Through provenance first and pixels second. File metadata, source-device records, and distribution history establish where a recording actually came from; content analysis — lighting, compression, biometric consistency — supports or undermines it. No single detector settles the question alone.
Provenance beats pixel-gazing
The strongest deepfake analysis usually never reaches the pixels. A genuine recording has a history: the device that captured it, the file's native container and encoding, metadata consistent with that device, and a traceable path from capture to courtroom. A fabricated one has to counterfeit all of that, and the counterfeits are typically incomplete.
- Original files, not re-shares. A video that exists only as a re-compressed social-media download has lost most of its forensic signal. The original file from the original device is the first demand.
- Container and encoding analysis. Cameras and phones produce files with characteristic structures — stream layouts, encoder signatures, metadata atoms. A file claiming to come from a particular phone model but structured like video-editor output has already answered the question.
- Capture-device corroboration. If the recording device is available, its own records — capture logs, thumbnails, sensor characteristics — can tie the file to the hardware or fail to.
- Distribution history. When and where the file first appeared, and in what form, often matters as much as its content.
What content analysis adds
Examination of the content itself contributes a second, independent line: lighting and shadow consistency, compression-artifact patterns, frame-boundary behavior around a subject's face, audio-video synchronization, and biometric consistency of voice and face across the recording. Automated detectors exist and improve constantly — but so do the generators they chase, which is why a defensible opinion treats detector scores as one input, reports its methods and their error characteristics, and never rests on "the tool said so." An expert whose entire opinion is a black-box classifier score should expect a serious admissibility challenge.
The liar's dividend cuts both ways
Deepfake disputes run in both directions: fabricated media offered as real, and genuine media denounced as fake by the party it damages. The second is increasingly common precisely because deepfakes exist. The forensic frame is identical either way — provenance, device corroboration, content consistency — and the side with the original file and a documented chain of custody usually wins the argument.
What to do now
Preserve the earliest, least-processed copy of the recording you can obtain, and the device that allegedly captured it. Do not rely on the platform copy — re-encoding destroys evidence. If authenticity will be contested, engage the examination early: the analysis shapes discovery demands (for originals, devices, and account records) that are much harder to make after the schedule closes.
From our work
Need this looked at properly?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
