
How to Check Where an Image Came From
To check image provenance, start from the largest copy you can find, run a reverse image search on two engines, read any Content Credential with the public Verify tool, inspect the metadata, find the earliest dated appearance, ask for the process record, and judge visual tells last. Log each result with a URL, a date and a screenshot.
An image arrives in your feed, your inbox or a submission pile, with a name attached or with none. Before you credit it, repost it, buy it or accuse anyone, you need its image provenance: where it first appeared, who made it, and what has happened to it since. Journalists have a settled routine for this, and most of it transfers to an artist or editor with a browser. This tutorial sets the checks in a fixed order, explains what each can and cannot show, and gives you a way to record the result. It closes the process and provenance pillar, where the earlier tutorials cover the artist's side of the same evidence.
The five questions behind an image provenance check
First Draft, the research group that trained newsrooms in verification, condenses the job into five pillars in its Essential Guide to Verifying Online Information: provenance (are you looking at the original?), source (who captured or made it?), date (when?), location (where?), and motivation (why was it posted?). The guide adds the caveat that verification is hardly ever foolproof and works more like collecting corroborating evidence. You are building a case, and the strength of the case is what you report.
Do the cheap, objective checks first and the subjective ones last. If you look at brushwork before you look at the earliest copy, you will see what you already expect to see.
Seven checks, in order
Start from the largest copy
A thumbnail or screenshot has been re-encoded and carries no metadata or credential. Open the post, find the full size file, and save it with the platform's own download option. If the post links to a portfolio, take the file from there.
Reverse image search on two engines
Run the file through two engines with different indexes, for example Google Lens and TinEye. Sort by oldest where the engine allows it. Note every hit that is larger, older or attached to a named account.
Read the credential
Drop the file into the public Verify tool at contentcredentials.org. If a credential exists, read the signer, the actions list and the match status, and follow any ingredients back to the earliest signed file. Most images carry none; that tells you nothing either way.
Read the metadata
Open the file in a metadata viewer and look for IPTC Creator, Copyright Notice, Credit Line and Digital Source Type, plus EXIF date and software. Every field is editable text, so treat it as a lead rather than a verdict.
Find the earliest dated appearance
From the reverse search hits and any names in the credential or metadata, open each candidate and record post date, account and file size. The earliest large copy on a named account is your working origin.
Ask for the process record
Message the working origin and ask for a work in progress crop or a short replay. A real maker can usually produce one within a day; see what a good answer looks like in how to document your art process.
Judge the visual tells last
Only now look at construction, edges, hands, text and repeated detail. Use the checks in how to tell AI images from hand-made art, and weigh them below everything above.
What each check can show, and what it cannot
No single check settles image provenance. The table sets out what each is good for, where it is blind, and how long it takes.
| Check | What it can show | What it cannot show | Time |
|---|---|---|---|
| Largest copy | Whether metadata or a credential could survive at all | Anything about origin on its own | 2 minutes |
| Reverse image search | Older, larger or named copies; reposts and crops | Copies the engines never indexed; private or deleted posts | 5 minutes |
| Content Credential | Signer, actions, ingredients, and whether the pixels changed since signing | Anything when absent; honesty of the signer | 3 minutes |
| Metadata | Creator, copyright, software and date fields as claimed | That the fields are true; anyone can edit them | 3 minutes |
| Earliest dated appearance | A working origin and a date before which the image existed | That an earlier private or offline copy does not exist | 10 to 30 minutes |
| Process record | Construction, corrections and a replay from the claimed maker | Much, if the maker refuses or cannot be reached | 1 day of waiting |
| Visual tells | Patterns worth a second look | Proof in either direction; polished hand-made work triggers the same tells | 5 minutes |
The C2PA 2.1 specification is precise about what the credential row means: the hard binding is a hash of the exact pixels, so a mismatch reports a change without saying who made it or why. Resizing for the web breaks it as surely as a forgery does, and the specification allows a signer to redact private assertions but never the actions list. The IPTC Photo Metadata Standard defines the creator and rights fields in the metadata row as fields a person fills in, which is exactly why they are leads.
Getting more from reverse image search
Reverse image search is the check that finds the original source of an image most often, and it rewards technique. Search the whole image, then crop to the most distinctive region, a face, a signature, a piece of lettering, and search again; engines match crops they miss in the full frame. Flip the image horizontally and search a third time, because reposters mirror to dodge matching. A print on demand shop or a wallpaper site is almost never the origin.
- Sort or filter by date where the engine allows it, and open the oldest three hits, not the top three.
- Compare pixel dimensions across hits. The origin is usually the largest, and a copy that is larger than the claimed original is a warning sign.
