You sign a lease, an NDA, or a contractor agreement by drawing your name on a PDF with a trackpad, and a reasonable doubt surfaces: does this actually count?
For most everyday agreements, yes. But the reasoning is more interesting than the answer, and there are specific situations where it does not hold — which are worth knowing before you rely on it.
This article explains how the relevant law is structured. It is not legal advice, and for anything consequential you should ask someone qualified in your jurisdiction.
Two different things share one name
Almost all the confusion comes from this, and it is rarely explained.
An electronic signature is a legal concept. It is any mark, sound, or process attached to a record and executed with the intent to sign. Drawing your name with a mouse is one. So is typing it into a box, clicking “I agree”, or replying “yes, approved” from your work email. The technology is irrelevant; the intent is the substance.
A digital signature is a cryptographic operation. It uses a private key and a certificate to compute a value over the document’s exact bytes. Anyone can verify with the corresponding public key that the document has not changed since signing, and that it was signed by the holder of that certificate.
Every digital signature is an electronic signature. Almost no electronic signature is a digital signature.
They answer different questions. An electronic signature asks did this person agree? A digital signature asks have these bytes changed, and can I prove who signed them? The first is about consent. The second is about integrity and attribution.
What the law says
The striking thing, once you read the actual statutes, is how consistent they are across your likely jurisdictions. Nearly all of them do the same thing: they refuse to invalidate something merely because it is electronic.
European Union. The eIDAS Regulation, (EU) No 910/2014, governs this across all member states. Article 25(1) is the key provision: an electronic signature “shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements for qualified electronic signatures.”
That last clause matters. Even the simplest electronic signature is admissible. eIDAS then defines three tiers:
| Tier | What it requires | Legal effect |
|---|---|---|
| Simple (SES) | A mark made with intent to sign | Cannot be rejected for being electronic |
| Advanced (AdES) | Uniquely linked to the signer, capable of identifying them, under their sole control, and detecting subsequent changes | Stronger evidential weight |
| Qualified (QES) | An AdES made with a qualified signature creation device and a qualified certificate | Article 25(2): legal effect equivalent to a handwritten signature, recognised in every member state |
Only the qualified tier gets automatic equivalence to a wet signature. The other two are admissible and generally effective — you may simply have more to prove if challenged.
United States. Two instruments work together. The federal ESIGN Act (15 U.S.C. §7001) provides that a signature may not be denied legal effect solely because it is electronic. The Uniform Electronic Transactions Act (UETA) does the same at state level and has been adopted by 49 states — New York operates its own equivalent statute instead.
The US approach is deliberately technology-neutral. It does not define tiers and does not require certificates. A typed name can satisfy it.
Elsewhere in the target markets, the pattern repeats: the UK’s Electronic Communications Act 2000 alongside its retained eIDAS framework; Japan’s Act on Electronic Signatures and Certification Business (Act No. 102 of 2000); Australia’s Electronic Transactions Act 1999; Canada’s PIPEDA Part 2 with the provincial UECA statutes; the UAE’s Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services; and Korea’s Digital Signature Act, whose 2020 amendment notably removed the long-standing requirement to use a state-issued certificate.
Where it stops applying
This is the part worth reading carefully, because the exclusions are specific and people get caught by them.
US federal law (15 U.S.C. §7003) carves out categories where the ESIGN Act simply does not apply:
- Wills, codicils, and testamentary trusts
- Family law — adoption, divorce, and related matters
- Most of the Uniform Commercial Code, other than sections 1-107 and 1-206 and Articles 2 and 2A
- Court orders, notices, and official court documents, including pleadings and briefs
- Notices of default, acceleration, repossession, foreclosure, or eviction under a credit agreement or a rental agreement for a primary residence
- Cancellation or termination of health or life insurance benefits
- Product recalls and notices of material failure affecting health or safety
- Documents accompanying the transport of hazardous materials
The EU takes a different route to a similar place: eIDAS governs the signature itself but leaves national law to decide what form a given transaction requires. Many member states still require notarisation or a written deed for real property transfers, certain guarantees, and testamentary documents.
The practical rule across both systems: routine commercial and employment agreements are fine; anything involving wills, property transfer, family law, or a court filing needs checking first.
What actually determines whether it holds up
Since the law rarely turns on the technology, what does a dispute turn on?
Intent. Did the person mean to sign? A drawn signature at the foot of a contract clearly does. A name typed in an email footer is more arguable.
