Supported document type
Detect tampered and deepfake PhilSys National ID (PhilID)
The PhilSys ID, issued by the Philippine Statistics Authority, is the Philippine national identity document, available as a plastic PhilID card, a printed paper ePhilID, and a digital ePhilID, all treated as equally valid. Because a printed or digital version is legitimate, verification has to separate an issued ePhilID from an edited copy, using the QR region, the card number length, and field consistency.
API slug: philsys_id
Last updated:
What a genuine PhilSys ID contains
The face prints a sixteen-character PhilSys Card Number, encoded in the QR code, along with surname, given name, middle name, suffix, sex, date of birth, place of birth, address, and a front-facing photograph. Blood type and marital status may be absent. The twelve-digit permanent number is microprinted on the back of the card and is not for general use.
Card numbers here are random or tokenised, so nothing in them reveals a birth date. Printed ePhilIDs sit on ordinary paper and digital ones are PDFs, which is normal. Handwritten additions are not expected on these IDs, so the analysis weighs QR presence and layout, number length, and edits to the printed fields.
How PhilSys ID forgeries are made
Card number length
The PhilSys Card Number runs sixteen characters. A shorter or longer string points to a mistyped or invented number.
QR region integrity
Printed and digital ePhilIDs carry a QR code. A missing QR, or one sitting on a different background or resolution than the page around it, signals a patched region.
Handwriting and annotation
The ID is meant to carry no handwritten information. Pen additions or corrections contradict the issuing design and warrant escalation.
Photo compression signature
On a PDF ePhilID the portrait should share the page's compression history. A photo with its own compression signature suggests substitution.
Field and font patching
Edited name, sex, date, or address lines leave font weight shifts, baseline breaks, and spacing changes that localise the edit within the structured layout.
What TamperCheck checks on a PhilSys ID
TamperCheck runs 200+ forensic checks across three layers and returns a risk score from 0 to 100 with plain-English findings tied to specific regions of the document. These three carry the most weight on this document class.
Portrait substitution and face-swap analysis
The document is isolated from whatever it was photographed on, then the portrait region is assessed against the card surface around it. A pasted or generated face rarely matches the substrate it was placed onto.
Barcode and QR payload comparison
Encoded payloads are decoded and compared against the human-readable values printed alongside them. Editing the visible text without re-encoding the barcode is a common and highly detectable mistake.
Reference and document number checks
Document, account, and reference numbers are checked for issuer format conformance and against every other place the same value appears on the page.
And many more checks
The three above are the layers that carry the most weight on a PhilSys ID. Every upload runs the full suite of 200+ checks regardless of document class, spanning file structure and metadata, pixel-level forensics, font and text rendering, optical and print characteristics, provenance signals, AI-generation signatures, and many more checks.
Who verifies a PhilSys ID, and why
Philippine banks, e-wallets, and eKYC platforms. In each case the document is being used to unlock money, access, or a legal status, which is exactly what makes it worth forging.
How to verify a PhilSys ID in 4 steps
Photograph the document
Capture the card flat, or export the ePhilID at full resolution, so the number, QR code, and fields survive close analysis.
Check the number and QR
Count the sixteen characters of the card number and confirm a QR region is present with a quality and background that match the rest of the page.
Review the fields
Confirm the printed fields carry no handwritten changes and that the photo shares the page's image characteristics.
Run a forensic check on the file
TamperCheck runs 200+ forensic checks including QR region and number length checks and patch detection, returning a risk score from 0 to 100 with findings tied to specific regions of the image.
Frequently asked questions
What is the difference between PhilID and ePhilID?
The PhilID is the plastic card, while the ePhilID is a printed paper or digital PDF version. All are treated as equally valid, so a paper printout is not a forgery by itself.
Does the card number encode a birth date?
No. The card number is a sixteen-character derivative of the permanent number, which is random, so nothing in it can be cross-checked against the date of birth.
Why might blood type or marital status be missing?
Those fields appear only when declared, so their absence is normal. Handwritten additions are the unusual feature, since the ID is designed to carry none.
How does TamperCheck verify a PhilSys ID?
TamperCheck tests the card number length, reviews the QR region for presence and consistency, and inspects the portrait and text for patching. It does not authenticate the QR contents. Uploads run through a single REST endpoint, are processed ephemerally and not stored, and findings tie to specific regions.
TamperCheck analyses philsys national id (philid) uploads with a hybrid forensic and AI pipeline tuned for this document class. Upload endpoints accept PDF and common image formats; class is inferred automatically. See the API documentation for authentication, async jobs, and webhooks.