Features

Identity verification: facts, examples and context

Identity verification explained both ways: proving who you are without oversharing, checking the other side, and what a verified badge does not mean.

Identity verification runs in two directions, and almost all the trouble comes from only thinking about one of them.

Downwards, a service asks you to prove who you are. Upwards, you have to work out whether the thing asking is real before you hand anything over. The second question is the one people skip, and skipping it is the entire basis of a large category of fraud: an impostor does not have to break a verification system if it can persuade you to complete one on its behalf.

What to take away

  • Knowing the mechanism tells you what an attacker has to do, and what it costs you if the check fails.
  • A short version of the obligations, because the design decisions determine how much harm a breach does.

Before you verify yourself to anyone

Ask three questions in this order.

1. Who initiated this? If a message, call, email, or pop-up asked you to verify, you are not verifying, you are responding to a claim. Stop and reach the organization through a route you already had: its app, a bookmark, the number on your card. If a genuine verification is pending, it will be visible there.

2. Does the ask fit the relationship? A bank opening an account for you needs your identity documents. A marketplace paying out your sales proceeds may need them. A stranger on a dating app does not. A "delivery company" does not. Somebody who says they will send you money does not. Ask what decision this data is being used for, and whether the amount requested is proportionate to it.

3. What exactly is being requested? There is a difference between confirming a name and a date of birth, and uploading a full scan of a passport plus a selfie holding it. Full document images are the most damaging thing to lose, because they support accounts opened in your name for years afterwards.

Verification requests that are never legitimate

No matter how convincing the sender:

  • A one-time code that was sent to you. It exists to prove you are you. There is no legitimate reason for anyone to want it, not support, not a buyer, not your bank, not a delivery driver.
  • A "verification payment" to prove an account is yours, or to release a transfer. Verification does not cost money.
  • Documents sent to a private individual. A buyer, a landlord you have not met, a date, an employer you cannot independently confirm exists.
  • Remote access to your device "so we can verify you together".
  • Verification through a link that arrived unprompted. Go to the service yourself.
  • A request to receive money and pass it on, framed as proving your account works. That is being used as a money mule, and the legal exposure lands on you.

Handing over documents with less exposure

Sometimes you genuinely do have to send identity documents. Reduce the damage if the recipient is careless or is not who you think.

  • Check the destination before the content. Type the address yourself, and confirm you are on the service's real domain. A password manager that declines to autofill is telling you something useful.
  • Upload inside the service, not by email or chat. Email copies live in two mailboxes forever and are a standard target.
  • Send the minimum. If a document number and a name are enough, do not send the whole page. Cover fields that are not required.
  • Mark the copy for its purpose where the service allows an overlay or where you are sending an image anyway: a visible note that this copy is for that specific application makes reuse harder.
  • Ask what happens to it. A service handling this properly can tell you how long it retains images, whether the check is done by a processor, and how to request deletion. In the EU and UK, and increasingly elsewhere, you have a right to ask.
  • Delete your own copies from the phone's camera roll and from chat threads afterwards. This is one of the most common ways document scans leak.

How the methods actually work, and where each one breaks

Knowing the mechanism tells you what an attacker has to do, and what it costs you if the check fails.

Method What it proves Where it fails
Document scan plus liveness selfie The document appears genuine and a live person matches it Poor lighting, damaged documents, disability, and appearance changes cause false rejections
Knowledge questions about your history That someone knows facts about you Weak: those facts are widely available after breaches
Code to a phone number Control of the number, not of you Number takeover and code phishing
Code or prompt in an authenticator app Control of an enrolled device Approval fatigue; you can be talked into approving
Passkey or hardware security key Control of a key bound to that exact site Strongest against impersonation; needs a recovery path
Bank-linked or government digital ID An identity already verified elsewhere Concentrates risk in one account; not available to everyone
In person with original documents The strongest link between person and document Inconvenient, and not always offered

Two consequences worth carrying around. Anything based on knowing facts about you is weak, because the facts are in circulation. And biometrics do not reset: a leaked face template is not like a leaked password, which is why it is reasonable to prefer a service that verifies and deletes over one that keeps images indefinitely.

Account recovery is the weakest point

Most accounts are not broken into. They are recovered by somebody else. Recovery is verification with the difficulty turned down, because the service is trying to help a locked-out user, and that is exactly the door an impostor uses.

