Tools are one input, not a verdict
Each tool below sharpens one part of source. Use them to gather evidence, then reason — a single score, label, or marker never settles the question on its own.
Content provenance & credentials (C2PA)
C2PA Content Credentials attach a tamper-evident record of where a file came from and how it was edited. They help you trace origin — but only when they survive; platforms often strip them, and their presence describes history, not truthfulness.
Content Credentials — Verify
Upload an image or paste a link to inspect any attached C2PA provenance: capture device, AI tool used, and edit history.
No credentials does not mean fake — most files never carry them, and they are easily stripped on upload. Credentials describe origin, not whether a claim is true.
C2PA Viewer
Drag-and-drop verification with full raw manifest JSON — useful when you need technical detail beyond a visual summary.
Same limits as any C2PA tool: provenance is not a truth guarantee.
Digimarc C2PA Chrome Extension
Right-click images, video, or audio to verify credentials while browsing; can auto-detect assets with manifests and show a Cr pin.
Only works when credentials survive to the page you are viewing.
Adobe Content Authenticity
Read the Content Authenticity Initiative's guidance on how credentials are created and what each field means before relying on them.
c2patool (CLI)
Official command-line tool for reading and validating C2PA manifests locally — batch checks and developer workflows.
Platform AI labels
Major platforms now label content that is disclosed as, or detected to be, AI-generated. Labels are a starting cue — coverage is inconsistent and depends on creators disclosing.
YouTube — altered/synthetic content labels
Check the description and expanded details for an 'Altered or synthetic content' disclosure; creators must flag realistic AI content.
The label relies on creator disclosure and selective detection. Its absence is not a guarantee the video is authentic.
Instagram / Meta — 'AI Info'
Tap the '⋯' menu on a post and look for 'AI Info' — Meta adds this when content is disclosed or detected as AI-generated (including via C2PA/IPTC signals).
Detection is partial and can miss edited or re-uploaded media. 'AI Info' can also appear on lightly AI-edited photos, not only fully generated ones.
LinkedIn — C2PA Content Credentials
LinkedIn shows a small 'Cr' Content Credentials marker on images that carry C2PA data; click it to view the provenance record.
A Cr marker means provenance data exists — not that the image is fake or real. Read the underlying record instead of treating the badge as a verdict.
TikTok — AI-generated content label
Look for TikTok's 'AI-generated' label; TikTok also reads C2PA credentials to auto-label some uploads.
Auto-labeling only triggers when credentials are present and intact.
X (Twitter) — synthetic media policy
Creators can voluntarily label posts as AI-generated in the composer. X also restricts deceptive synthetic media under its manipulated-media policy.
Labeling is voluntary — most AI content on X carries no label. Read the policy for context, not as a detection tool.
Watermark detection (SynthID)
SynthID is an invisible watermark Google embeds in media made with its AI. Detecting it can confirm a Google-AI origin — but it says nothing about content from other generators.
Google Gemini
Upload an image and ask whether it was created with Google AI; Gemini can identify content carrying Google's SynthID watermark.
Only detects Google's SynthID. Other AI generators leave no SynthID, so a 'no watermark' answer is not proof the content is real.
SynthID — how it works
Read how SynthID watermarking and detection work, and which Google products embed it, so you know the limits of a positive or negative result.
Account & domain tracing
Source is about who is accountable — not just what metadata a file carries. Trace domains, account history, and page longevity before trusting a claimed origin.
WHOIS lookup
Check when a domain was registered, who holds it, and whether registrant details are hidden — new domains pushing urgent offers are a common scam pattern.
Privacy-protected WHOIS is common and not suspicious on its own — combine with other signals.
Wayback Machine
See whether a site or page existed before the claim surfaced — impersonation pages often appear only days before a scam.
Social Blade
Review account creation date, follower growth, and posting patterns — brand-new accounts pushing financial offers deserve extra scrutiny.
Growth metrics alone don't prove a scam; use alongside content and link checks.
Google — About this result / image
When available, tap 'About this result' in Search or 'About this image' in Google Images for indexing context and earlier appearances.
Not available for every result; absence doesn't mean the source is trustworthy.

Meet the Amito toolkit
Most verification tools handle only one part of the STOP&SCAN framework — and many aren't free to use. Our program's technical cohort has been building Amito, the AI Media Integrity Toolkit: a conversational bot that turns the framework into an evolving, interactive toolkit you can chat with.
Start a chat with the Amito bot on Telegram.
Open on Telegram
@AMITOAIBOT