For property managers

An applicant’s photo of their ID: what the file can tell you, and what it cannot

An application comes in through your portal. The driver’s license photo is exactly what you ask for: the whole card, in focus, lying on a bit of carpet, shot from above on a phone. Nothing about it looks wrong.

In February 2024 a reporter at 404 Media paid $15 to a site called OnlyFake and got back a picture of a California driver’s license carrying whatever name, address, birth date and signature he had typed in. The site said it used “neural networks”. The picture came styled the way verification services ask for it: the card appeared to be laying on a fluffy carpet, as if someone had put it on the floor and snapped a picture. The reporters then used a fake from the same site to get through the identity check at OKX, a cryptocurrency exchange. The site went offline after the story ran. The technique did not.

So it is fair to ask whether you can check the file behind an applicant’s ID photo the way you would check a move-out photo. You can. It tells you less here than it does anywhere else we write about, and it helps to know exactly why before you rely on it.

How often this comes up

The best current figure for rental housing comes from the NMHC Pulse Survey published in January 2024. It surveyed 75 large apartment owners and managers between November 2023 and January 2024. Seventy of them, 93.3%, had seen fraud in the previous twelve months. Of those seventy, 49 (70.0%) had seen “identity theft, fraudulent ID documents or use of another individual’s personal information”.

That is one category in the survey, not three. It does not tell you how many fake ID pictures those operators saw, only that nearly three quarters of large operators have met some form of identity fraud. Faked income documents were more common still, at 84.3%. The survey asks nothing about how any of the fakes were made.

What reading the file can catch

A photo straight off a phone carries a record of its own making: the camera model, the exposure, the moment the shutter fired. A picture that came out of a generator usually carries none of that, and sometimes carries something worse for the person sending it. Checking the file behind an ID photo can tell you three things.

What reading the file cannot catch, and this is the important part

“Camera Original” means a camera took the picture. It does not mean the card in the picture is real.

Print a fake license, lay it on the carpet and photograph it with a real phone, and you get a real camera file with every field intact. It is an honest record of a photograph of a forgery. The same goes for a real card belonging to someone else. Every ID-fraud tactic older than generators produces a perfectly genuine camera file, and checking the file cannot tell any of them apart from the real thing.

What does a picture from a site like OnlyFake carry inside it? We have not had one in front of us, so we will not guess. The 404 Media reporting says nothing about the files’ metadata. Assume the worst, because camera data can be copied into a file by anyone who knows how: a well-made fake may arrive looking exactly like a phone photo, down to the file.

So for an ID the file check is a filter against carelessness. It does not verify anything. A file that names a generator is a serious finding. A file that comes back clean has not been cleared.

Where the real check has to happen

Our articles on repairs and invoices keep coming back to one idea: go around the photo to the thing itself. Look at the leak, look at the countertop, call the supplier. An ID is the same, and the thing itself here is the card and the person holding it.

  1. See the physical card before keys change hands. Hold it, and look at the face on it next to the face in front of you. A picture of a card can be made for $15. Making the card itself is a much harder job.
  2. If you screen remotely, use a service built to check identity, one that looks at the document and the person at the same time, and do not treat an uploaded picture on its own as identification.
  3. Ask for the photo through a channel that keeps the file. An upload form or an email attachment keeps what the phone wrote. A screenshot or a picture forwarded through a messaging app throws it away, and then there is nothing left to check at all.
  4. Check the file anyway, because it is free and quick. If it names an AI tool, stop and ask. If it comes back as a camera original, you have learned where the picture came from and nothing more.
  5. Run the same steps for every applicant, and write them down. A check you apply only when someone “seems off” is a check someone else can question. The same process applied to everyone is easy to defend.

The limits, stated plainly


ImposterShield reads the evidence inside image and video files. It runs in your browser and uploads nothing, which matters more than usual when the file is somebody’s driver’s license. If a file has been stripped, it says so. That is the product working, not failing.

Check the file behind an ID photo

Drop the picture on the page. It shows whether the file names an AI tool, came straight off a camera, has been saved again since, or has nothing left in it. It runs in your browser, so the license never leaves your computer.

Open the checker