Supported document type
Detect tampered and deepfake Aadhaar Card
An Aadhaar card is the 12-digit identity credential UIDAI issues to residents of India, carrying the holder's photograph, demographic details, and a digitally signed QR code, with no expiry date to manage. It doubles as proof of identity and address for banking, telecom, and government services, which makes it one of the most frequently forged documents in Indian onboarding. The characteristic fraud edits the address block, or prints a number that fails the checksum the real card always passes.
API slug: aadhaar_card
What a genuine aadhaar card contains
The number runs twelve digits whose final digit follows the Verhoeff checksum over the first eleven, and every authentic card and e-Aadhaar PDF embeds a QR code holding the same demographic data under a UIDAI digital signature. Fields cover name, gender, a full date of birth or a year alone, and the registered address, and the letter, e-Aadhaar, and PVC card editions each look different while carrying the same payload.
Masking the first eight digits, or substituting a 16-digit virtual ID for the number, is a legitimate privacy practice rather than an anomaly, and a year-only birth date is normal where the holder never proved the full date. Aadhaar establishes residence and identity, not citizenship, and it works as a date-of-birth proof only where the full date is printed.
How aadhaar card forgeries are made
Verhoeff checksum
The twelfth digit is a Verhoeff check digit computed over the first eleven. A printed number that fails the check was never issued, which turns what looks like an OCR slip into a fabrication signal worth reporting.
Signed QR payload
Authentic editions embed a QR code signed by UIDAI carrying the demographic fields. Decoding it and comparing the signed name, gender, and birth date against the printed fields exposes a card where only the print was touched and the signature still tells the original story.
Address-block scrutiny
The registered address is the fraud magnet, because Aadhaar is India's default proof of address. Baseline realignment, a changed font pass, or ink density that departs from the rest of the card localises a substituted address.
Masking consistency
Where the number is masked or replaced by a virtual ID, the visible digits must still agree with the QR payload and any covering documents. Inconsistency across renderings suggests a composite assembled from two sources.
Edition conformance
Letter, e-Aadhaar, and PVC card layouts differ legitimately, so each edition is judged against its own typography and field placement rather than against another edition's design.
What TamperCheck checks on an aadhaar card
TamperCheck runs 200+ forensic checks across three layers and returns a risk score from 0 to 100 with plain-English findings tied to specific regions of the document. These three carry the most weight on this document class.
Portrait substitution and face-swap analysis
The document is isolated from whatever it was photographed on, then the portrait region is assessed against the card surface around it. A pasted or generated face rarely matches the substrate it was placed onto.
Security print, foil, and hologram analysis
A genuine security overlay or guilloche background behaves differently from a printed picture of one. A reproduction loses the structure that made the feature a security feature in the first place, and that loss is measurable even when the copy looks convincing on screen.
Barcode and QR payload comparison
Encoded payloads are decoded and compared against the human-readable values printed alongside them. Editing the visible text without re-encoding the barcode is a common and highly detectable mistake.
And many more checks
The three above are the layers that carry the most weight on an aadhaar card. Every upload runs the full suite of 200+ checks regardless of document class, spanning file structure and metadata, pixel-level forensics, font and text rendering, optical and print characteristics, provenance signals, AI-generation signatures, and many more checks.
Who verifies an aadhaar card, and why
Banks, lenders, telecom operators, and government subsidy portals. In each case the document is being used to unlock money, access, or a legal status, which is exactly what makes it worth forging.
How to verify an aadhaar card in 4 steps
Photograph both sides
Capture the card flat at full resolution under even light, keeping glare off the QR code, which carries the signed demographic payload the analysis compares against the print.
Check the number
Confirm twelve digits, apply the Verhoeff checksum, and compare any visible portion against a masked rendering or virtual ID shown elsewhere on the document.
Scan the QR code
Decode the QR where present. A code that will not parse, or one whose signed fields disagree with the printed name and birth date, is a strong fabrication signal.
Run a forensic check on the file
Checksums and QR payloads sit on top of print-level fraud a careful eye can miss. TamperCheck runs 200+ forensic checks across the print, the payload, and the address block, and returns a risk score from 0 to 100 with findings tied to specific regions of the image.
Frequently asked questions
Does a masked Aadhaar number mean the document is fake?
No. UIDAI encourages masking, and a card or e-Aadhaar showing only the last four digits is a legitimate privacy format. What matters is consistency: the visible digits must agree with the QR payload and the surrounding paperwork, so inconsistency, not masking itself, is the signal worth acting on.
Is an e-Aadhaar PDF as valid as the PVC card?
Yes. The e-Aadhaar PDF is generated by the UIDAI portal, carries the same signed QR payload, and is equally acceptable. Its layout differs from the PVC card, so it should be judged as its own edition rather than measured against the card design.
Can Aadhaar serve as proof of date of birth?
Only where the card prints a full date of birth. Many authentic cards show the year alone, which supports identity and address rather than age, so a year-only card offered as DOB proof deserves a closer look at how the requirement is otherwise met.
How does TamperCheck analyse an Aadhaar card?
TamperCheck validates the number's checksum, decodes the signed QR payload and compares it against the printed fields, and inspects the address block for localised edits. Everything runs through a single REST endpoint, the upload is processed ephemerally and not stored, and the verdict arrives within seconds.
TamperCheck analyses aadhaar card uploads with a hybrid forensic and AI pipeline tuned for this document class. Upload endpoints accept PDF and common image formats; class is inferred automatically. See the API documentation for authentication, async jobs, and webhooks.