Fake photos & AI images
How to Spot a Deepfake: Red Flags in Video, Voice and Calls
How to spot a deepfake: the red flags in fake videos and cloned voices, why detection apps miss so many, and the call-back habit that really protects you.

You can rarely spot a deepfake from the picture alone. Look for warning signs such as blurry edges around the face, lips that don't match the audio, or a flat, metallic-sounding voice. Context matters even more: if someone asks for money or personal information over a video call, phone call or voice message, hang up and call them back on a number you know is theirs.
Deepfakes are videos, images and audio faked with artificial intelligence, and criminals use them to pose as relatives, bosses, officials and celebrities. At TrustCamera we build a camera app that gives photos and videos a check code at the moment they are recorded. That work has shown us how little you can read from a finished file after the fact. Below are the warning signs authorities describe, where they fall short, and the checks that work even against a flawless fake.
How to spot a deepfake: the key steps at a glance
To spot a deepfake, combine two things: a close look for typical flaws in the picture and sound, and a check through a second channel. Those flaws are getting harder to find with every new generation of tools. Calling back on a known number, asking a personal question or using a family code word works even when the fake itself is perfect.
- Pause: Pressure to pay quickly or to share sensitive information is the strongest red flag, however real the face and voice seem.
- Look and listen closely: Check the edges of the face, the teeth, eyes and lips, and listen for a flat or metallic voice.
- Verify through a second channel: Hang up and call the person on a number you know is theirs.
- Ask something only they would know: Or ask for the secret word your family agreed on.
- Check the source: For viral clips, find out who posted them first and whether trusted news outlets report the same thing.
Steps 3 and 4 matter most because they work no matter how good the fake is. If you're dealing with a single picture rather than a video or a call, our guide on how to tell if a photo is real walks you through seven checks.
What deepfakes are: face swaps, lip sync and voice clones
The term covers several AI techniques that fake faces and voices or generate them from scratch. Germany's Federal Office for Information Security (BSI) describes them in detail. For everyday purposes, four types are worth knowing:
- Face swap: One person's face is placed onto someone else in a video, keeping the original expressions and gaze. According to the BSI, only a few minutes of video of the target are needed, and some models work in real time.
- Face reenactment (lip sync): The head movements, expressions or lip movements of a real person are manipulated, so they appear to say things they never said.
- Synthetic faces: AI creates people who don't exist. The BSI notes that common methods are still mostly limited to single images.
- Voice clones: Text-to-speech reads any text in a target's voice, while voice conversion turns a spoken recording into that voice.
For a high-quality voice fake, the BSI says several hours of training audio are needed. With recordings of other speakers as helper data, that can drop to a few minutes, and researchers are working on methods that need only seconds. The agency expects the amount of material required to keep shrinking.
Synthetic faces mostly show up as profile pictures. Our guide on how to tell if an image is AI-generated covers those still images. And not every fake needs AI at all: often a real video is shared out of context, or a photo is edited the old-fashioned way. Here's how to tell if a photo is photoshopped.
How to tell a deepfake video: signs in the face and movement
Many deepfake techniques leave visible flaws, known as artifacts. The BSI describes the typical ones for face swaps, and an FBI public service announcement adds its own list for AI-generated images and videos. If you can, pause the video, zoom in and check these areas:
- Edges of the face: Where the swapped face meets the head, skin tone or texture can change. In some frames, parts of the original face flicker through, such as a second set of eyebrows.
- Teeth and eyes: Sharp details look smeared or unrealistic on closer inspection.
- Head turns: Many models learn the side view poorly, so a quick turn of the head can blur the face.
- Light and shadows: Lighting on the face doesn't match the scene, or shadows fall in the wrong direction.
- Hands and accessories: The FBI mentions distorted hands or feet and unrealistic glasses or jewelry.
- Sync and movement: Look for lag, a voice that doesn't match the lips, and unnatural movements.
Live video calls give you a small advantage. The BSI points out that in real time, an attacker can't clean up flawed footage after the fact. Pay extra attention when the other person moves a lot or turns their head to the side.
The catch: these flaws get rarer with every new generation of models, and the BSI expects spotting fakes by eye to keep getting harder. If you find no artifacts, that doesn't make a video real. Clips on social media are also often compressed so heavily that fine details blur anyway.
It's usually easier to spot a deepfake video by its context: who posted it first, and are trusted outlets reporting it? You can also take a screenshot of a key frame and run a reverse image search to find older versions or the original.
