Is it safe to send a selfie holding your ID?

A real identity check happens inside the company's own app. A still photo you take yourself and send over chat is a different thing entirely.

Short answer

A verification selfie is normal, but almost always inside the company’s own app or web flow, where a live camera session confirms a real person is present. If someone asks you to take a still photo of yourself holding your ID — often with today’s date on a handwritten note — and send it over email, SMS or chat, treat that as a scam signal: a still image of a face next to a document is exactly what a fraudster needs to pass somebody else’s identity check.
  • The channel is the tell. A guided, live camera session run by the company is a real check; a still photo sent over chat is not.
  • The handwritten note with today’s date exists to satisfy some other platform’s verification, not the person asking you for it.
  • If you do send one, cover the document number, MRZ, date of birth and signature — your face and name still prove the point.
  • Inside a bank’s or exchange’s own regulated flow, do not redact: a covered field can fail the check.

At some point a request lands that feels different from the usual ask for a document copy: send a photo of yourself holding your ID up next to your face. Sometimes with a sheet of paper, today’s date written on it. It is common enough that it feels routine — and that is exactly why it works as a scam. The answer is not that verification selfies are wrong. It is that the legitimate ones almost never arrive the way this request did.

Why anyone asks in the first place

A document copy proves a document exists. It does not prove the person sending it is the person on it. Binding the two together — a real, living human, holding a real document, right now — is the whole reason remote identity checks exist, and for regulated businesses it is not optional. Under the EU’s anti-money-laundering rules, banks, crypto-asset providers and others have to identify customers from a reliable, independent source; the European Banking Authority’s guidelines on remote customer onboarding set out how to do that at a distance without being fooled, and the eIDAS regulation governs the electronic identification schemes many of them lean on.

None of that framework produces a request to email a photo of yourself. It produces a live camera session: an app or a page that turns on the camera itself, tells you to turn your head or follow a dot, captures frames it chose rather than frames you chose, and checks the document in a separate guided step. The session is designed on the assumption that whatever you hand it might be a photo of a photo. That is precisely the assumption a still image sent over chat cannot survive.

The tell is how it is collected

A real verification flowA request to distrust
Where it happensIn the company’s own app, or a page on its own domainWhatsApp, SMS, email, or a marketplace chat
Who works the cameraThe flow does — a live, guided sessionYou do, and you attach the result
What it wantsYour face and the document, as separate guided stepsBoth in one frame, often with a handwritten note
How it reached youYou started it, from inside your accountIt arrived unsolicited, and it is urgent
Where it goesA verification provider bound by contract and retention limitsSomeone’s inbox or personal phone
If you push backYou can restart it from your account, on your own initiativeThe story changes, or the pressure increases

The last row is the most useful in practice. A genuine check is something you can always walk away from and reopen yourself later, by logging in. A scam has to keep you in this conversation.

Why the still photo is worth so much

A photo of your document alone is dangerous in specific, limited ways. A photo of your face and your document, in one frame, is worth considerably more than the sum of the two, because it is a finished artefact: it is the file format that manual identity reviews at banks, exchanges and marketplaces are built to accept. The fraudster does not need to defeat a liveness check if they can get a human reviewer to approve a picture instead.

That also explains the paper. A handwritten note with today’s date, a platform’s name, or a reference number is the thing many services ask for to prove an image is recent and made specifically for them. When someone asks you to write one, the note is not for them. It is being commissioned to satisfy a verification screen somewhere else — usually one where an account is being opened, or taken over, in your name. No regulated identity check will ever ask you to hold up a piece of paper.

This is a documented pattern, not a hypothetical

Spain’s national cybersecurity institute, INCIBE, has published an advisory on exactly this: a smishing campaign impersonating social services, sending SMS messages that ask for three photos — the front of the ID, the back, and a selfie — to be returned to an address on a free mail domain. The tells INCIBE lists are the ones above: an unsolicited SMS, sloppy register that drifts between formal and informal, and a destination address that does not belong to the organisation it claims to be.

Worth noting what that campaign asked for: the front, the back, and the face. Collected together, that set is a complete remote-onboarding submission for somebody else’s platform.

What you can cover, and what has to stay

If you have decided the request is real but informal — a small business, a private landlord, a club membership — you can still narrow what you hand over. The check being performed is does this face match this document, and that survives redaction almost entirely intact.

