How to Detect a Deepfake Video: What Actually Works in 2026
Most published advice on spotting deepfakes is several generations out of date. Counting blinks, looking for blurred hairlines and checking whether the ears match were reasonable heuristics in 2019. They are not now. This is what still works, what does not, and why the honest answer is more often "inconclusive" than either side of the question.
Why visual inspection stopped working
The early advice worked because early face-swap pipelines had specific, repeatable weaknesses. Training corpora were built from web images of people with their eyes open, so generated faces under-blinked. Blending was crude, so hairlines and jawlines showed seams. Temporal consistency was an afterthought, so faces flickered.
Every one of those was a solved problem within about two years of being published. That is the nature of an adversarial field: naming a weakness publicly is also a specification for fixing it. Advice that tells an investigator to look for artefacts that current tooling no longer produces is worse than no advice, because it produces false confidence in a clean result.
The deeper issue is that visual inspection asks the wrong question. It asks whether the image looks wrong to a human. Modern synthesis is optimised precisely against that objective — human perceptual plausibility is the loss function. You are inspecting for the one property the system was trained to get right.
If a detection method can be described in a viral thread, assume it has already been engineered around.
What still carries signal
The methods that hold up share a property: they measure something the generator has to fabricate rather than something it copies. Four families are worth understanding.
- Physiological signals. A living face perfused by a beating heart shows periodic colour changes invisible to the eye but recoverable from pixel statistics. Crucially, those changes are spatially coherent — one heart drives the whole face, so independent facial regions must agree on rate and phase. Synthesis reconstructs appearance, not circulation.
- Provenance. Cryptographic content credentials and platform upload records authenticate the genuine article rather than attempting to detect every fake. This is the most durable layer available and the most under-used.
- Frequency-domain structure. Generation pipelines leave structural traces in the frequency domain from how they build images up. Real camera sensors leave a different and equally structural trace from how they capture them.
- Temporal coherence. Whether a face moves through a scene as one object or is reconstructed frame by frame is measurable independently of how convincing any single frame looks.
Why one detector is not enough
Every method above has conditions under which it fails, and those conditions are common. Physiological measurement degrades with subject motion, poor lighting and heavy compression. Frequency analysis degrades when a file has been re-encoded — which describes essentially everything that has passed through a messaging platform. Provenance is absent from most media in circulation.
A single detector gives you one number with no way to know whether it landed in the regime where that method works. Multiple independent families let you see whether they agree, and disagreement is information: it usually means the exhibit is degraded, unusual, or genuinely borderline.
There is a subtlety here that catches most systems. Related measurements must not be counted as independent corroboration. Six measurements that all fire on the same recompression are one piece of evidence, not six, and averaging them manufactures confidence the underlying physics does not support.
The trap: absence of evidence
This is the single most consequential error in the field, and it is almost universal in commercial tooling.
Most detectors can only evidence manipulation. A blending-boundary test that finds nothing has established that there is no composite — which is exactly what a wholly generated video looks like, because nothing was composited. Treating that silence as evidence of authenticity is how a fully synthetic exhibit gets scored "authentic" with high confidence.
The correct handling is asymmetric. Detectors of this kind may indicate manipulation loudly, but must never assert authenticity. A genuine finding of authenticity requires positive evidence of real capture: a recovered sensor signature, a coherent physiological signal, a valid provenance manifest.
"No manipulation detected" and "this is authentic" are different statements. Conflating them is the most common way a detection result misleads.
What to do with an inconclusive result
Inconclusive is a substantive finding, not a failure. It means the available evidence does not discriminate for this exhibit — usually because the file has been compressed and redistributed until the recoverable evidence is gone.
The productive response is to stop asking the file and start asking around it. Obtain a higher-quality original from the source device rather than a forwarded copy. Issue preservation requests to the hosting platform before the upload record expires. Pursue the account, the device and the circumstantial account of how the media came to exist.
These lines of enquiry do not depend on the detection result holding up under challenge, which is precisely why they are worth more.
A practical sequence
For an investigator handling a suspected deepfake, the order that works:
- Preserve first. Hash and seal the file before anything else touches it, and issue platform preservation requests immediately — that evidence expires fastest and does not depend on any technical finding.
- Establish what you actually have. Resolution, duration and compression severity determine how much evidence is recoverable at all, and therefore how confident any result can legitimately be.
- Check provenance before detection. A valid content credential or a platform upload record settles more than any classifier will.
- Run multiple independent methods and look at whether they agree, not just at the aggregate number.
- Have a qualified examiner adjudicate. An automated result is not an expert opinion, and it will not be treated as one.
Frequently asked
Can you tell if a video is a deepfake just by looking at it?
Not reliably, and increasingly not at all. Current synthesis is optimised directly against human perceptual plausibility, so visual inspection tests the one property these systems are trained to get right. The visual tells widely circulated online — blink rate, hairline artefacts, ear mismatches — were engineered around years ago.
What is the most reliable deepfake detection method?
There isn't a single most reliable method, and any vendor claiming one should be treated with suspicion. Provenance verification is the most durable layer where it exists, because it authenticates the genuine article rather than trying to detect every fake. Beyond that, the reliable approach is combining several independent families of evidence and treating their disagreement as information rather than averaging it away.
Does compression affect deepfake detection?
Substantially, and it is the single biggest practical problem. Re-encoding strips high-frequency content, suppresses sensor noise and attenuates the physiological signals detection depends on. Since most media in an investigation arrives after passing through several platforms, accuracy on real casework is materially lower than on benchmark corpora.
See how Exiphore handles this in practice
Deployed on your infrastructure. Bring an exhibit from a closed case and we will walk through what it finds, what it misses, and what it refuses to conclude.
Request a demoContinue reading
Why deepfake detectors fail
Detectors that score 99% on a benchmark routinely underperform on real casework. The four failure modes behind that gap, and how to test for them before you deploy.
Is deepfake evidence admissible in court?
A detection score is not evidence. What actually has to be established for a media authentication finding to survive challenge — custody, methodology, stated limitations and a named examiner.