- A named portfolio account outranks any social repost.
Documenting what you found
First Draft's first practical rule is to screenshot everything, because posts get deleted and you will need to show your work. Keep one short image provenance log per file, in a text file or a spreadsheet row, and fill it as you go. It turns a hunch into a record you can hand to an editor, a client or a platform.
- The file you tested: filename, pixel dimensions, where you downloaded it from and when.
- Reverse search: the two engines used, the oldest hit from each with its URL, date and size.
- Credential: present or absent; if present, the signer, first action, match status and any ingredient chain.
- Metadata: creator, copyright, software and date fields as read, with a note that they are unverified claims.
- Earliest dated appearance: URL, account, date, size, and a screenshot of the post with the date visible.
- Process request: who you asked, when, and what came back.
- Your conclusion in one sentence, with a confidence word: confirmed, likely, unclear or contradicted.
A good log ends with a sentence like: earliest dated copy is a named portfolio post from 2024-03-02 at 3000 px, credential absent, maker supplied a replay on request; attribution likely. Anything stronger than the evidence is the part a reader will attack.
When the trail goes cold
Sometimes the oldest hit is an anonymous repost, the file carries nothing, and nobody answers. First Draft calls this the rabbit hole and advises knowing when to stop, after trying the direct approach people skip: contact the source and ask. Set a limit, an hour for a repost decision and a day for a purchase or a public claim, then act on what you have.
- To repost: if you cannot name a maker, do not post it as if you could. Credit as source unknown with a link to the earliest copy you found, or skip it.
- To buy or commission: ask the seller for a process record before paying. A maker who cannot show construction for a piece they claim as their own has answered the question.
- To accuse: do not. A cold trail is an absence of evidence, and the person you suspect may have a stripped upload; the reasons real art gets flagged are in why AI image detectors flag real art.
- To reclaim your own work: if the earliest copy of your piece sits on another account, your dated process archive is the evidence a takedown asks for.
Mistakes that break an image provenance check
| Mistake | Why it hurts | Fix |
|---|---|---|
| Testing a screenshot | No metadata, no credential, wrong dimensions | Download the largest copy with the platform's own option |
| One search engine only | Each index misses copies the other has | Two engines, plus a crop and a mirror search |
| Reading a missing credential as proof of AI | Most real work has none | Record absent and move on |
| Trusting the metadata creator field | Anyone can type a name | Treat it as a lead to confirm against the earliest copy |
| Judging brushwork first | Confirmation bias shapes every later check | Visual tells last, and weighted least |
Image provenance in one routine
Image provenance is a routine, and the order is the method: largest copy, two reverse searches, credential, metadata, earliest dated appearance, process record, visual tells last, with a log that ends in a claim you can defend. Run it before you credit, repost or accuse, and most disputes never start. For the fields you are reading in step four, and what an artist should have filled in, see image metadata for artists.
Common questions
How do I find the original source of an image?
Download the largest copy, run it through two reverse image search engines sorted by oldest, then crop to a distinctive region and search again. Open the oldest large hits and look for a named portfolio account. Check any Content Credential and the metadata creator fields as leads, and record the earliest dated appearance with URL and screenshot.
Is reverse image search enough to verify an image?
No. It finds indexed copies and shows which are older or larger, but it misses private, deleted and never indexed posts, and the oldest hit can still be a repost. Pair it with the credential, the metadata, and a direct request to the claimed maker for a process record, then log the result with a confidence word.
Can metadata tell me who made an image?
It can tell you what someone wrote into the file. IPTC Creator and Copyright Notice are useful leads, but they are editable text and are stripped by many platforms, so to verify an image treat them as a claim to confirm against the earliest dated copy and the maker's process record.
What if I cannot find where an image came from?
Set a time limit, record what you checked, and act on the evidence you have. Do not repost it as credited work; label it source unknown with a link to the earliest copy or skip it. Do not accuse anyone, since a cold trail is an absence of evidence. If the image is yours, your dated process archive is what a takedown request needs.
Sources and further reading
Primary references for the facts and definitions in this piece, all from independent publishers:
- Content Credentials: Verify: reading a file's signer, actions and match status.
- C2PA Technical Specification 2.1: the hard binding hash and what a mismatch means.
- IPTC Photo Metadata Standard: the creator and rights fields read in the metadata step.
- First Draft: Verifying online information, the absolute essentials: the five pillars of verification, screenshotting everything and knowing when to stop.
This method is part of the process and provenance pillar. Pair it with How to Document Your Art Process and Content Credentials and C2PA for Artists.