by the person who does not. “That photo is AI-generated” is not evidence of fraud in that situation. It is evidence of somebody doing exactly what they were advised to do. So we decline work whose object is to strip an account back to a person who has taken steps not to be reached, and a request whose background includes a protective order, a domestic violence or stalking history, or a contested custody matter gets more scrutiny at intake, not less — it goes to the court that issued the order, to law enforcement, or to a victim services advocate, all of whom can act without handing a private party an address. Never frame the person on the other end as evasive. People choose their own visibility, and most of the reasons are none of your business.

One last boundary, because this question sits one step away from a regulated one. People Locator Skip Tracing is not a consumer reporting agency, and what we return is a research finding rather than a consumer report. It may not be used to decide whether to hire, promote, retain or terminate an employee, whether to rent to an applicant, whether to extend or review credit, whether to underwrite insurance, or for any other eligibility purpose listed at 15 U.S.C. § 1681b. That matters more than usual here, because “is this remote applicant’s photo real” is a question hiring teams ask in good faith and it is an employment screening question wearing a technical costume. Those decisions require an FCRA-regulated screening product, with the adverse action notice and dispute rights attached — which exist so that a person wrongly flagged can find out and get it fixed. A detector score carries no such rights, and a candidate rejected on one will never learn why.

Who asks us to check a face

Different situations, one shared requirement: a conclusion that can be defended if the person on the other end turns out to be real.

Anyone being courted from a distance

Weeks of messages, no meeting, and a photograph that is the only unambiguous thing about the account. Usually answerable without ever resolving the image.

Community and forum moderators

A wave of new accounts with immaculate portraits and no history. The account pattern is the case; the faces are a side effect.

Fraud and disputes desks

A counterparty that exists only as a profile. What we can document is whether the name, business or address behind it exists in the record.

Newsroom and research desks

A source, a subject or a viral account that has to be characterized carefully, where the cost of overstating a conclusion lands on a named person.

Recruiters screening remote applicants

We will confirm whether a claimed identity, license or work history exists in the record. Anything that decides the hire has to run through a regulated screening product, not through us.

People accused of being fake

Someone ran a detector on your photograph and told a group chat you do not exist. This is a real and growing category, and it is why we write findings the way we do.

What connects these is that the interesting question is never really about the picture. It is whether a specific human being exists, holds the position claimed, and can be reached — and that is a records question, answerable from documents, with an answer that survives somebody asking how it was reached.

We would rather be unsure in writing

You get back what we checked, what each check supports, and precisely where the evidence ran out — including the checks that produced nothing, which are the ones most likely to be quietly dropped elsewhere. If the honest answer is that the account cannot be tied to a real person and cannot be shown to be fabricated either, that is what the finding says, along with the one record that would break the tie. Most requests come back within 24 hours. An unresolved answer delivered plainly is worth more than a confident one that turns out to have been about somebody’s actual face.

People Locator Skip Tracing Investigation Team — public-records research, in practice since 2004. Sources on this page re-verified for 2026.

Questions about a face you cannot place

Can an AI-generated image be detected with complete accuracy?

No, and the published testing is not close. A NewsGuard audit released on May 8, 2026 ran forty-five images through five leading detection models; across the five, genuine photographs were declared AI-generated 13.33 percent of the time, and the worst tool got 40% of real news photographs wrong. The two tools with no false positives were the weakest at catching heavily manipulated images, one of them identifying only 5 of 15. That trade-off is structural rather than a bug anyone is about to fix.

Are AI image detectors reliable enough to act on?

Treat one as a weak opinion, not a verdict. Detectors read faint statistical traces left by the production process, and ordinary handling wrecks those traces — a crop, a screenshot, a re-save or a platform’s automatic recompression can erase the signature of a synthetic image or add noise a model misreads as one. Bellingcat’s 2023 test found that compressing 10 AI images caused 7 of 10 to be labeled human work. Profile photographs have almost always been through several of those steps before you see them.

Why does a reverse image search find nothing on an AI-generated face?

Because a generated face has never existed anywhere else, so there is nothing for the index to match. The trap is what people conclude from that. A photograph taken privately last month and posted nowhere returns exactly the same empty result, as does a real image that was cropped, mirrored, filtered or recompressed on the way to the profile. Empty means the search failed, not that the person is fabricated.

So is an empty reverse image search a good sign or a bad one?

Neither, which is the honest and unsatisfying answer. It is weak evidence pointing in two directions at once and it cannot carry a decision on its own. The result that does carry a decision is the opposite one: if the same face comes back attached to a different name, or to several, you are finished. You have not established how the image was made and you no longer need to, because you have established the account is not who it claims to be.

What are Content Credentials, and can I rely on them?

They are provenance metadata built on the C2PA open standard: a cryptographically signed record bound to an image, describing what created it, what edited it, and whether generative AI was involved. Rely on them in one direction only. The specification states plainly that Content Credentials do not judge whether the provenance data is true, only that it is well-formed, untampered and signed by someone on a known trust list, and its own FAQ confirms the metadata can be removed. A credential saying “generated with AI” is close to conclusive. No credential at all is the normal state of almost every image on the internet and proves nothing.

Do the old visual tells still work — fingers, teeth, jewelry?

They still work when they fire and they were never useful when they do not, which is the half people skip. Finding a hand with six fingers is real evidence; finding a clean image tells you only that the tool avoided the failures you happen to know about, or that the crop was tight. Which artifacts persist depends on the specific model, and models are replaced constantly, so no fixed checklist stays correct. The details that survive longest are the ones that must agree with something else in the frame — readable lettering, reflections, an object that has to match itself where it passes behind a shoulder.

Can a live video call prove the person is real?

It is a stronger test than any image check because it tests the person rather than the picture, and it is not proof. Live video manipulation exists, and the FBI’s December 2024 advisory describes criminals generating video for real-time chats to convince targets they are speaking to a real person. What raises the cost for an operator is an unscheduled call on a channel you chose, with an unrehearsed request in it. The same advisory recommends verifying identity by hanging up and calling back on a number you looked up yourself, which is the same principle applied to the phone.

I think this is a romance or investment scam. What should I do first?

Stop trying to settle the photograph — it has stopped mattering. The FTC’s standing advice is never to send money or gifts to a sweetheart you have not met in person. If you have already paid, contact the gift card company, wire service, card issuer, bank or crypto platform immediately and tell them you paid a scammer. Then report it to the Federal Trade Commission at ReportFraud.ftc.gov and to the FBI’s Internet Crime Complaint Center at IC3.gov. Report it even if the amount was small and even if you feel foolish; linking complaints across victims is how these operations get traced at all.

Bring us the account, not just the photograph

Send the profile, the name and any claim it has made about itself — an employer, a license, a business, a city — and we will tell you what exists in the public record behind it and what does not. That answers the question you actually have, whoever or whatever made the picture. Talk to a researcher first if you are unsure whether your purpose is one we can take on.

Start an account verification request