When a political document surfaces online with a claim that it's “leaked,” my instinct as an editor is to treat it like any other piece of evidence: valuable, potentially explosive, and in need of careful verification. I’ve overseen coverage where a single leaked memo changed a campaign narrative overnight — and I’ve also seen how badly a newsroom can be burned when a document turns out to be manipulated. Over the years I’ve developed a checklist of the exact kinds of evidence I ask reporters to produce before running with a story. Below I walk through those markers, the tools and experts we turn to, and the practical limits we keep in sight.
Provenance and chain of custody
The first thing I want to know is: where did this document come from? Provenance is about the chain of custody — who had it, when, and how it moved. A clear provenance can’t prove authenticity on its own, but it frames every other check.
When a source approaches me, I ask for a timeline: how they obtained the file, who else has seen it, whether there were intermediaries. If they got it off a messaging app, which app and what kind of account? If it was handed over in person, do any witnesses corroborate that meeting? A document with multiple, independently verifiable custody points is more credible.
Metadata and file-forensics
Digital files carry metadata — timestamps, authoring software, device IDs — that are often the first concrete clues. I ask reporters to extract and preserve metadata using tools like ExifTool for images and Office/PDF metadata, or specialized suites like Forensically and Ghiro for deeper image analysis.
Some specific checks I look for:
It’s important to remember that metadata can be altered, so I don’t treat it as definitive. But an inconsistent or suspicious metadata trail raises red flags and guides further verification.
Cryptographic and signature checks
When available, cryptographic verification is gold standard. Official documents sometimes carry digital signatures, PGP signatures, or transmitted checksums. If a government or institution publishes a public key, we compare signatures with tools such as OpenSSL or built-in verifiers in PDF readers.
For example, an authenticated PDF may include a visible digital signature that, when clicked, shows whether the signature is valid and which certificate it matches. If a file purports to be an internal email, we can sometimes check DKIM/SPF headers or message IDs to determine origin.
Technical and typographical forensic analysis
For print-looking files (scans or PDFs), I pay attention to technical details that are hard to fake consistently across a whole document.
I’ve asked designers and typography experts to compare suspected fakes against official templates using font-identification tools like WhatTheFont and manual inspection of style sheets.
Contextual consistency and factual corroboration
Even if all technical checks pass, a document must make sense in its political and factual context. I look for corroborating details that can be independently checked.
We often reach out to multiple, independent insiders — former employees, partner organizations, or vendors — to see if they recognize the format or can confirm specific details. A single anonymous source rarely suffices; multiple, separate confirmations strengthen the case.
Source vetting and motives
I always assess who is providing the leak and why. Motive doesn’t disprove authenticity, but it helps contextualize potential manipulation. If a disgruntled employee with access provides the file, that’s different from a politically aligned actor claiming a “leak.”
We verify the source’s identity where possible: email verification, phone calls, video chats, even in-person meetings. When sources ask for anonymity, I still try to verify their claims through documents or secondary confirmations.
Expert consultation
No newsroom can be expert at everything. When a document’s authenticity hangs on niche technical points, I call in specialists.
We often quote these experts in articles to explain technical findings to readers — transparency matters when you’re asking the public to trust your judgment.
Cross-referencing physical evidence
When possible, I prefer having both digital and physical verification. Photocopies, printed letterhead, or original-signature pages can be compared to known originals. Paper analysis (watermarks, stock type) and ink analysis are tools laboratories use, though we turn to them only when stakes are very high and resources allow.
Red flags that require caution
There are certain patterns that usually demand skepticism:
Practical checklist I use before publication
| Check | Why it matters |
|---|---|
| Provenance documented | Frames credibility and leads to other checks |
| Metadata extracted | Gives timeline and technical clues |
| Cryptographic/signature verification | Strong technical authentication |
| Forensic image/file analysis | Detects edits or inconsistencies |
| Contextual corroboration | Confirms facts independent of file |
| Source identity checked | Assesses motive and reliability |
| Expert opinions obtained | Explains complex findings to readers |
In practice, verification is rarely binary. Most leaked documents present a mix of confirming and suspicious signs, and editors must weigh the public interest against the risk of amplifying misinformation. I’ve published leaks that later required updates — and I’ve spiked others that would have misled readers. What I’ve learned is to be transparent with audiences about the evidence we have, to explain which checks we performed, and to be candid when uncertainty remains.
When the stakes are high — a document that could change elections, affect national security, or ruin reputations — I push for additional layers of verification: multiple independent sources, lab forensics, or official confirmation. And when we can’t reach that threshold, I err on the side of caution, while still reporting responsibly about the existence of the claim and the verification process itself. Readers deserve both the story and the full context on how we vetted it.