PDF Security Blog

How to Spot a Fake ADP Pay Stub

HTPBE Team··11 min read
How to Spot a Fake ADP Pay Stub

This article is a snapshot – content was accurate as of September 2026 (code examples tested against the API as of August 2026). The product evolves actively; specific counts, examples, and detection rules may have changed since publication – see the changelog for the current state.

A pay stub with ADP across the top is harder to review than an unbranded one, not easier. A stub from a small employer’s in-house payroll gives you nothing to anchor on, so you treat it with appropriate suspicion. A stub carrying the layout of a large payroll platform arrives pre-anchored: it looks like something a real system produced, and it usually is — because the fastest route to a convincing fake ADP pay stub is to start from a real one.

The general visual checklist — the math, the fonts, the deductions, the alignment — already has a home in how to spot a fake pay stub, and it applies here unchanged. Run it. It just cannot tell you anything about how this particular file reached your inbox, and with a document from a hosted payroll platform, the delivery path is where most of the usable information sits.

Why “It Says ADP” Answers Almost Nothing

The employer block, the earnings and deductions grid, the footer text, the general shape of the page — that is the visible layer, and all of it is inherited when a forger works from a genuine document. Nobody rebuilds an ADP-style layout from scratch when they can download the real thing and retype one number in it, in ordinary consumer software. The parts a reviewer is trained to recognize are precisely the parts a careful edit never touches.

So the branding is not evidence. It tells you which system the document claims to have come from. That claim is useful — it gives you an expectation to test — but it is the start of the question, not the answer.

None of this is a criticism of ADP, and it is not a claim that anything on ADP’s side went wrong. It is a description of where custody ends. A payroll provider controls the document while it is inside the portal. The moment an employee clicks download, the file is on a personal device, and no payroll platform — ADP or any other — has any further reach over it. Everything a reviewer worries about happens in that gap.

The Delivery Path Is the Part Worth Interrogating

So ask the question that separates cases: how did this file get from the payroll portal to you? A pay stub starts life as an institutional document, but employees and employers have several legitimate ways to get one to you. Knowing which route the document took tells you more than knowing what the page looks like.

Direct download from the portal. The employee signs in to ADP’s employee self-service, opens the statement, and saves the file the platform serves them. Shortest path: one system produced the document, and it reached you with nothing in between. If the applicant says they pulled it from MyADP last Tuesday, this is the route they are describing.

An image-format statement. ADP’s own documentation notes that the format depends on how the employee’s company is configured, and that, where the statement is served as an image, saving it means right-clicking and choosing “Save Picture As” rather than saving a PDF (ADP portal help, accessed August 2026). An employee on that configuration who needs to send you a PDF has to wrap the image in one, using whatever tool is at hand. The result is a genuine statement inside a file the payroll platform never produced. An applicant on that configuration may genuinely not have a portal-generated PDF to give you — a reason to ask, not a reason to assume.

Employer-forwarded. HR pulls the statement on the employee’s behalf and emails it. A normal path, and one more step between the payroll system and you.

Printed and scanned. The employee prints the statement and scans or photographs it, often because that is what a form asked for. What you receive is an image of a page rather than the file the payroll system produced. Printing is not suspicious in itself; it does mean you are reviewing a derivative, so if the original matters, ask for it.

Phone screenshot. The employee opens the statement in the ADP mobile app, screenshots it, and shares the picture, sometimes converted to PDF by the phone itself. Same consequence as the scan: what reaches you is a picture of the statement, not the export.

These are not equivalent. A direct download and an employer forward can both put the original file in your hands — the forward just adds a custodian between the payroll system and you, which is a chain-of-custody question rather than a different document. The other three routes produce something else: an image wrap, a scan or a screenshot all hand you a picture of the statement, not the file the payroll platform produced. All five are normal behavior, and none of them is an accusation. They are simply not the same object, and it is worth knowing which one is in front of you.

Which is a reason to ask one question you probably are not asking today: how did you get this file? If the answer and the document disagree, that gap is the thing to follow up on. And if the direct export cannot be produced on request, keep the request open rather than drawing a conclusion from it.

What a Structural Check Adds

A PDF is not a picture of a page. It is a structured file that records how it was assembled and, when it is opened and saved again, what happened to it afterwards. That record is separate from the layout, which is why retyping a figure convincingly does not touch it. It is the one part of the document a forger working from a genuine original does not inherit cleanly.

HTPBE? reads that structure and returns one of three verdicts, along with a list of named modification markers describing what it found. For a stub claimed to be an ADP export, they mean roughly this:

  • modified — the file carries structural evidence that it was changed after it was first generated. This is the case the visual checklist is blind to: the page can look entirely normal while the file itself records that it was written to again. It is not a finding about a person, and it is not proof of intent — a benign step in the delivery chain can produce it too. It is a reason to ask for the document again, from its source.
  • inconclusive — the file does not give enough of a basis to assess integrity either way. Treat it as “not answered,” not as “answered no.” The next step is the same one a missing answer always calls for: ask for the document again from its source, rather than reading anything further into the result.
  • intact — no structural evidence that the file was changed after it was created. This is the absence of evidence of alteration. It is not a statement that the employment is real or that the figures are true.