Deepfake audio: how to recognize a cloned voice on the phone
Cloned voices are especially convenient for scammers because a phone call shows no visual glitches. That makes it harder to spot a deepfake on the phone, but the BSI still lists several typical weaknesses of synthetic voices:
- Metallic sound: The voice sounds tinny or artificial.
- Monotone delivery: Sentences sound flat, without natural rises and falls.
- Wrong pronunciation: Some words are mispronounced, or the accent and emphasis don't match the real person.
- Odd noises: Pauses or very long sentences can produce unnatural sounds.
- Delay: High-quality fakes often answer with a slight lag.
According to the Federal Trade Commission, a scammer needs only a short audio clip, perhaps from content posted online, and a voice-cloning program to sound just like your family member. Its advice is blunt: don't trust the voice on the line, even if it sounds exactly like someone you love. The FBI suggests listening closely to tone and word choice.
Don't rely on the sound alone, though. A bad cell connection can sound tinny too, and good clones sound natural. The pattern behind the call tells you more: a familiar voice, a sudden emergency, pressure to act now and a request to keep it secret. On top of that, scammers push for payment methods that are hard to reverse, such as wire transfers, cryptocurrency, payment apps or gift cards, the FTC warns.

Can apps detect a deepfake? Why tools often get it wrong
There are apps and websites that promise to detect a deepfake in a video or audio file. What they give you is a probability, not proof. From the outside, you can hardly judge how reliable a particular tool is.
The BSI points to a competition that shows how hard automatic detection is. In the 2020 Deepfake Detection Challenge, even the best model reached an average accuracy of only 65.18 percent, while pure guessing would have scored 50 percent. The agency calls the core problem poor generalization: a detector mostly recognizes fakes that resemble its training data.
Fakers can also work against detectors on purpose. According to the BSI, attackers can add a layer of noise to a manipulated image that people won't notice but that fools the detection model. The Content Authenticity Initiative describes detection tools as being in a constant arms race with bad actors, which is why they need regular updates.
Treat any detection app as a second opinion at most. A "likely fake" result is a good reason to call the person back. A "likely real" result doesn't clear anything. Online quizzes that test whether you can spot a deepfake are still worth a few minutes, because the BSI says knowing the typical artifacts can significantly improve detection. They just won't replace a call-back when it counts.
The best defense: verify the person through a second channel
Because it keeps getting harder to spot a deepfake by eye, the most reliable checks don't depend on the fake at all. The FTC and the FBI recommend these steps:
- Hang up and call back: Tell the person you'll call right back, then use a phone number you know is right. If the call claims to come from a bank or agency, look up its number yourself.
- Ask a question only the real person could answer: The FTC suggests something like "Where did you spend Thanksgiving last year?"
- Agree on a secret word: The FBI recommends creating a secret word or phrase with your family to verify their identity.
- Loop in someone else: Call another family member or friend, even if the caller said to keep it a secret.
In our view, the family secret word offers the best return for the least effort. It takes one conversation and works against even a perfect fake. Agree on it in person rather than in a group chat, and talk through when you'd ask for it.
The FBI also suggests limiting how much of your image and voice you post publicly, making social media accounts private and keeping followers to people you know. That gives scammers less material to clone.
Worried about seeming rude? Real family members and bosses will understand a quick call-back. Scammers, on the other hand, work hard to prevent one. According to the FTC, they insist it's urgent, that you're the only one who can help and that you shouldn't tell anyone.
Common deepfake scams: celebrity ads, fake executives, family emergencies
Deepfakes rarely appear on their own. They usually make an existing scam more convincing by adding a real face or a real voice, so knowing these scams helps you spot a deepfake before it costs you. The FBI alert on generative AI fraud describes these patterns:
Celebrity and influencer promos: Criminals create believable videos of public figures and misleading promotional material for investment schemes. AI-generated images of celebrities also promote counterfeit products or goods that never arrive. If a famous face promises high returns with no risk, treat it as a scam until proven otherwise.
Fake executives and officials on video: Scammers generate videos for real-time video chats with supposed company executives, law enforcement officers or other authority figures.
Family emergencies: Criminals create short audio clips in a loved one's voice, claiming a crisis and asking for immediate money or demanding a ransom. This is the classic grandparent scam, now with a cloned voice.
Romance and "prove you're real" videos: In online relationships, scammers send AI-generated photos and videos to convince you they are a real person. If a new contact gets very personal very fast and money comes up, step back. Our guide to romance scams shows how these schemes unfold and what to do if you already paid.
Content Credentials: the long-term answer to deepfakes
All the methods so far judge a finished recording after the fact. The BSI therefore names a different approach: cryptographic methods that tie a recording to its source, so later manipulation is noticed immediately, for example through a digital signature created during recording. As the agency notes, a signature can't stop the source itself from manipulating the material beforehand.
