Can you trust the metadata in a photo someone sent you?

Nearly every page on this site puts you on the sending side: your file, your risk, your decision about what to remove before it leaves. This one turns the file around. Somebody else has sent you a photo, they have made a claim about it — it is recent, it is of their apartment, it is untouched, it shows the damage as it was found — and you have opened the metadata to see whether the claim holds. The question this page answers is not how to read the fields. It is what reading them entitles you to believe, which turns out to be considerably less than most people assume, and less in both directions.

Ready to clean a photo? MetadataWipe processes JPEG and PNG files locally — no account and no server transfer.

Open MetadataWipe tool

The situations are ordinary. A marketplace seller sends a picture of the item and says it was taken this morning. A contractor sends photographs as proof the work was finished. A landlord or host sends listing images that may or may not be from the current decade. Someone in a dispute — a neighbour, a customer, a former partner — produces a photo as support for their version of events. A person you have not met sends a picture of themselves. In each case you are not protecting anything; you are evaluating something, and the cost of getting it wrong runs the other way. On the rest of this site the failure mode is a leak. Here the failure mode is a confident false conclusion: you believe a photograph you should have doubted, or you accuse someone based on a field that never meant what you thought it meant.

That reversal matters because the reasoning habits are different. Removing metadata is a procedure, and procedures can be followed. Reading metadata is inference, and inference goes wrong quietly. The rest of this page is mostly about the ways it goes wrong.

What a metadata field actually is

Start from the right mental model, because most bad conclusions come from the wrong one. People treat a metadata field as an observation — a record of what happened, made by the file itself. It is not. A field is a claim written by whatever software last saved the file, derived from whatever that software had available at the time, on a device configured by a person. That is the whole of its authority.

There are three separate reasons the claim can fail to match reality, and they are worth keeping apart because they call for different follow-up questions.

Put those together and you get the core asymmetry of reading someone else's photo: the presence of a field is weak positive evidence, because it could have been written by anyone, and the absence of a field is almost no evidence at all, because it disappears for a dozen innocent reasons.

Why an empty header proves nothing

The most frequent misreading, by a wide margin, is treating a bare file as an admission. There's no EXIF on this — they've scrubbed it — what are they hiding? Almost every step of that chain is unsound.

Photos arrive stripped all the time without anyone intending it. Many platforms re-encode images when they are posted, so a picture saved back down from a public post is usually a derivative rather than the original — the habits vary by service and change over time, which is the subject of which social platforms strip photo metadata automatically. Messaging apps frequently compress. A screenshot of a photo is a new image with the screenshotting device's own minimal record and none of the original's. Re-saving in a gallery or editing app can rewrite the file. Even a file forwarded from a chat rather than pulled from a camera roll may be the compressed copy rather than the source.

And when the removal was deliberate, it still is not an admission about the photo. Stripping metadata before sharing is standard privacy advice — it is the advice this entire site gives — so a person who cleans their photos is displaying a habit, not a motive. Inferring guilt from a clean file is inferring guilt from cautiousness.

What an empty header genuinely tells you is narrower and still useful: you are probably not holding an untouched original. That is a good reason to ask for the original, and a good reason not to build anything on this copy. It is not a finding about the sender.

What the common fields are actually worth

Assuming you do have fields to read, here is a realistic valuation of the usual ones. The pattern to notice is that almost every field is informative about consistency and poor as standalone proof.

A reading discipline

The following sequence is designed to stop the two failure modes — believing a field and over-interpreting its absence.

  1. Write down the claim before you look. "Taken yesterday", "taken at this address", "not edited" and "taken by this person" are four different tests with four different answers. Deciding afterwards what the metadata proves is how people end up proving whatever they already suspected.
  2. Establish which file you are holding. A copy that came through a messaging app or a social post is a different artefact from the original. If the question matters, ask for the file as it came off the device, sent by a route that does not recompress, and note that the request itself is informative.
  3. Look for internal consistency, not single-field truth. Do the various timestamps in the file agree with each other? Does the camera model match what this person plausibly owns or what their other photos show? Does the location fit the time?
  4. Compare across several files. A set is much harder to fabricate coherently than one file, and this is where most real discrepancies surface. It is the same property that makes a batch of photos leak more than one photo does, working in your favour for once.
  5. Seek corroboration outside the file. What is visible in the frame — weather, seasonal light, signage, a model of car, the state of a building — is frequently more informative and much harder to edit than a tag. So are ordinary non-technical checks.
  6. Decide in advance what would change your mind, and accept "cannot tell" as a real, common and respectable result. Most of the time the honest answer to "does the metadata prove this" is no.
  7. Do not confront on a field alone. Given how easily timestamps go wrong innocently, an accusation resting on one value is likely to be both wrong and unrecoverable.

One practical caution about handling: preserve the file you were sent. Opening it in some applications, re-saving it, or running it through any processing produces a different file, and if the question ever becomes serious you will want the thing as it arrived. Work on a duplicate.