One boundary worth being precise about, because it is the difference between a useful tool and an overclaim: HTPBE? does not hold a reference copy of what an ADP pay statement is supposed to look like, and it does not check the document against ADP’s records. It has no relationship with ADP and no access to any payroll system. It answers a narrower question — whether this file shows signs of having been changed after whatever system produced it — and that question is answerable without knowing anything about the employer, the employee or the payroll provider.

The Verification Route ADP Actually Provides

Structural analysis tells you about the file. It cannot tell you whether the person works there or earns that amount, and no amount of PDF forensics will. For that there is a purpose-built route, documented for ADP-run payroll: ADP offers an employment and income verification service that answers verification requests from payroll-linked data, on the employer’s behalf, through a secure portal (ADP SmartCompliance Employment Verification, accessed August 2026).

The conditions attached to that route are the point, not an obstacle. ADP describes the service as supporting applicable US Fair Credit Reporting Act requirements by releasing reports only to credentialed verifiers who certify a permissible purpose, with income verifications additionally requiring certification that the employee consented to the release. Whether you have a permissible purpose, and what consent you need, are your own determination under the rules that apply to you — not something a PDF check can answer. Where those conditions are met, that route answers the income question directly, which no inference drawn from a file can.

The two checks answer different questions and sit in different places. The structural check runs on arrival, in seconds, on every document, and costs nothing in applicant friction. The verification request is slower, involves credentialing, and is what you escalate to. Using the first to decide when to spend the second is a reasonable way to run a queue.

What This Does Not Solve

Two limits, because a review that misunderstands them is worse than one that skips the check entirely.

A structurally unremarkable file can still be false. If a stub was generated inside any payroll system with figures that were wrong before the PDF existed — a complicit employer, an employee with the access to run payroll — the file is clean because the fraud happened upstream of it. Structural analysis has nothing to say there. The control for that case is verification against the employer or the payroll provider, not forensics.

And the absence of structural evidence is not the presence of proof. intact means the file does not show signs of post-creation modification. It does not mean the employment exists, the salary is accurate, or the document is what it claims to be. Treat it as one input into a review, never as a clearance.

The caution runs the other direction too. A modified verdict is a routing signal for a human, not a decision. It says the file was written to after it was created; it does not say who did it or why, and there are ordinary reasons a file gets rewritten in transit. Wiring any structural verdict directly to an adverse decision about an applicant is a misuse of it.

Putting It Into a Review Queue

For a single document, the sequence is: run the visual checks, ask how the file was obtained, and check the file itself if the answer and the document disagree — or if the decision is large enough that “looks right” is not a good enough bar. Registering on this site gives you five checks to try that on real documents, with pay-per-check after that.

At volume the order inverts, because the structural check is the one that scales. It is a single integration: submit the document as it arrives, then read back the verdict and its named modification markers as structured data.

curl -X POST https://api.htpbe.tech/v1/analyze \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://your-storage.example.com/paystubs/applicant-4417.pdf"}'

The routing is the part to design deliberately. modified goes to a human, along with a request for a fresh copy pulled directly from the portal — which, for a hosted payroll platform, is usually a request the applicant can satisfy in a couple of minutes. inconclusive goes to a human too: an unanswered question is not a pass, and the same request for the document from its source is the cheapest way to resolve it. intact continues into the content review, which is where the visual checklist earns its place. Endpoints, the response shape and test keys for building against deterministic sample scenarios before spending a credit are in the API reference.

The Short Version

Looking harder at the page will not spot a fake ADP pay stub, because the page is usually genuine and only one field is not. What you have is a claim — this came from a payroll portal on a specific date — and two independent ways to test it. Ask how the file was obtained, then check whether the file’s own construction is consistent with the answer. When the income itself is the question, go to the verification service built for it. The PDF check is fast and runs on everything; the verification request goes to the source and runs on what the PDF check flags.

For adjacent document types and workflows, see how to spot a fake pay stub for the general visual checklist, altered paystubs and W-2s for mortgage underwriting, payslip fraud in HR for hiring and background verification, and the fake pay stub detection use case for the product view.

ADP, MyADP and ADP SmartCompliance are trademarks of ADP, Inc. and are used here only nominatively, to describe a widely used payroll platform and the documents and services it produces. HTPBE? is not affiliated with, endorsed by, sponsored by or connected to ADP in any way.

Share This Article

Found this article helpful? Share it with others to spread knowledge about PDF security and fraud detection.

https://htpbe.tech/blog/how-to-spot-fake-adp-pay-stub

Secure your workflow

Create your account – check PDFs on the web or with an API key, both ready on signup.
No sales call. Cancel any time.