You withhold $650 for a cracked bathroom vanity top. The itemized statement goes out, and a week later the tenant replies with a photograph: the same vanity, the same crack, and one line of text. “This was here when I moved in. I took this the day I got my keys.”
Maybe they did. Maybe the crack was there all along and nobody wrote it on the move-in checklist. Or maybe the photo was taken last month, the week the crack happened, and “the day I got my keys” is doing all the work.
For most of the history of this business you settled that by looking at the picture and deciding whether you believed the person. That was never a good method, and it is getting worse, because the same tools that let anyone produce a convincing photograph also let anyone doubt one. So it is worth knowing what you can actually check, and what the check will do when the tenant is right.
The fraud to expect is a real photo with the wrong date
The public conversation about AI and rental disputes imagines a tenant generating a picture of damage that was never there. That can happen. It is not what you will see most often.
What you will see is a genuine photograph of a genuine crack, taken at a different time from the one claimed. Nothing about it is fabricated except the sentence attached to it. It needs no software, and you cannot catch it by looking, because the picture is real.
What catches it is the date. Not the one in the email: the one inside the file.
What the file knows that the email doesn’t
When a phone takes a photograph it writes a block of data into the file alongside the pixels: the make and model of the device, the exposure settings, and the time on the phone’s clock when the shutter fired. An image generator writes none of that, because there was no camera and no moment.
Drop the original file on our checker and, if that block has survived, you get something like:
Camera Original. Shot on Samsung SM-F966U, capture settings still intact (ExposureTime, FNumber, ISO, FocalLength, DateTimeOriginal). Camera clock recorded 2025-08-02 14:11:09.
Put that line next to the lease. If the keys changed hands on 1 August, the tenant’s account just got considerably stronger. If the clock says 14 March, eight months into the tenancy, you have a specific, polite question to ask, and a tenant with an honest explanation (a reset phone, a wrong time zone, a different photo) can answer it in a sentence.
One trap worth knowing: the date your computer shows next to a file (“date modified”, “date created”) is not the capture date. It records when the file arrived on your machine or was last saved, and it changes every time the photo is downloaded or copied. Only the date inside the file means anything, and that is the one the checker reads.
Five answers, and what each one means for this dispute
The checker gives one of a small number of verdicts. For a pre-existing-damage claim, each points somewhere different.
- Camera Original, clock date at or before move-in. This supports the tenant. Take it seriously. If your own move-in record does not show the crack, you are likely to lose this line item, and it is much cheaper to find that out now than in front of a judge.
- Camera Original, clock date well into the tenancy. A concrete question about the timeline, not an accusation. Ask it plainly and let them answer.
- Re-saved. The file still names a device but the capture settings are gone, so it has passed through an editor or an app since it was taken. Sometimes the clock date survives and is shown. Re-saving is ordinary, so this is a reason to ask for the original, not a reason to disbelieve.
- Can’t Verify. No camera data at all. The photo was sent through WhatsApp or Messenger, sent as an MMS text, or screenshotted, and those routes usually strip it. This says nothing about whether the photo is honest. It says the evidence was thrown away in transit, usually by someone who did not know it existed. Ask for the original file.
- Not Read. iPhones save photos as HEIC by default, and our checker does not read HEIC files yet. It says so rather than implying it looked. Ask whether they can send it as a JPEG.
None of these is “fake.” That is deliberate, and it is explained below.
Ask for the original, and ask everyone the same way
The most useful change is one sentence in your deposit-dispute correspondence:
If you have photographs of the unit’s condition, please send the original files from your phone as email attachments, not screenshots and not through a text or messaging app.
Two things make this fair rather than adversarial. First, it is a request anyone can meet in two minutes: if they took the photo, the original is still on their phone. Second, you hold your own photos to the same standard. Your move-in inspection pictures carry a camera clock too, and if they were kept as original files they will show it. We wrote about protecting that side of the record in Move-out damage photos: what you can actually prove.
When both sides’ files are originals, the argument stops being about who is more believable. It becomes two sets of dated records, and those can be compared.
Putting it on the record
If the dispute is heading to small claims or a mediator, file the tenant’s photos and your own in a single report. Each file is listed with its verdict and its SHA-256, a fingerprint of its exact bytes, on a dated page at a fixed address. Anyone holding the same file can recompute the fingerprint and confirm it is the one the report describes. That settles which file everyone is talking about. It does not settle whether the photograph is truthful, and we do not claim it does.
What this does not do
It does not tell you a photo is AI, and it does not tell you a photo is real. “Can’t Verify” is not a finding against anyone. Tenants send stripped files constantly and innocently.
It does not give you a confidence score. We tried twice to build a classifier that judges a picture by its pixels. The second attempt looked at eighteen ordinary photographs and called seventeen of them fake. It is switched off. A number that gets an honest tenant called a liar is worse than no number at all.
A camera clock can be wrong, and EXIF can be edited. Phones get reset, people cross time zones, and someone who knows how can rewrite the date. The clock reading is a specific claim that can be checked against other facts. It is not a signature.
It cannot tell you when the crack happened. It can tell you what a phone’s clock said when a photograph of the crack was taken. The gap between those two things is where your judgement still lives.
If a tool you are evaluating promises more than this, ask it what it does with a screenshot. The honest answer is that nothing can be read from one. Anything else is a guess dressed up as a finding.
ImposterShield reads the evidence inside image files. It runs in your browser and uploads nothing. If a file has been stripped, it says so. That is the product working, not failing.
Check a tenant’s photo right now
Take the last photo a tenant sent you and drop it on the page. If it comes back “Can’t Verify”, that tells you how your dispute evidence is arriving. Free, and nothing is uploaded.
Open the checker