Supported document type
Detect tampered and deepfake Emirates ID
The Emirates ID is the United Arab Emirates' national identity card, issued by the ICP to citizens and residents alike, and it is the country's primary KYC document for banking, telecom, SIM registration, and government services. The card carries a 15-digit identity number beginning with 784, the holder's photograph and nationality, and a validity window tied to the holder's visa. Fraud reuses expired cards and swaps photographs on legitimately issued ones.
API slug: emirates_id
What a genuine Emirates ID contains
The identity number runs fifteen digits beginning with 784, the ISO country code for the UAE, grouped for readability but strictly numeric after the prefix. The front carries name, date of birth, nationality, and photograph; the reverse adds a three-line MRZ and sponsor or occupation fields depending on edition, plus the card access number used at e-gates.
Card validity tracks the holder's residence visa, so a resident's card expires with the visa behind it while citizens' cards run longer, and renewals produce fresh cards rather than extensions. Employers, banks, and free zones accept the card as the definitive identity document, and a photo-swap on a genuinely issued card is the fraud that survives casual inspection.
How Emirates ID forgeries are made
Number structure
The fifteen-digit number starts with the 784 country prefix and continues in strictly numeric groups. Numbers that break the pattern, or start with any other prefix, were invented rather than issued.
MRZ validation
The reverse carries a three-line MRZ whose check digits bind the card number and dates. A validator failure means the zone was retyped, the standard route for reprinting an edited card.
Validity versus visa
A resident's card expires with the residence visa behind it, so a card valid far beyond the visa dates in the file contradicts the issuing model rather than extending it.
Photograph patching
Swapping the portrait redirects a legitimately issued card to a new holder. Cut-line edges, resolution steps, or sharpening halos around the portrait localise the patch.
Edition conformance
ICP card generations differ in layout and security features, so the analysis scores each edition against its own known design rather than against a single template.
What TamperCheck checks on an Emirates ID
TamperCheck runs 200+ forensic checks across three layers and returns a risk score from 0 to 100 with plain-English findings tied to specific regions of the document. These three carry the most weight on this document class.
Portrait substitution and face-swap analysis
The document is isolated from whatever it was photographed on, then the portrait region is assessed against the card surface around it. A pasted or generated face rarely matches the substrate it was placed onto.
Security print, foil, and hologram analysis
A genuine security overlay or guilloche background behaves differently from a printed picture of one. A reproduction loses the structure that made the feature a security feature in the first place, and that loss is measurable even when the copy looks convincing on screen.
Barcode and QR payload comparison
Encoded payloads are decoded and compared against the human-readable values printed alongside them. Editing the visible text without re-encoding the barcode is a common and highly detectable mistake.
And many more checks
The three above are the layers that carry the most weight on an Emirates ID. Every upload runs the full suite of 200+ checks regardless of document class, spanning file structure and metadata, pixel-level forensics, font and text rendering, optical and print characteristics, provenance signals, AI-generation signatures, and many more checks.
Who verifies an Emirates ID, and why
UAE banks, tenancy desks, HR onboarding, and government portals. In each case the document is being used to unlock money, access, or a legal status, which is exactly what makes it worth forging.
How to verify an Emirates ID in 4 steps
Photograph both sides
Capture the card flat at full resolution with glare kept off the MRZ and portrait, since both regions drive the analysis.
Check the number
Confirm the fifteen-digit structure with the 784 prefix, and compare the printed card number against its MRZ encoding on the reverse.
Weigh validity against the visa
Compare the card's expiry with the residence visa dates in the file. A resident's card does not outlive its visa by design.
Run a forensic check on the file
Photo swaps and MRZ retypes both survive a glance at a wallet card. TamperCheck runs 200+ forensic checks including MRZ validation and portrait-patch analysis, and returns a risk score from 0 to 100 with findings tied to specific regions of the image.
Frequently asked questions
What does the 784 at the start of an Emirates ID mean?
It is the ISO 3166 country code for the United Arab Emirates, and every Emirates ID number begins with it. Fifteen digits with that prefix is the issued pattern, so any other opening digits mark a fabricated number.
Why does an Emirates ID expire when a passport does not?
For residents the card's validity tracks the residence visa, which itself has a term, so the card renews as the visa renews. Citizens' cards run longer, and an expiry far beyond the visa dates in a resident's file contradicts the issuing model.
Is a photocopy of an Emirates ID acceptable for onboarding?
Most UAE institutions accept clear scans of the card, though banks may require the physical card or a validated digital copy for final KYC. A scan is exactly where photo-swap fraud lives, so forensic analysis of the portrait region is the check that matters before acceptance.
Does TamperCheck read the Emirates ID MRZ?
Yes. TamperCheck validates the three-line MRZ check digits against the printed card number and dates, then scores the portrait region and edition conformance, returning a risk score from 0 to 100 with findings tied to specific regions.
TamperCheck analyses emirates id uploads with a hybrid forensic and AI pipeline tuned for this document class. Upload endpoints accept PDF and common image formats; class is inferred automatically. See the API documentation for authentication, async jobs, and webhooks.