Digital Forensics

Screen recordings as evidence: what gets checked before the court believes the video

A screen recording of a conversation looks like the strongest evidence you can bring. Often it is. But it is also the easiest thing to fake convincingly, so it gets examined harder than almost anything else.

By the Editorial Team · October 2026 · 9 min read

Clients increasingly arrive with a phone video of a WhatsApp thread, a banking app, or an Instagram conversation, recorded by holding one phone over another or captured with the built-in screen recorder. The logic is understandable: a screenshot can be edited in thirty seconds, so a moving video of the screen feels harder to fake. That instinct is half right. A continuous recording is harder to fake than a still image, but it is nowhere near impossible, and the examination a forensic analyst runs on one is specific enough that solicitors should know what it involves before relying on the artefact.

What a screen recording actually is

A native screen recording, the kind produced by iOS or recent Android from the control centre, is a compressed video file with its own metadata layer. On iOS it is an MP4 or MOV written by the operating system itself, which is useful: the file records the creation timestamp, the device model, and often the iOS version, exactly as a photo would. On Android the output is typically an MP4 with a frame rate that varies depending on what the screen was doing, which matters later. A recording made by pointing a second camera at the screen is a completely different artefact: it carries the recording camera's own metadata, moiré patterns off the screen pixels, and refresh-band artefacts that an analyst checks for first.

The distinction sounds academic. It is not. The native recording is evidence of what the software rendered, with timestamps anchored to the phone's clock. The camera recording is evidence of what a human saw, which is sometimes exactly what you need and sometimes a chain-of-custody problem, because the phone that showed the thread and the camera that filmed it are now both part of the exhibit.

The five things an examiner checks

One: internal clock consistency. Nearly every screen recording captures a visible clock somewhere: the status bar, the app's own timestamps, the conversation thread dates. The file's own creation metadata must agree with what the screen shows, allowing for the recording length. A recording whose file says 14 March but whose status bar says 11 March, or where the visible timestamps jump backwards mid-thread, is flagged immediately. WhatsApp threads sort messages by server time, not phone time, so a faked thread assembled in a drafting app and then filmed scrolling past often shows messages in the wrong order or with timestamps that cannot correspond to any real sorting.

Two: platform rendering. Every messaging and banking app renders specific fonts, spacing, bubble shapes, tick marks and animation timing. Fakes are built in screenshot editors or cloned app UIs, and small things betray them: the wrong font weight in the timestamp, delivery ticks the wrong shade of grey, a bubble radius off by two pixels, the wrong animation when a message sends. An examiner works with reference captures from a real device running the same app version and compares frames side by side. This is slow, unglamorous work, and it is where most forgeries fail.

Three: frame continuity. Native recordings are continuous streams. Editing one means cutting the stream, and a cut shows up structurally: keyframe intervals break, the variable frame rate pattern resets, the audio track (if any) has a discontinuity, and motion that should be continuous, a scroll, a typing animation, a progress bar, jumps or stutters. Tools do not need to be exotic. Comparing frame hashes either side of a suspicious moment catches splices that are invisible to the eye. The same principles we described for testing deepfake video and audio apply here in miniature.

Four: what the interface implies. The recording shows more than the conversation. It shows battery level, signal, the presence or absence of read receipts, whether the sender's name matches the number, and whether the keyboard appears when a message is composed. Faked threads frequently show replies arriving while the "keyboard" is plainly not in use, or delivery receipts on messages in an order the platform cannot produce. Courts are getting better at noticing these themselves, because judges use these apps daily.

Five: provenance and transfer. The file that reaches the solicitor is rarely the file the phone produced. Sending the recording through WhatsApp, email or cloud drive recompresses it, strips or rewrites container metadata, and can remove the very fields the examination depends on. The first question in cross-examination will be how the exhibit was obtained, and "my client sent it to me on WhatsApp" has cost more than one claimant their best evidence. This is the same transfer problem we set out for chat exports and messaging records: the original device, or a forensic image of it, is worth ten times a forwarded copy.

What actually strengthens the exhibit

The honest limits

Some of what clients want from these recordings is not available. A screen recording does not prove a message was received by the other party, only that the screen showed a tick. It does not prove who was holding the phone. It does not authenticate the underlying account. It is, at its best, a faithful witness of a display, with a timestamp anchored to one phone's opinion of the time. Courts accept it for what it is, and exclude or discount it when it is asked to carry more. Instruct an examiner early, because the questions above are cheap to answer while the original device still exists and expensive to answer after three forwarding hops have flattened the file.

SolveAssist →