Attribution. Can you show it was them? This is where most electronic signatures are actually weak — a drawn squiggle on its own proves very little. What strengthens it is the surrounding evidence: the email address it came from, an audit trail, an IP address, a timestamp, a confirming reply.
Integrity. Can you show the document has not changed since? A plain drawn mark cannot demonstrate this at all. A cryptographic digital signature is designed to.
Consent to transact electronically. Both ESIGN and UETA require the parties to have agreed to do business electronically. In consumer contexts ESIGN adds specific disclosure requirements.
Retention. You need to be able to produce the signed record later, in a form that accurately reflects what was agreed.
Notice that four of those five are about evidence, not cryptography. A drawn signature in an email thread with a clear acceptance is often more defensible in practice than a certificate nobody can explain.
The uncomfortable research finding
If you are relying on a cryptographic digital signature specifically because it proves the document has not changed, there is a limitation you should know about.
At NDSS in 2021, researchers presented Shadow Attacks: Hiding and Replacing Content in Signed PDFs. They showed that a document can be prepared so that what the signer approves and what a reader later sees are different — while the signature still validates. The technique exploits PDF’s layered structure, in which a later revision can change what is displayed without altering the signed bytes. This is the same incremental update mechanism that makes multi-party signing possible in the first place.
They tested 29 PDF viewers and found 16 vulnerable. Earlier work by the same research group had already found systemic weaknesses in how viewers validate signatures.
The honest reading is not “digital signatures are worthless” — they remain far stronger than a drawn mark, and the specific flaws were disclosed and largely fixed. It is that a green validation tick is a claim made by your viewer software, not a mathematical certainty about what you are looking at. For a high-value agreement, that argues for keeping your own copy of what you signed rather than relying solely on the file the other party holds.
What Lemmafour’s tool does, and does not do
Plainly: Sign PDF creates an electronic signature. You draw or type your signature and place it on the page. It is a visual mark, exactly like signing a printed page and scanning it, and it carries the same legal footing — which, per everything above, is sufficient for the large majority of everyday agreements.
It is not a cryptographic digital signature. There is no certificate, no private key, and no tamper-evidence. It does not produce an Advanced or Qualified electronic signature under eIDAS.
So use it for NDAs, contractor agreements, consent forms, school and medical paperwork, rental applications, and ordinary commercial contracts. For anything that specifically demands a qualified electronic signature — some public-sector filings in the EU, certain regulated financial documents — you need a qualified trust service provider, and no browser tool can substitute for one.
We would rather state that boundary than let the word “sign” imply more than it delivers.
The part we do handle well is where the document goes. Signing happens in your browser: the contract is not uploaded to a server to have your signature added. Since the documents people sign are disproportionately the ones containing salary figures, addresses, medical details, and commercial terms, that is not a small distinction.
Practical guidance
Sign the whole document, not a page. If the agreement is six pages, keep them as one file. A detached signature page is trivially attached to a different document.
Keep the surrounding evidence. The email thread, the timestamps, the confirming reply. This is what attribution rests on, far more than the mark itself.
Both parties should retain a copy immediately after signature, before anything else happens to the file.
Check the exclusion list before signing anything involving a will, a property transfer, a divorce, or a court filing.
Do not rely on a permissions password to protect a signed document. As covered in does password-protecting a PDF actually protect it, those restrictions are advisory and any reader may ignore them.
If the transaction is high-value and cross-border in the EU, ask whether a qualified electronic signature is required, because that is the only tier with automatic handwritten equivalence across member states.
Sources and further reading
- Regulation (EU) No 910/2014 (eIDAS) — the consolidated text on EUR-Lex; Article 25 governs legal effect, and Articles 3 and 26 define the advanced and qualified tiers.
- 15 U.S.C. §7003, Specific exceptions — the US federal exclusion list, from the Office of the Law Revision Counsel.
- NTIA, Electronic Signatures: A Review of the Exceptions to the Electronic Signatures in Global and National Commerce Act — the US government’s own review of how those exceptions operate.
- Mainka, C., Mladenov, V., Rohlmann, S. et al., Shadow Attacks: Hiding and Replacing Content in Signed PDFs, NDSS 2021 — 16 of 29 viewers accepted altered content under a valid signature.
- Müller, J., Ising, F., Mladenov, V. et al., Practical Decryption exFiltration: Breaking PDF Encryption, ACM CCS 2019 — related work on the gap between PDF’s security guarantees and their implementation.
- ISO 32000-2:2017, the PDF 2.0 specification — defines signature dictionaries, the signed byte range, and incremental updates.