If someone asks you to “sign digitally,” they could mean two different things: They might want you to type or draw your signature in an electronic-signature tool. Or they might require a digital signature that uses cryptography and, in some cases, a digital certificate.
A digital signature is a cryptographic method that uses a private key to create a signature and a corresponding public key to verify it. An electronic signature is a broader category that can include a typed name, drawn signature, click-to-accept process, or a digital signature.
So a digital signature can also be an electronic signature, but an electronic signature doesn’t have to use digital-signature technology.
If you’re trying to decide how to sign or send a document, start with the requirements for the transaction. Check what the recipient, filing system, regulator, or other party expects before choosing a signing method.
Disclaimer: This information is for general purposes only. It isn’t legal advice and shouldn’t replace counsel from a licensed attorney.
Digital signature vs electronic signature: What’s the difference?
An electronic signature describes a way of signing an electronic record. A digital signature describes a cryptographic technique used as part of the signing process.
Say you’re sending an agreement to a new contractor. If the requirements allow a standard electronic signature, you might prepare the document, add the fields they need to complete, and send it through an eSignature service.
If you’re submitting a document to a system that specifically asks for a certificate-backed digital signature, typing your name into a signature field won’t necessarily meet that requirement. So check first.
Just because one method uses cryptography doesn’t mean it’s the right choice for every agreement.
What’s an example of a digital signature?
A common digital signature example is a certificate-backed signature on a PDF.
When the document is signed, the software uses a private key to create the digital signature. The recipient’s compatible software can then use the corresponding public key to verify the signature and check whether the signed data has changed.
That’s different from typing your name into an eSignature field. Your typed name may qualify as an electronic signature, but it isn’t necessarily a digital signature in the cryptographic sense.
For documents where a standard electronic-signature workflow is appropriate, Dropbox Sign electronic signatures give you a straightforward way to prepare the document, add signer fields, send it, and keep track of its progress.
How does a digital signature work?
You don’t need to know all the ins and outs of digital signatures to understand what they’re doing.
A digital signature relies on two mathematically related keys:
- A private key, which is kept secret by the signer or trusted signing system and is used when creating the signature
- A public key, which can be shared with anyone who needs to verify the signature
When you digitally sign a document, the process generally looks like this:
- The software creates a hash of the document: Think of the hash as a value calculated from the document’s contents. Change the data, and you’ll normally get a different hash.
- The private key is used to create the digital signature: The signing algorithm uses the private key as part of creating a signature associated with that version of the data.
- The public key is used during verification: The recipient’s software uses the corresponding public key and signed data to check the signature.
If verification is successful, it can indicate that the corresponding private key created the signature and that the signed data hasn’t changed.
What it doesn’t tell you on its own is who was actually controlling that private key when the document was signed. That’s where certificates and other parts of a signing process can become relevant.
What’s a digital signature certificate?
If you’ve been told you need a “certificate-based digital signature,” the certificate provides information about the key being used.
A digital certificate links a public key to an identifier for a person, organization, or system. A certification authority signs the certificate so the association can be verified. How much confidence that gives you about identity depends on the issuer, how it verifies certificate holders, and whether the recipient trusts it.
You might also encounter the terms certified digital signature or certificate-backed digital signature. In each case, the certificate is being used as part of the trust framework around the signing key.
The broader system used to issue, manage, validate, and revoke these certificates is called public key infrastructure (PKI).
Unless your recipient or workflow asks for a particular certificate, you generally don’t need to choose one simply because you’re working with an electronic document.
Do you need a digital signature or an electronic signature?
If you’re staring at an unsigned agreement and can’t decide, work backward from what needs to happen when the document reaches its destination.
Check if the recipient has given you instructions
A regulator, court, filing system, customer, vendor, or other recipient may specify a certificate-backed digital signature, an accepted provider, or a particular file format.
Follow their instructions. A technically valid digital signature won’t help if the system receiving your document requires something different.
Check what needs to be verified
If your workflow specifically needs cryptographic verification that the signed data hasn’t changed, a digital signature provides a way to do that.
If the signing key also needs to be associated with an identifier, the requirements may call for a particular type of certificate.
If no special digital-signature method is required, look at the whole signing process
For many everyday agreement workflows, the job isn’t just putting a signature on a page. You may need to prepare the document, collect information from the signer, route it to several people, see who has completed it, and follow up with anyone who’s holding things up.
An electronic-signature platform can bring those steps together.
With Dropbox Sign, for example, you can add signature blocks, dates, text fields, and other information you need recipients to complete. You can then send the request, track its status, and set automatic reminders rather than following up on every outstanding item yourself.
And if you send the same document regularly, there’s no reason to rebuild it every time. Dropbox Sign templates let you save frequently used documents once and reuse them, which can help keep recurring processes more consistent.
Before you start any of these workflows, confirm the signature method, certificate or provider (if applicable), file format, and what evidence the recipient expects.