In the frameKeep visibleCover
Your faceYes — it is the entire point of the photo
Name and photo on the documentYes — that is what is being matched
Document numberCover it
Machine-readable zoneCover it; it repeats the number and your date of birth
Date of birthCover, unless your age is the thing being checked
SignatureCover it
The room behind youFrame it out

That last row is not padding. A doorway, a window view, a delivery label or an envelope on the table can put you at an address as effectively as any field on the document — and unlike the document, nobody thinks to look at it. Use a plain wall. Bear in mind, too, that a photo file straight from the camera can carry GPS coordinates in its metadata: a screenshot or a re-exported, flattened copy does not carry the original’s, but the original itself may.

Prepare the document copy first, then take the photo holding that, rather than the real document — see how to redact a passport or ID card for the full method, and how to watermark it for naming the recipient and the purpose across the image.

When you should not redact

There is one clear exception, and it matters. Inside a bank’s, broker’s or exchange’s own regulated onboarding flow, send the document as it is. Those systems read the full document automatically, including the machine-readable zone, and a covered field will usually fail the check outright — costing you the account rather than protecting you. The distinction is covered in full in what ID copy your bank actually needs. Redaction is for copies that leave your control; a regulated flow you started yourself, inside an app you logged in to, is the opposite of that.

If the channel itself is the problem

Plenty of these requests are genuine but arrive somewhere unsuitable — a letting agent’s WhatsApp, a recruiter’s personal email. The request being real does not make the channel safe, and the copy will outlive the conversation: see is it safe to send your ID over WhatsApp or email, and how long a company may keep it once it has one. Under the GDPR, whoever asks needs a lawful reason to hold it and may only collect what is adequate and limited to what is necessary — which is the legal shape of the same argument this whole page makes.

If you have already sent one

Do not panic, but do not leave it either. Ask in writing for the copy to be deleted, report the request to the platform it came through, and watch for account-opening attempts and password resets in your name. The step-by-step version is in you already sent an unredacted ID copy — what now.

For the next request, the fix is a copy that is already safe before it goes anywhere near a camera. Anonymize my ID covers the document number, MRZ, date of birth and signature and watermarks the result for one named recipient, entirely on your phone — nothing is uploaded, so the copy exists only where you send it.

Handle a selfie-with-ID request safely

  1. Ask where the official flow is. Reply asking for the identity check inside the company's own app or on its own domain. A business that genuinely has to verify you has that flow already; a fraudster cannot produce one.
  2. Check the channel, not the wording. Look at where the request arrived and where the reply is meant to go. An unsolicited SMS, a marketplace chat, or an address on a free mail domain is the signal — polished wording is not reassurance.
  3. Refuse the handwritten note. A sheet of paper with today's date, a platform's name or a reference number is not part of any regulated check. It is there to make your photo satisfy a verification screen somewhere else.
  4. Redact the document before it goes in frame. Cover the document number, machine-readable zone, date of birth and signature, and hold the redacted copy rather than the original. Your face and the name and photo on the document are what the request is nominally for.
  5. Watermark it for that recipient. Write the organisation, the purpose and the date across the image, so a copy that resurfaces anywhere else is visibly out of context.
  6. Frame out the room. Use a plain wall. A doorway, a window view, a delivery label or post on the table behind you can place you at an address as effectively as the document does.

Frequently asked questions

Is it normal to be asked for a selfie holding my ID?

Inside a company's own verification flow, yes — banks, exchanges, and other regulated businesses have to bind a document to the living person presenting it, and a camera step is how that is done remotely. What is not normal is being asked to take that photo yourself and send it as a file over email, SMS or chat. Real checks capture the image themselves, in a live session they control.

How do I know whether a selfie-with-ID request is a scam?

Judge the channel, not the wording. A genuine check happens in the organisation's own app or on its own domain, guides you through a live camera session, and never arrives as an unsolicited message asking you to email photos to an address. A request that reached you by SMS or chat, points at a free mail domain, and stresses urgency is the documented scam pattern.

Why do they want a handwritten note with today's date?

Because a dated note is what many platforms ask for to prove a photo is recent and made for them. A fraudster collecting your face and your document wants that note so the image passes a verification screen at a bank, exchange or marketplace where they are opening or taking over an account in your name. No regulated identity check needs you to hold up a piece of paper.

Can I cover fields on the ID in a verification selfie?

For an informal request, yes — cover the document number, machine-readable zone, date of birth and signature. The person is checking that your face matches the document, and your face, name and photo do that. Inside a bank's or exchange's own regulated onboarding flow, do not redact: those systems read the full document and a covered field will usually fail the check outright.

What should I do if I already sent a selfie holding my ID?

Treat it as a leak of both your face and your document at once, which is more than either alone. Ask in writing for the copy to be deleted, tell the platform the request was made through, and watch for account-opening attempts and password resets in your name. There is a full guide on what to do after sending an unredacted copy.