Signature check
Check a Fromensics signature
Got an email that ends with “Signed with Fromensics”? Click Check signature. The page checks it in your browser. The signature stays in the part of the link that’s never sent to our server.
What you’ll see
Valid
The signature checks out.
A key that says it belongs to accounts@sterlingcooper.com. It has four words:
- bold
- cove
- dawn
- fern
Invalid
This signature doesn’t check out.
The link was changed or cut short, so treat the email as unsigned. Anyone can paste a footer that says “Signed with Fromensics”.
Empty
Nothing to check yet.
Open this page from the “Check signature” link at the bottom of a signed email.
Compare the bank details
Paste the IBAN or account number from the email. It’s compared on the page and never sent anywhere.
| You’ll see | What to do |
|---|---|
| Matches what was signed. | This bank detail hasn’t changed since the key signed it. |
| Not what was signed. | Don’t pay this account. Call the sender on a number you already have, not one from the email. |
What the page can’t tell you
The page proves a key signed the email. It can’t prove the key belongs to the person. “Anyone can make a key that claims an address. The first time, ask them to read you their four words on a call you start.” The Fromensics extension remembers keys you’ve confirmed, so their emails then show It’s really them.
Questions
Is the signature sent to Fromensics?
No. It sits after the # in the link, which browsers don’t send to servers. The check runs on the page, in your browser.
How long does a signature stay valid?
30 days. After that the page says it’s too old to rely on, and you should treat the email as unsigned.