DeepFake Check
Back to Blog
Updated DeepFakeCheck Team 6 min read

How to Detect a Deepfake Video in 2026: A Step-by-Step Guide

Start with the source, not a single visual clue

A strange blink, blurred jawline or mismatched shadow can justify a closer look. None of those signs proves that a video is a deepfake. Compression, low light, stabilization, editing and screen recording can create similar artifacts.

The safer approach separates three questions:

  • 1. Where did the video come from? Check the account, caption, upload time and earlier copies.
  • 2. What does the file record? Review the timeline, metadata and any Content Credentials.
  • 3. What does a detector estimate? Treat the result as one risk signal that may be wrong.

NSA, FBI and CISA guidance recommends combining verification, passive detection and provenance rather than relying on one technique.

A seven-step video verification workflow

1. Preserve the post and the best available file

Record the original URL, account name, caption and upload time before a post changes or disappears. When you have permission, save the original attachment or export. A forwarded download is usually more useful than a screenshot or screen recording because each extra conversion can remove metadata and visual detail.

Keep a clean copy. If the video may matter later, record its file hash and work from a duplicate.

2. Test the claim outside the video

Write down what the clip is supposed to prove. A real recording can carry a false date, location or caption, and a synthetic clip can reuse true background details.

For an impersonation or payment request, stop the transaction and contact the person or organization through a number you already know. The FBI also recommends a family secret word or phrase for identity checks. Do not use contact details supplied inside the suspicious message.

3. Review the whole timeline

Watch once at normal speed, then review several moments from the beginning, middle and end. Compare repeated details such as face boundaries, glasses, jewelry, hands, text, reflections, shadows and object continuity.

Look for changes that persist across multiple frames. A single blurred frame is weak evidence because motion and compression can produce the same effect. There is no reliable fixed blink interval, breathing pattern or “too perfect” appearance that identifies every deepfake.

4. Check audio and picture separately

Listen for abrupt changes in room tone, cuts, timing or a voice that does not match the visible speaker. Then watch the mouth and face without sound.

These are review prompts, not rules. Real recordings can have clean studio audio, dubbed speech or network lag. Synthetic speech can contain breaths and hesitations. A lip-sync mismatch can come from ordinary editing or connection delay.

5. Search representative frames

Capture clear frames that contain a face, landmark, logo or distinctive background. Reverse-search more than one frame to find earlier publications or a different caption.

The InVID-WeVerify Verification Plugin provides search, OCR, image-context and forensic tools for online verification. A match can establish that an image existed earlier, but it does not by itself explain every edit in the current video.

6. Check Content Credentials when available

Use Content Credentials Verify on a supported file. It may show signed provenance information and recorded changes.

No credential does not mean the video is fake. Credentials are still being adopted, and platforms or editing workflows may remove them. A valid credential records signed statements about the asset; it does not prove that the depicted event or caption is true. The C2PA explainer covers that distinction in more detail.

7. Use a detector as a second signal

Upload the best available copy to a detector that supports video. Read the evidence and limitations, not only the score. If the consequence is serious, preserve the result and compare it with source verification or qualified forensic review.

Different tools may disagree because they sample different frames and look for different patterns. Agreement does not turn model output into proof.

What visual artifacts are worth reviewing?

The FBI advises people to look for subtle imperfections such as irregular faces, unrealistic accessories, inaccurate shadows, lag, voice mismatch and unrealistic movement. These clues can help decide where to inspect more closely.

Useful review areas include:

  • face or hair boundaries that change between frames;
  • glasses, jewelry, teeth, hands or text that deform or disappear;
  • reflections, shadows or lighting that conflict within the same scene;
  • mouth movement and audio that drift apart;
  • objects that change shape or position without a plausible cause.

Always compare multiple moments. Re-encoding, beauty filters, frame interpolation and poor connections can create false alarms.

Using DeepFakeCheck on a suspicious video

  • 1. Open the full-video detector.
  • 2. Upload an MP4, MOV or WebM file up to 100 MB. The current tool accepts files and does not fetch third-party URLs.
  • 3. The browser samples up to 10 timestamped frames across the full duration. It does not inspect every frame, so a brief manipulation between samples can be missed.
  • 4. Review the timestamps and visible indicators. Repeated conflicts matter more than one compression artifact.
  • 5. Verify the sender, caption and original publication outside the detector.

DeepFakeCheck does not authenticate a person or event. Usage limits apply, and a low-risk result only means the sampled evidence did not support a stronger warning.

If the concern is specifically a replaced identity, use the face swap detector. For a broader tool comparison, see deepfake detection tools in 2026.

What to do when money, safety or reputation is at risk

Pause before sharing, paying or accusing someone. Preserve the original message and file, then verify through a known channel.

For suspected fraud in the United States, the FBI directs victims to IC3. Elsewhere, use the relevant national fraud or cybercrime reporting service. Report manipulated media to the platform when its rules apply.

Do not use an automated score as the sole basis for a legal, employment, academic or disciplinary decision. High-stakes cases need a documented chain of custody and qualified review.

Limits to keep in mind

  • Sampling has gaps. A detector can miss a short edit between reviewed frames.
  • Compression cuts both ways. It can hide original evidence and create artifacts that look suspicious.
  • Visual clues are not universal. Generators and editing workflows change, while real videos can contain the same anomalies.
  • Provenance and detection answer different questions. One records signed history; the other estimates patterns in the file.
  • Source verification remains necessary. A technically authentic video can still be old, mislabeled or taken out of context.

Sources

Need to check a suspicious file?

Open the matching detector and interpret the result alongside the source and context.

Open Detector