Text under black boxes
Detects extractable text sitting underneath a dark rectangle or highlight — the classic "black box over live text" failure.
PDF Redaction Checker
Drop in a PDF and find out whether its redactions are real — content removed — or fake: a black box drawn over text you can still copy. The check runs entirely in your browser, so your file is not sent to RedactVault servers and is safe to use on confidential documents.
Drop a PDF here to check it
Or click to choose a file. Your PDF is analyzed in your browser and is not sent to RedactVault servers.
Choose a PDFWhat we check
Detects extractable text sitting underneath a dark rectangle or highlight — the classic "black box over live text" failure.
Finds dark annotations drawn over content, and redaction marks that were placed but never actually applied.
Flags author, title, and other Info-dictionary fields, plus embedded XMP metadata that can identify people and tools.
Detects incremental updates, where earlier revisions of a page — including content that was later redacted — remain recoverable.
Surfaces embedded files, attachments, and JavaScript that are unaffected by a visual redaction.
Reports optional-content layers that are switched off by default but still carry content inside the file.
How this checker works
The checker parses each page's content stream and looks for solid dark rectangles drawn over the page — the same geometric approach as the Free Law Project's open-source x-ray tool — as well as dark cover annotations and unapplied redaction annotations. It then loads the page's text layer and checks whether any readable text falls underneath those shapes. If it does, the redaction is only visual and the text can be recovered.
When text is found under a shape, the checker renders the page and samples the pixels where that text sits. If the area is uniformly dark, the text is genuinely covered (a real failure); if the text is actually visible, the finding is demoted to a warning so design elements are not mistaken for redactions.
Separately, it inspects the document's object graph for metadata (Info dictionary and XMP), embedded files and attachments, JavaScript, hidden optional-content layers, and incremental updates that leave earlier versions of a page recoverable.
Failed means recoverable text or an unapplied redaction was found. Needs review means no recoverable redacted text was confirmed, but some items need review — for example image-only pages (a scan, or a redacted export deliberately flattened to images) or leftover hidden data. Looks redacted means nothing recoverable was found. No redactions found means the document has no redaction-shaped marks. Cannot verify means the PDF is protected, or every page is an image (a scan or a fully flattened export) with no readable text layer — we never mark those as safe.
This is a best-effort structural check, not a guarantee. It does not read image-only pages without OCR (whether scanned or deliberately flattened by a redaction tool), cannot inspect encrypted documents, treats covers that are not rectangular or use pattern fills conservatively, and scans up to the first 300 pages of very large files. Always review a document yourself before releasing it.
Why this matters
Thousands of pages were released with black boxes over live text. Readers copied the hidden names within hours.
Court filings drew boxes over competitor data. Journalists copy-pasted the "redacted" figures straight out.
Improper redactions in federal filings have repeatedly exposed the exact details they were meant to hide.
Frequently asked
A real redaction removes the underlying content, not just covers it. This checker looks for text that is still extractable underneath dark boxes or annotations, plus other places data can hide — document metadata, embedded XMP, prior saved versions, attachments, and hidden layers. If it finds recoverable text under a black box, the redaction was only visual and can be undone.
No. The checker runs entirely in your browser. Your PDF is analyzed on your device and is not sent to RedactVault servers, which makes it safe to use on confidential or privileged documents.
A fake redaction is a black rectangle or highlight drawn on top of text without removing the text itself. The page looks redacted, but anyone can select and copy the text underneath, or extract it with software. This is the single most common redaction failure.
Scanned or image-only PDFs have no text layer to read, so this tool reports "cannot verify" rather than guessing. It never marks a scanned document as safe just because it cannot see the text. For those files you need OCR-based checking or a tool that flattens the image.
Extractable text under dark boxes and cover annotations, unapplied redaction annotations, document metadata, XMP metadata, incremental updates (recoverable earlier versions), embedded files and attachments, JavaScript, hidden optional-content layers, and invisible text layers.
If the redaction was only a visual overlay, yes — the original text usually remains in the file and can be copied or extracted. Real redaction removes the content from the document so nothing is left to recover.
Yes. The PDF redaction checker is free to use with no signup. If you need to actually redact a document, RedactVault does that in your browser too.
Further reading
Practical reading on verifying redactions and recovering from a redaction failure.
A step-by-step way to confirm a redaction actually removed the content, not just covered it.
Why "redacted" text so often remains in the file, and what makes a redaction permanent.
Damage control after a redaction failure, and how to re-issue the document safely.
Found a problem?
If the checker found recoverable text or hidden data, RedactVault can remove it for real. Redaction runs on your device, and the export is verified so nothing is left behind.
Free to use
The checker is free and needs no account. Bookmark it and run any suspect PDF through before you send or publish it.
Get 24-hour Professional individual access for one urgent redaction job. Includes a 50-document cap with unlimited pages and excludes team and high-volume batch features.