How to tell if the date or time on a photo was changed
A photo never says its date was edited. What it does carry is several dates, written by different things at different moments: the camera, the app that last saved it, the GPS chip, and your computer. Someone who changes one of them usually leaves the others behind. When two of those dates cannot both be true, the photo's own story is broken. When they all agree, the story holds together, which is not the same as being true.
Have the photo in hand? Upload it and ChronoVerify reads every date it carries, compares them, and tells you whether they contradict. Free, no account.
Check the photo's datesCan you tell if someone changed the date on a photo?
Sometimes. It depends on how the change was made.
Most people change a date in their phone's gallery or in Windows. That rewrites one date and leaves the rest alone, so the photo ends up telling two stories at once. You can catch that by comparing the dates against each other.
Someone who knows what they are doing uses a metadata tool and rewrites every date to match. The photo then tells one consistent story that happens to be false. Nothing inside the file can catch that. What can: a signed Content Credential, other copies of the picture on the internet, and the scene in the photo itself.
If the dates contradict each other, do not trust the date. If they agree, nobody made a careless edit, and that is all you know.
The five dates a photo carries
Cameras write a hidden block of information into every photo, called EXIF. It holds the capture date, the device, sometimes the GPS position, and more. You can see it with a free viewer such as ChronoVerify's EXIF inspector. Here is what to look for.
| Date | EXIF name | Written by | Changes when |
|---|---|---|---|
| Taken | DateTimeOriginal | The camera, when you press the shutter | Someone edits it in a gallery app, in Windows, or with a metadata tool |
| Created | DateTimeDigitized | The camera, at the same moment (a scanner, for old prints) | Rarely. Most gallery date edits leave it alone, which is why it gives edits away |
| Last saved | DateTime | Whatever app last saved the file | Every export, edit, or re-save |
| GPS time | GPSDateStamp and GPSTimeStamp | The GPS chip, on world time (UTC) | Only by tools that know to rewrite it |
| File dates | Date modified, date created | Your computer, not the photo | Every copy, download, or save |
One more detail: the "taken" date is written in local time and usually has no time zone attached, so 3:30 PM could be 3:30 in any city. Newer phones add a time zone tag. Older photos do not have one, and that is normal.
Which contradictions show the date was changed?
Read the dates against each other in this order. ChronoVerify checks the first two on every upload. The third and fourth you check by eye in the inspector.
- Last saved comes before taken. A file has to exist before it can be saved. If the "last saved" time is more than an hour earlier than the "taken" time, the dates cannot both be true. ChronoVerify flags this as a metadata anomaly. The one-hour margin is there because a clock change, for example the end of daylight saving time, can legitimately move a save time a little earlier.
- Taken in the future, or before 1990. A "taken" time more than 48 hours ahead of now is flagged. So is a date before 1990, when consumer digital cameras did not exist. The 48-hour margin covers every time zone and a badly set clock, so a real photo never trips it.
- Taken and created disagree. A phone or camera writes both at the same moment, so they should match to the second. If someone changed "taken" and forgot "created", they split, and "created" is usually the honest one. Scanned prints are the exception: there, "created" is when the scan was made.
- The GPS time does not fit. GPS time is world time. Subtract it from the "taken" time and you should get a whole number of hours (or a half hour in a few countries): the time zone. If the two are nine days apart, or four hours and seventeen minutes apart, someone rewrote the "taken" date and missed the GPS block. ChronoVerify shows the GPS location; comparing the two clocks is a check you do yourself.
Now the two things that look like evidence and are not. A "last saved" time after the photo was taken is what every export, edit, or phone backup produces. An editing app's name in the file, such as Lightroom or Snapseed, only means the photo was opened there at some point. ChronoVerify reports both without alarm, because treating them as red flags would accuse most honest photos.
How to check a photo yourself
- Open the hidden dates. Drop the file into the free EXIF inspector and find the four dates in the table above. Ignore the friendly "Date taken" label in your file manager; it shows only one of them.
- Compare taken against created. They should match. A split is the most common trace of a gallery date edit.
- Compare last saved against taken. Later is normal. Earlier by more than an hour is a contradiction.
- Check the GPS time, if there is one. The gap to the "taken" time should be a whole time zone.
- Run the free verifier. Upload the file to ChronoVerify. It runs the impossible-date checks above, reads any signed Content Credential and checks it against the official trust lists, and gives one plain result: consistent, metadata anomaly, or provenance confirmed.
- Look outside the file. Google's About this image shows when Google first saw the picture, which puts a limit on how new it can be. Shadows, weather, and known events pin down the claimed date from the scene itself. A date that survives every check inside the file can still fail here.