What does US law say about electronic signatures?
If you’re signing documents in the US, you’ll often see the ESIGN Act mentioned alongside electronic signatures.
The Act defines an electronic signature as an electronic sound, symbol, or process attached to or logically associated with a contract or other record and executed or adopted by a person with the intent to sign.
Under 15 USC § 7006(5), that definition has four basic elements:
- An electronic sound, symbol, or process: That could include typing a name, drawing a signature, clicking to accept, or using a digital-signature process.
- A connection to the record: The signature is attached to or logically associated with the relevant contract or record.
- An action by a person: The person executes or adopts the sound, symbol, or process.
- An intent to sign: The person takes that action with the intent to sign the record.
For transactions covered by the Act, 15 USC § 7001(a) says that a signature, contract, or record can’t be denied legal effect solely because it’s electronic.
There are limits to what you should take from that rule. It doesn’t automatically make every electronic signature or electronically signed contract valid or enforceable. Other contract-law requirements and rules governing the transaction can still apply. ESIGN also generally doesn’t require someone to accept electronic records or signatures.
The Act defines electronic signature. It doesn’t separately define digital signature or give a signature a different federal legal status simply because cryptography or a certificate is used.
Your eSignature platform shouldn’t make that legal decision for you. Once you’ve established that an electronic-signature workflow is appropriate, Dropbox Sign can help you prepare and send the request, automate reminders, and track request status.
What about electronic signatures outside the US?
If you’re sending agreements internationally, don’t assume the US terminology travels with them.
In the European Union, the eIDAS Regulation distinguishes between:
- Electronic signature: The broadest category.
- Advanced Electronic Signature (AES): An electronic signature that meets additional requirements around factors such as its link to the signer, signature-creation data, and detection of later changes.
- Qualified Electronic Signature (QES): An advanced electronic signature based on a qualified certificate and created using a qualified signature-creation device.
These are legal classifications. They don’t change the technical definition of a digital signature.
If you’re asked to use AES or QES, check the exact requirements before you prepare the request. The accepted certificate, trust service provider, signing format, and validation process can matter.
Dropbox Sign supports eID-based signing through qualified trust service providers for eligible Dropbox Sign API Premium customers. Available identity providers and signature types vary by country.
You can also read our guide to Simple, Advanced, and Qualified Electronic Signatures if you need to dig further into the eIDAS categories.
Choose the right Dropbox Sign workflow
Once you’ve worked out how an agreement needs to be signed, there’s still the process around it.
Take a document you send every month. Perhaps you update a few details, add the right recipient, send it, wait, check the status, send a reminder, download the completed copy, and then do the same thing again next month.
Dropbox Sign is designed to make that agreement workflow simpler. Reusable templates help you standardize documents you send regularly. Automatic reminders take care of routine follow-up. Status visibility shows you which requests are still waiting for action. The completed signature request includes a non-editable audit trail recording when it was sent, viewed, signed, and completed.
If your process needs additional recipient verification, you can also explore signer authentication with Dropbox Sign. The right authentication or signature method still depends on your requirements.
For a one-off agreement, this can mean fewer manual steps. When you’re managing recurring agreements across sales, hiring, procurement, vendor relationships, or other business processes, standardizing the workflow can also make it easier to see what’s done and what still needs your attention.
If you want to look at how that could work across your team, talk to a Dropbox Sign specialist about your current agreement process.
常見問題集
What’s the purpose of a digital signature?
A digital signature gives you a cryptographic way to verify signed data. Successful verification can indicate that the corresponding private key created the signature and that the signed data hasn’t changed.
If a digital certificate is used, it can also associate the public key with an identifier for a person, organization, or system. How much identity assurance that provides depends on the certificate issuer and its validation process.
Is typing your name a digital signature?
No, not in the cryptographic sense.
Typing your name can potentially qualify as an electronic signature when it’s associated with the relevant record and adopted with the intent to sign. A digital signature specifically uses public-key cryptography.
What does a digital signature look like?
There’s no required visual appearance.
The digital signature itself is cryptographic data. Your signing software may show you a signature block, certificate details, or verification status, but that visual element is separate from the underlying digital signature.
Is a digital signature more secure than an electronic signature?
Not all electronic signatures offer the same level of security.
A digital signature provides cryptographic evidence about the signing key and whether the signed data has changed. A certificate can provide information associating the key with an identified holder.
For other electronic signatures, the available security and identity evidence depends on the platform, signing method, authentication process, and records collected.
Choose based on what your document and recipient require rather than assuming one category is always the better option.
Do you need a digital certificate to create a digital signature?
Not for the underlying digital-signature algorithm itself.
A certificate-backed signing process uses a digital certificate to associate a public key with an identifier. If your recipient, regulator, court, or filing system requires a certificate, check which types and issuers it accepts before you choose one.
Ready to experience the difference?
時時參與其中
Thank you!
Thank you for subscribing!