Where this site's tool fits, and where it does not

MetadataWipe is a removal tool, and it is worth being explicit that it is the wrong instrument for the task on this page. It accepts a single JPEG or PNG at a time. Its built-in check is a quick heuristic scan of roughly the first half-megabyte of the file, reporting only whether EXIF-like markers, GPS-like markers or PNG metadata chunks appear to be present — it displays no values, so it cannot show you a date, a coordinate pair or a camera name. Cleaning works by redrawing the image and generating a fresh copy with -metadatawipe added to the filename. Everything runs in the browser; the file is not sent anywhere and the download is produced from data already held in the page.

For the receiving end, that means two things. First, if you want to read values rather than detect their presence, you need a metadata viewer rather than a stripper. Second, and more importantly: do not clean a file you are evaluating. The cleaned output is a newly generated image, and what it discards is precisely the material you were examining. If you later decide the cleaned copy is the one you want to forward on — because you are republishing the photo and do not want to pass someone else's location onward — that is a separate, legitimate step to take on a duplicate, after you have finished looking.

Common mistakes and misconceptions

"No metadata means they scrubbed it." It usually means the file has been through a normal pipeline. And even deliberate removal is ordinary privacy behaviour, not a signal about the photo's content.

"The date in the file is the date it was taken." It is the capturing device's clock reading, subject to drift, wrong settings, time-zone ambiguity and straightforward later editing. Treat it as a claim to be corroborated.

"The coordinates put them there." They put a device's positioning estimate there, at some moment, in the belief of that device. They do not identify the photographer, and being somewhere is not the same as the claim you are probably testing.

"Faking metadata takes real skill." Writing tag values is routine. The realistic barrier to a convincing fake is internal consistency across several files, not technical difficulty on one.

"An editing-software tag means the image was manipulated." It means the file passed through that software. Cropping, resizing and exporting produce the same trace as anything else, and many innocuous paths leave no trace at all.

"Metadata is where the answer will be." In most everyday disputes it is not. The contents of the frame, the timing and manner of the message, what the person says when asked a specific follow-up question, and information from outside the photograph entirely will usually settle things faster and more reliably than any field ever will.

"If it looks clean, it's safe to pass on." Different question, and worth separating from everything above. Whether a photo is trustworthy and whether it is safe to republish are unrelated; a file can be entirely genuine and still carry someone else's home address onward.

Related guides

See also:

Frequently asked questions

Someone sent me a photo with no metadata at all. Are they hiding something?

Probably not, and this is the single most common wrong conclusion people reach. A bare header is the normal end state of a great many ordinary routes: a photo posted to a platform and saved back down, an image sent through a messaging app that recompressed it, a screenshot, a picture re-saved by a gallery or editing app, a file exported from a chat thread rather than from a camera roll. None of those involves anyone deciding to remove anything. There is also a second reason to be careful: stripping metadata is normal, widely recommended privacy hygiene, so even a deliberate removal is not evidence of bad faith about the subject of the photo. An empty header tells you that you are almost certainly not looking at an untouched original. That is a genuinely useful fact, and it is roughly the only one you get.

Can EXIF dates and GPS coordinates be faked?

Treat them as editable. Metadata fields in common image formats are ordinary data written into the file, and in the general case nothing in the file makes them tamper-evident — there is no built-in signature that a viewer checks and no neutral party attesting to the values. Editing tags is not an exotic forensic skill; a range of widely available software can write them. Signed provenance schemes exist that are specifically designed to close this gap by binding claims to an asset in a way that can be validated, but whether any given photo carries one, and whether the software you are using can check it, varies and has to be established case by case rather than assumed. In practical terms: a field is a claim recorded by whatever last wrote the file, and it inherits that writer's accuracy and honesty.

How much weight should I give GPS coordinates in a photo?

Read them as where the capturing device believed it was, which is a different statement from where the photo was taken and a very different statement from where a particular person was. Positioning can be approximate, can come from a cached or assisted fix rather than a fresh one, and can be absent or coarse depending on the device, the settings and the conditions at the time. Beyond accuracy, there is an attribution gap: coordinates say nothing about who was holding the camera, and a photo of a place is not proof that the sender was ever at that place. GPS is one of the more informative fields when it is present and is a reasonable lead to follow, but it earns a follow-up question, not a conclusion.

Can I use MetadataWipe to check a photo somebody sent me?

Only in a very limited way, and this page is the wrong job for it. MetadataWipe is a removal tool for JPEG and PNG files. Its built-in check is a quick heuristic scan of roughly the first half-megabyte of the file that reports whether EXIF-like markers, GPS-like markers or PNG metadata chunks appear to be present. It does not display values — no dates, no coordinates, no camera names — so it cannot answer any of the questions on this page. Reading actual field values needs a metadata viewer, not a stripper. There is also a caution worth stating plainly: do not run a file through a removal tool if you might need to examine it later or hand it to someone else, because cleaning replaces it with a newly generated copy and the information you were trying to evaluate is exactly what gets discarded. Keep the file you were sent, untouched, and work on a duplicate.

Remove EXIF data, GPS location, and common photo metadata in your browser — one file at a time, before you share it.

Try MetadataWipe free