How iPhone, Windows, and metadata tools change a date
What an edit leaves behind depends on where it was made.
- iPhone and Mac Photos. Adjust Date and Time changes the entry in your photo library, not the original file. Export the unmodified original and the camera's dates are still inside. Share an edited copy and the copy carries the new date. The capture-time guide covers where each device keeps the date.
- Windows. Right-click, Properties, Details lets anyone type over Date taken, and Windows writes the new value into the file. Microsoft documents that field as the EXIF "taken" date. The other dates stay as they were, which is exactly where the comparison above catches it.
- ExifTool and similar tools. One command rewrites taken, created, and last saved together, and an option keeps the file's modified date untouched. Someone who does this leaves no contradiction. That is the honest limit of every metadata check, including ours, and the reason a signed credential and outside evidence are the only durable anchors.
What a signed Content Credential adds
Some cameras, phones, and editing apps sign their photos with a C2PA Content Credential. The signature covers the file's contents and the time of signing, so the date is no longer a text field anyone can retype. Change a date after signing and the signature no longer matches: the credential reads as Invalid instead of Trusted. ChronoVerify is a C2PA Conformant Validator, listed on the C2PA Conforming Products List for JPEG, PNG, WebP, and AVIF, and it checks every credential it finds against the official C2PA and CAI trust lists. Credentials are still uncommon on everyday photos, and most social platforms strip them on upload, so their absence proves nothing. When one is present and Trusted, it is the strongest answer this page can offer.
When you need a record you can hand to someone
A screenshot of a metadata viewer is not evidence anyone else can check. If the date matters, for an insurance claim, a marketplace dispute, a workplace issue, or a story, ChronoVerify produces a signed PDF report for a single photo for $29, bought at the result screen of the free verifier with no account. It records the file's fingerprint, every date read, each check and its outcome, the Content Credential result, and the pixel analysis, then signs it and adds an independent trusted timestamp that can be verified offline. Anyone can check the signature against our published public key without trusting us. It is a record for review, not courtroom proof, and it says what the file's data says, not whether the scene in the picture happened.
Honest limits
Every check here reads what the file says about itself. A contradiction shows the recorded history is unreliable; it does not say who changed what, or why. Agreement shows only that nobody made a careless edit. A one-hour gap can be daylight saving time rather than a rewrite, which is why the margins exist. Screenshots and downloads from social platforms usually carry no dates at all, and a missing date is not evidence of anything. ChronoVerify never turns a later save time or an editing app's name into an accusation, and it needs two independent signals before it flags pixel-level editing. On its measured corpus of real photos, no genuine capture was wrongly flagged. The benchmark has the figures and the method page lists every limit.
Want to know whether a photo's dates agree, and a signed record if they matter?
Check a photo nowCommon questions
Can you tell if someone adjusted the time on a photo?
Sometimes. A date changed in a gallery app or in Windows usually rewrites one date and leaves the "created", "last saved", and GPS dates as they were, so the dates contradict each other. A change made with a metadata tool that rewrites every date leaves no contradiction, and only a signed Content Credential or evidence outside the file can catch it.
Does changing the date on an iPhone change the photo file?
Not the original. Adjust Date and Time in Photos changes the entry in your library, and an export of the unmodified original still carries the camera's dates. A copy shared with edits applied carries the new date.
Does ChronoVerify detect an edited date?
It detects contradictions. A "last saved" time more than an hour before the photo was taken, a "taken" time more than 48 hours in the future, or a date before 1990 is flagged as a metadata anomaly. A later save time and an editing app's name are reported without alarm, because every honest export produces them. A rewrite that leaves all the dates consistent cannot be detected from the file alone.
What if all the dates agree?
Then nobody made a careless edit, and that is all it means. The date can still be wrong if every field was rewritten together or the camera's clock was wrong. Check a Content Credential, Google's About this image, or the scene itself before relying on it.
Is the file's date modified the same as the photo's date?
No. Date modified and date created belong to your computer and change on every copy or save. The photo's own dates live inside the file. Comparing the inside dates to each other is the real check; the file dates only tell you about this copy.
Sources and further reading: CIPA DC-008-2019, Exif 2.32 specification (the DateTimeOriginal, DateTimeDigitized, DateTime, OffsetTime, and GPS tags); Microsoft Learn: System.Photo.DateTaken maps to EXIF tag 36867; ExifTool by Phil Harvey and its FAQ on writing date and time tags; C2PA Technical Specification 2.3.