The best-known open standard for this is C2PA. It attaches so-called Content Credentials to a file: signed information about when a recording was made and which device or software created and edited it. The Content Authenticity Initiative explains that this makes later changes visible. It also says clearly that Content Credentials aren't meant to decide whether a piece of content is "real."
We're pursuing the same goal with TrustCamera. Photos and videos are captured directly in the app, and uploads from the gallery aren't possible. Videos can be up to 20 seconds long, with an invisible code embedded at the start. Every capture gets a check code, and anyone who has it can check authenticity, capture time and approximate location for free in their browser, without an account. The app for Android and iOS is coming soon.
It's important to be clear about what such proof shows. It shows that a file hasn't changed since it was recorded. It can't tell you whether the filmed scene was staged, and it won't help you during a live video call. For a video without proof of origin, you still have to spot a deepfake the old way: with the warning signs and, above all, a call-back.
What to do if a deepfake scam targets you
If you've already paid or shared information, act fast. The FTC's guide on what to do if you were scammed and the FBI alert point to these steps:
- Contact the payment company immediately: Report it to your bank, payment app, wire transfer company or gift card issuer and ask them to reverse the payment.
- Stop paying and cut contact: Don't send more money, whatever the reason given.
- Save the evidence: Note names, phone numbers and email addresses, plus the date, amount and method of every payment and how the contact started.
- Report it: File a report at ReportFraud.ftc.gov and with your state attorney general. For financial fraud, the FBI asks for a report at ic3.gov.
If someone shares an intimate deepfake of you, a newer federal law helps. Under the TAKE IT DOWN Act, covered platforms must offer a way to request removal and take the images down within 48 hours, including AI-generated deepfakes, as the FTC explains. If a platform doesn't comply, you can report it at TakeItDown.ftc.gov. The FTC also advises reporting the person who shared the image to local law enforcement and the FBI.
Frequently asked questions about how to spot a deepfake
Can you always detect a deepfake?
No. Many fakes still show flaws around the face, teeth, lips or voice, especially in live calls. But the BSI expects spotting fakes by eye to get harder, and detection tools are unreliable. A second-channel check works better than any warning sign: hang up, call back on a known number or ask a personal question.
Is there an app that can reliably detect deepfakes?
No. Detection apps give you a probability that depends heavily on their training data. They often miss fakes made with newer methods, and fakers can deliberately trick them. Use a tool as a second opinion at most. A "likely real" result doesn't mean you can relax.
How do you spot a deepfake voice on the phone?
Typical signs are a metallic, tinny sound, flat emphasis, mispronounced words and slight delays in answering. Good voice clones show few of these, though. Focus on the pattern instead: a familiar voice, a sudden emergency, pressure to pay and a request for secrecy. Then hang up and call the person back on a number you know.
How does a family secret word protect you?
You agree on a word or phrase that only your family knows and that never appears online. If someone calls with an emergency, you ask for it. An AI can clone a voice, but it can't know your secret word. The FBI specifically recommends this step to verify a caller's identity.
Can deepfakes happen on a live video call?
Yes. According to the BSI, some face-swap methods work in real time, and the FBI warns of live video chats with fake executives and officials. Live fakes can't be cleaned up afterward, so flaws are more likely to show, for example when the person turns their head. If someone on a video call asks for money or data, end the call and call back on a known number.
How do you spot a deepfake photo?
For still images, look for distorted hands, unrealistic teeth, eyes or jewelry, and shadows that don't fit. Then run a reverse image search to see where the picture appeared before. Fully AI-generated pictures are a slightly different problem, covered in our guide on spotting AI-generated images.
What should I do if someone made a deepfake of me?
Report it to the platform through its reporting tools and save the link, the date and screenshots where that's appropriate. For intimate images, the TAKE IT DOWN Act requires covered platforms to offer a removal process and act quickly on your request. You can also report the person who shared it to local law enforcement and the FBI.
Conclusion: context is the surest way to spot a deepfake
Checking for flaws in the picture and sound is still worth it. Many fakes show glitches around the face, teeth, lips or voice, especially live. You can't rely on those signs, and you can't rely on detection apps either. What works reliably has nothing to do with technology: pause, call back on a number you know, ask a personal question or ask for your family's secret word.
We believe the question will flip over time. Instead of trying to spot a deepfake after the fact, genuine recordings will carry proof of their origin from the start. Open standards like C2PA are working on that, and so are we with TrustCamera. Until it's the norm, a call-back remains your best protection.
About the author