  • Check the recovery email and phone on your important accounts and remove anything stale. An address you no longer control is a permanent open door.
  • Prefer recovery codes stored offline over security questions. Where questions are unavoidable, the answers do not have to be true: they have to be unguessable and recorded.
  • Put the strongest available method on the email account that receives everyone else's password resets. It is the master key.
  • Add a port-out or transfer PIN with your mobile carrier. A hijacked number defeats every text-based check you have.
  • If verification data was exposed in a scam, treat recovery settings as compromised and re-check them; the sequence is in account security.

When verification fails and it is you

This happens to real people constantly and it is not evidence that you did something wrong.

Common causes are a name that does not match across documents after a marriage or a legal change, a recently moved address, a thin or absent credit history, a document that is worn or in a format the system does not read well, no smartphone, poor connectivity, and a face the system struggles with. Several of these fall disproportionately on people who already have the least slack.

What helps: use the alternative route rather than repeating the failing one, because repeated attempts sometimes lock the account. Ask specifically what a manual or in-person review requires. Fix the underlying mismatch where you can, consistent name and address across documents removes a whole class of failure. Keep a note of reference numbers and dates, because you will be re-explaining this. And if you are being asked to pay a third party to "fix" a failed verification, that is a scam.

Verifying the other side

The same rigor, pointed outwards. Where documents of yours have already been misused, the recovery process rather than any further checking is what helps, and it is set out at IdentityTheft.gov.

  • A business: the companies or business registry for its jurisdiction, a registration number that matches the one on its invoice, a verifiable address, and a trading history. Bank details confirmed by a call to a number you found yourself, never the one in the email.
  • A professional: the licensing body's or regulator's own register, checked by number.
  • A person you met online: a live video call at a time you choose, and a reverse image search on the profile photo. That is proportionate, and the fuller version of it is in catfishing. Building a file on a private individual is not, and the boundary is set out in background checks.
  • A support agent who contacted you: they do not get verified. You end the conversation and start a new one through the organization's own channel. This is the whole content of impersonation scams, and it is worth more than any other check on this page.

If you are the one building verification

A short version of the obligations, because the design decisions determine how much harm a breach does.

Match the strength of the check to the risk of the action rather than applying the heaviest check everywhere. Collect the minimum that answers the question, and prefer confirming an attribute (over eighteen, resident here, holds this license), to storing the whole document. Set a retention period and actually delete. Offer a genuine alternative route, because the people who fail automated checks are disproportionately the people who most need the service. Treat biometric data as a special category, since several jurisdictions require specific consent and give people deletion rights over it. Make recovery as considered as enrollment, since it is the path attackers prefer. And log decisions well enough to explain a rejection to the person it happened to. For the underlying model, including what the different levels of assurance are actually for, the NIST digital identity guidelines are the place to start.

Common questions

Is a verified badge proof of identity?

It depends on the platform. On some it reflects a document check; on others it is a paid subscription feature. Treat it as weak evidence and confirm through the organization's own site.

A service wants a selfie holding my ID. Should I do it?

It is a normal request from a regulated financial service, an employer, or a marketplace paying you out. It is never a normal request from a private individual, a buyer, or someone who contacted you first. Verify that the organization is real and that you initiated the process before sending anything.

Is it safer to verify with a bank login or a government digital ID than to upload documents?

Often yes, since fewer copies of your documents end up in circulation. The trade-off is concentration: whoever gets into that one account can present as you in many places, so it needs your strongest sign-in method.

Someone asked me to verify my account by sending them a code. They seemed official.

That is the request itself, not a step toward it. No legitimate party ever needs a code that was sent to you. If you already sent one, change that account's password, sign out all sessions, and check the recovery settings for changes.

More in Features

Features

Best account security tools 2027: facts and context

Account security tools sorted by what each makes impossible rather than unlikely, with the two categories that block and the ones that only reduce.

Features

Phishing scams checklist explained with examples

A phishing checklist in two speeds: a twenty second test for the message in your hand, and one afternoon of setup that stops most of them mattering.

Features

Account security: requirements and practical steps for 2027

Account security ordered by the way accounts are actually lost: the email account, the recovery route, second factors, sessions and connected apps.