Evidence Basics · 9 min read

Can Text Messages Be Faked? How to Tell

Fabricating a convincing text message screenshot takes about a minute. Why visual tells are a weak defence, and what actually separates a real thread from a manufactured one.

The short answer

Yes, easily. A convincing fake text message screenshot can be produced in about a minute using a free generator site, a photo editor, or a browser developer console, and none of those methods leaves a mark that a person can reliably see. Sender numbers can also be spoofed outright, so a message can genuinely arrive on a phone appearing to come from a number that never sent it. This matters because the popular advice — look for uneven spacing, odd fonts, wrong bubble colours — describes what an incompetent forgery looks like, not what a competent one looks like, and those same irregularities show up constantly in perfectly genuine screenshots taken on older devices or unusual display settings. Visual inspection produces false confidence in both directions. What actually distinguishes a real thread from a manufactured one is not how the image looks but whether it can be corroborated: against the underlying record on a device, against the other party’s copy, or against carrier metadata showing the exchange occurred. That is why authentication under the rules of evidence has never turned on examining the picture. It turns on what supports the claim that the messages are what the proponent says they are, and an image with nothing behind it supplies very little of that.

How are fake text messages made?

There are three broad routes, and they differ in what they leave behind. The simplest is a fake-message generator: websites and apps that render a convincing conversation from typed text, reproducing a specific phone model and operating system version faithfully because that is precisely what they were built to do. The second is editing a real screenshot in an image editor, which is more fiddly but starts from genuine material and so inherits its rendering quirks. The third is manipulating a live page or app view before capture, which produces a screenshot that is authentic in every technical respect while showing content that was never received. Separately from fabrication, sender identity itself can be spoofed. Services exist that will deliver a message displaying an arbitrary sender number, which means a genuine, unedited screenshot taken on an untampered phone can still show a message that the apparent sender never wrote. No amount of inspecting the image resolves that, because the image is accurate.

Why do visual tells not settle it?

Because the checklist people circulate cuts in both directions. Misaligned bubbles, inconsistent fonts, a timestamp in the wrong format, or a battery icon that does not match the claimed date are offered as signs of forgery. Every one of them also occurs naturally: display scaling and accessibility settings change spacing and type size, operating system updates change timestamp formatting mid-thread, and a screenshot cropped and re-saved by a messaging app loses detail that then reads as tampering. The reverse error is worse. A generator-produced fake exhibits none of these irregularities, because it was written to reproduce the interface exactly. So the images that pass visual inspection most cleanly include both genuine screenshots and the best fakes, while the images that fail it include both crude fakes and a great many honest ones. A test that misclassifies in both directions is not a test worth relying on, and presenting one as though it were invites a straightforward challenge. There are circumstances where technical examination is meaningful — a qualified examiner working with the original file rather than a re-shared copy can sometimes say useful things about compression history and editing artifacts. That is expert work performed on a preserved original, which is a different activity from looking closely at a picture someone forwarded.

How do you prove a text message is real?

By corroboration, which is also how the rules of evidence approach it. Federal Rule of Evidence 901 asks for evidence sufficient to support a finding that the item is what its proponent claims, and it expressly contemplates using distinctive characteristics and surrounding circumstances rather than any single technical proof. In practice that means assembling several independent supports. The underlying record on the device, exported rather than photographed, carries fields a screenshot does not. The other party’s copy of the same conversation, produced in discovery, is powerful because two independently held copies matching is very hard to arrange after the fact. Carrier metadata can confirm that messages passed between those numbers at those times, without revealing content. And the messages themselves often contain distinctive detail — references to events, knowledge only the sender had, replies that only make sense as part of that exchange — which is the sort of thing Rule 901 was written to accommodate. Export the thread from the device rather than screenshotting it, and preserve that export unmodified with a recorded checksum. Request the other party’s copy of the same conversation, since two independently held matching copies are hard to fabricate. Use carrier records to corroborate that contact occurred at the claimed times, remembering that they will not show content. Identify distinctive content within the thread that only the sender plausibly knew. Keep the original image files with their metadata where screenshots are all that exists — never re-shared copies.

What if you suspect the other side’s messages are fabricated?

Ask for the source rather than arguing about the image. A party who has genuine messages can normally produce the export, the device, or an account record; a party who does not will often resist that request in ways a court finds informative. Discovery obligations, and the consequences of failing to preserve or produce, do more work here than any analysis of a screenshot will. Look for internal inconsistency too, which is harder to fake than appearance. Fabricated threads frequently conflict with things that are independently documented — a message sent from a phone that records show was off, a reply arriving impossibly fast, a reference to something that had not yet happened, or a gap where carrier metadata shows traffic the produced thread does not contain. Raise the concern through counsel rather than accusing anyone directly, since an unfounded allegation of forgery is costly and the remedy usually lies in a production request rather than an argument.

Can text messages be faked?

Yes, and easily. A convincing fake screenshot can be produced in about a minute with a free generator site, a photo editor, or a browser developer console, and sender numbers can be spoofed so that a message genuinely arrives displaying a number that never sent it. None of these leaves a mark a person can reliably see, which is why a screenshot on its own is weak evidence regardless of how authentic it looks.

How can you tell if a text message screenshot is fake?

Not reliably by looking at it. The usual visual tells — uneven spacing, inconsistent fonts, odd timestamp formats — appear in genuine screenshots taken on older devices or with accessibility settings enabled, and do not appear in fakes made by generators built to reproduce the interface exactly. The test misclassifies in both directions. Real confidence comes from comparing the screenshot against a device export, the other party’s copy, or carrier records.

Are screenshots admissible if they could have been edited?

Usually yes, because the possibility of editing goes to weight rather than admissibility. Authentication under Rule 901 requires evidence sufficient to support a finding that the item is what it is claimed to be, not proof beyond doubt that it was never altered. A screenshot supported by a preserved original, testimony, and corroborating detail is commonly admitted; one offered with nothing behind it is much easier to exclude or discount.

Can someone fake the sender number on a text message?

Yes. Spoofing services can deliver a message that displays an arbitrary sender number, so a genuine unedited screenshot taken on an untampered phone can still show a message the apparent sender never wrote. Inspecting the image cannot detect this, because the image is accurate — the deception happened before capture. Carrier records for the claimed sending number are one of the few ways to test it.

What should I do if I think the other party fabricated messages?

Ask for the source through counsel rather than arguing about the picture. Someone with genuine messages can normally produce the export, device, or account record, and resistance to that request tends to be informative. Look also for conflicts with independently documented facts — timing that carrier records contradict, or references to events that had not happened. An unfounded forgery allegation is costly, so route it through a production request.

Does Textimony detect edited or fabricated messages?

No. Textimony records a checksum at intake, which shows whether a file changed after it was received, and it keeps every message linked to its source so a reader can trace what was relied on. It cannot determine whether the export was truthful before it arrived. Detecting fabrication requires comparison against an independent source or forensic examination of an original, both of which happen outside review software.

Published by

Textimony. Editorial status: Source-linked informational guide. Updated: 2026-07-27.

Sources

Federal Rule of Evidence 901: Authenticating or Identifying Evidence; Federal Rule of Evidence 1003: Admissibility of Duplicates; NIST IR 8387: Digital Evidence Preservation Guidelines