Three ways a profile photo can be false
Only one of them is a detection problem, which is why starting with a detector so often produces a confident and useless answer.
- Stolen. A real photograph of a real person, taken from somewhere else. The most common by a wide margin, and completely invisible to a pixel check.
- Generated. A person who does not exist, produced from a prompt. This is the one a detector is built for.
- Enhanced. The account holder's own face, run through a portrait generator or a heavy filter. Extremely common now, and not deceptive.
The third category is where most false alarms come from. Services that turn a few selfies into studio portraits are cheap and widely advertised, and somebody using one has skipped a photographer rather than lied about who they are.
| Reverse search | Pixel check | Account history | |
|---|---|---|---|
| Stolen from a real person | Yes Finds the original | No Reads as genuine | Partly Thin history is a hint |
| Fully generated person | Partly No earlier copy exists | Yes This is the case it is built for | Partly Often a new account |
| Own face, enhanced | No | Partly May score high, harmlessly | Yes Consistent with the rest |
| Real photo, false claim | Yes Finds the true context | No Nothing synthetic to find | Yes Contradictions surface |
Start with reverse image search
It costs ten seconds and it settles the most likely case outright. Drag the picture into an image search and look for earlier copies: a stock library, a different name, a modelling portfolio, somebody's actual social account from four years ago.
A hit is close to conclusive. If the same face appears under a different name on a site that predates the profile you are looking at, the question is answered and no amount of pixel analysis was needed.
No hit is much weaker evidence. It is consistent with a generated image, and equally consistent with an ordinary photograph that was simply never posted anywhere a search engine crawled, which describes most photographs ever taken.
Reading the score on a portrait
Portraits sit awkwardly on the scale, because everything people do to a portrait before posting it pushes the number upward. Beauty filters, portrait mode, skin smoothing and platform recompression are all software rewriting pixels after capture.
A profile photo landing in the forties is therefore close to uninformative. The band that means something on a face is the high one, and even there the honest reading is that the picture was probably generated, not that the account is fraudulent.
- Camera original 0–20
- Phone, filtered 20–45
- Uploaded and recompressed 45–65
- Enhanced portrait 65–90
- Generated 90–100
The checks that catch what pixels cannot
-
Look at the account, not the photo
Creation date, posting history, whether other people have tagged them, whether the interests are consistent. A three-year history with mutual connections is evidence no generator produces.
-
Look for a second photograph
One perfect portrait and nothing else is the pattern. Real accounts accumulate awkward, badly lit, incidental pictures over time.
-
Check whether the face repeats
The same face across several photos, in different places and lighting, is hard to fake consistently and easy for a real person to have.
-
Ask for something specific
A photo holding a written note with today's date, or a short live video call. This defeats almost every version of the problem, including the stolen-photo case that no detector touches.
-
Weigh the ask
If money, credentials or urgency are involved, the photograph is the least important signal. Behaviour is the finding.
The fourth step deserves emphasis because it is the only one that scales to every category at once. A live video call with a specific request resolves stolen photos, generated photos and enhanced photos in one action, and it does not depend on any model being right.
What a scam profile usually looks like
Patterns repeat because they work. The photograph is the part people examine, and it is rarely the weakest link in a fabricated account. The weakest links are the things that take time to build rather than seconds to generate.
A thin history is the first. Accounts created recently, with few posts, few connections and no photographs taken by anyone else, describe something assembled rather than lived. Real accounts accumulate other people: tags, comments, appearances in someone else pictures.
Mismatched detail is the second. A stated employer with no corresponding record, a city that does not match the background of any photo, a name that appears nowhere else. None of these is conclusive alone and together they compound quickly.
Pace is the third, and the most reliable of all. Fabricated accounts move toward money, credentials or a different platform faster than a real relationship would. Where that pressure exists, the photograph stops being the interesting question.
When to stop investigating and act
There is a point past which more checking adds nothing. If the account is asking for money, for a login, or to move the conversation somewhere with no record, you already have your answer regardless of what any image analysis says.
Block and report at that point rather than gathering more evidence. The checks in this guide are for deciding whether to engage at all, and once a request of that kind has arrived, the decision has been made for you.