Inside the Fake-ID Detection Stack

Picture a mortgage closing happening entirely online: a signer holds a driver's license up to their laptop camera during a remote notarization session, and the platform has seconds to decide whether that ID and that face belong together.
Or picture a fraud ring opening a dozen bank accounts with stolen Social Security numbers stitched to fabricated names: classic synthetic identity fraud.
Both scenarios run through the same machinery, independent checks stacked so a fraudster who slips past one runs straight into the next. Let’s unpack the five layers of a fake-ID detection stack - and what you need to do to protect your transactions from fraud.
Key takeaways
- A fake-ID detection stack runs five layers: image capture and quality, document authentication, DMV cross-referencing, biometric and liveness matching, and behavioral or device risk scoring.
- Document authentication checks holograms, UV ink, microprint, and barcode data against AAMVA's design standards, catching counterfeits and screen-capture attempts.
- DMV cross-referencing, through AAMVA's Driver License Data Verification (DLDV) service, covers roughly 73% of the US population and catches fabricated or stolen data.
- Biometric and liveness matching catches the hardest case, a real ID used by someone who isn't its owner, right where TransUnion recorded a 37% year-over-year jump in account takeover fraud.
Layer 1: Capture and image quality
Before any authentication check runs, the system needs a usable image: detecting glare, blur, cropped edges, or a screen capture held up to the camera instead of the physical card. Platforms often prompt for multiple angles or a document tilt to catch light-reactive features a flat, static image can't reproduce. A fraudster submitting a screenshot rather than the physical card typically gets stopped here, before the more sophisticated checks engage.
Layer 2: Document authentication and forensic security features
Once the image is usable, the system examines the document against design standards published by the American Association of Motor Vehicle Administrators: holograms and optically variable ink that shift under light, microprint too fine for a home printer, UV-reactive elements invisible in normal light, and a PDF417 barcode encoding the cardholder's data in a regulated format.
Authentication software checks all of this at once: whether the hologram sits correctly for this state and card version, whether the barcode decodes to data matching the front, whether the font and template match known genuine samples. Replicating physical security features is a fundamentally different, and far more expensive, problem than replicating a visual design, which is why a counterfeit built from an online template can look convincing and still fail here.
Layer 3: Cross-referencing against issuing authorities
A document can be internally consistent, well-forged, and still not correspond to a real, valid credential. Cross-referencing solves this by querying the source of record directly, most often through AAMVA's Driver License Data Verification (DLDV) service, which checks license data in real time against the issuing state DMV rather than a static, outdated copy, reaching roughly 73% of the US population across 44 jurisdictions. A mismatch on name, date of birth, address, or license number, or a credential reported lost, stolen, or suspended, gets flagged immediately.
This layer has a specific blind spot: DLDV confirms a license's data matches DMV records, but it can't confirm the physical card is genuine or that the person holding it is who the data describes. That's why it always runs alongside document authentication and biometric matching, never on its own.
Layer 4: Biometric matching and liveness detection
This layer answers the question the first three can't: is the person on camera actually the person named on the document? A face-matching algorithm compares the photo printed on the ID to a live selfie or video frame, scoring facial landmarks to judge whether they're the same person despite age, lighting, and camera differences.
Liveness detection runs alongside the match to confirm the face in frame belongs to a real, present human rather than a photo held up to the camera, a video replay, a mask, or an AI-generated deepfake. Some systems use active liveness, prompting a head turn or blink on command; others use passive liveness, analyzing cues like skin texture and micro-movement without asking the user to do anything. This layer catches the hardest fraud pattern to spot on paper alone: a real, validly issued ID used by someone who isn't its owner. That pattern shows up constantly in account takeover, where TransUnion recorded a 37% year-over-year increase in suspected account takeover fraud from 2024 to 2025.
Layer 5: Behavioral and device signals
The last major layer looks past the document and the face, at the session's context: device fingerprinting, IP geolocation, connection metadata, typing patterns, and velocity checks, how many verification attempts come from this device or identity in a short window, all feeding a risk score in the background. A single mismatched data point rarely triggers a rejection on its own. What matters is the combination: an ID that authenticates fine, paired with a device that's attempted verification under three names in an hour.
This layer is also where continuous monitoring lives, especially in longer sessions like a remote online notarization closing. Rather than checking identity once at intake, platforms increasingly score video frames throughout, flagging deepfake or spoofing attempts the moment they appear.
Why the stack matters more than any single check
Each of these five layers has a blind spot the others cover. A stolen but genuine ID paired with an accomplice's face passes document authentication and the DMV cross-reference, and only gets caught by biometric matching or a behavioral anomaly. A well-made counterfeit with fabricated data fails at the cross-reference step even if it looks flawless.
Defeating all five at once is far harder and costlier than defeating any single one, which is why Proof and other platforms running identity verification at scale build the stack this way: it turns fraud from a difficult problem into an expensive one.
The financial pressure behind getting this right keeps growing. The FBI's Internet Crime Complaint Center logged over 1 million complaints and nearly $20.9 billion in losses in 2025, up 26% year over year; business email compromise, often layered on top of identity fraud, accounted for $3.04 billion of that, and real estate fraud complaints reached $275.1 million.
Every layer in this stack exists because fraud adapts fast enough to make any single check obsolete within a few years. If your setup is missing one, see how Proof runs document authentication, DMV cross-referencing, and biometric liveness together as a single, layered check.










.jpg)



































































.jpg)


























































