E-signature authentication methods run from a link sent to an email address, through a one-time passcode by text, to a check of a government ID by a specialist vendor. None of them proves who signed. Each adds one fact — the person controlled this inbox, or this phone, or held up this card — and the law lets facts like that be used to show a signature was a person's own act. The real question is how many facts a given document is worth, and how many signers you are willing to lose asking for them.

Each of those facts is easy to describe as more than it is. It helps to know what each one actually shows, because the gap between them is where a dispute is argued.

What the law asks for: attribution

UETA, which almost every state has adopted in some form, has a section on exactly this. Section 9 says an electronic signature is attributable to a person "if it was the act of the person," and that the act "may be shown in any manner, including a showing of the efficacy of any security procedure applied to determine the person to which the electronic record or electronic signature was attributable."

Two things follow, and the drafters' own comments spell them out. First, no method is required. A security procedure can be as sophisticated as cryptography or as plain as a phone call back, a PIN or a mother's maiden name, and the Act gives none of them a presumption. Second, a stronger procedure does not change what kind of evidence it is; it changes how much weight it carries. The attribution of an electronic signature is built from circumstances, and each method below is one more circumstance. What the file has to hold when somebody challenges one is in what to keep for the day a signature is disputed.

A brass service bell, a guest register open at blank ruled pages with a pen across it, and a phone with a dark screen on a polished wooden front desk.

E-signature authentication methods, rung by rung

A link sent to an email address. It shows that whoever signed had the link, and that the link went to one inbox. That is possession, not identity. A link forwarded round a family, or opened on a shared computer, breaks the chain, and the record should say how the link travelled so that the break is visible rather than hidden.

A one-time passcode. A short code sent to the same inbox or phone number and typed before signing. It shows the person at the keyboard controlled that inbox or number at that moment, not only when the link arrived, and a forwarded link stops being enough on its own. An SMS passcode for e-signature has a known weakness: numbers can be ported and SIM cards swapped, which is why NIST's digital identity guidelines class codes sent over the phone network as a restricted option rather than a standard one.

Signing in person at a counter. A person physically in front of your staff, on a device you own. For walk-ups this is often the strongest position available, and it is only as good as what gets written down: which device, when, and whether anybody looked at a card.

Knowledge questions. Questions built from records, meant to be things only the signer would know. They are cheap and feel rigorous, but the answers can often be found or guessed, and NIST's guidelines, written for federal agencies, now say knowledge-based verification must not be used for identity verification.

ID document checks. A specialist vendor examines a photo of a government ID, often alongside a photo of the person, and reports whether the document looks genuine and whether the two match. It is the rung people usually mean when they say they want to verify signer identity. It costs money per check, and every extra step loses a share of the people asked.

Certificate-based signing. The signer holds a key tied to a certificate that an issuing authority gave them after establishing who they were. It underpins the EU's qualified signatures and some regulated work, and it is rare in anything a customer signs at a counter. How that differs from an ordinary electronic signature is in electronic signature or digital signature.

Matching the method to the risk

The mistake is choosing one level for everything. A better way in is three questions about the particular document.

What would a dispute actually be about? A waiver is questioned after something has gone wrong, often by the person who signed it or their family. "That was not me" is one possible argument. "I was not shown that", "I did not understand it" and "I did not sign for my son" are others, and a stronger identity check does nothing for any of them. The record of what was shown, the consent, and who signed for whom does.

What is at stake if the wrong person signed? A rental of expensive equipment, a document authorising work on somebody's property, a consent for a minor from a guardian who is not in the room: here "was it really them" is a live question, and a passcode, or ID verification for the e-signature, starts to earn its place.

What does each step cost? Every screen before the document loses some people. For a queue at a kayak rack on a Saturday morning that cost shows up within minutes. For a document signed once a year from a sofa it is small.

For most waivers, the bottom of the ladder done properly is where the evidence already is: a personal link, a typed name, consent recorded as its own step, and the time and address of each. Of all the e-signature authentication methods, the upper rungs are for documents where the second question has a large answer. Whichever you choose, the record should say which method was used rather than let a reader assume the strongest.

How SignSealer does it

SignSealer records evidence; it does not establish who somebody is. A signing link is minted for one named person and sent to their own email address or phone number. The full name they type is checked against the name the link was sent to, consent is its own step, and the network address, browser and time are kept for each event.

A business can ask for more under its settings. One-time passcodes send a six-digit code to the inbox the link went to, or to the phone when the link went by text, to be typed before the person consents. ID Evidence asks the signer for a photo of their ID, and of themselves if they wish, after consent and before the signature. The images are kept encrypted for thirty days, seen only by the business, and put on the certificate by hash; they are never checked against anything. It is evidence that somebody held that card up when they signed, not a check of who they are. At the counter, a document started on the business's own paired tablet is recorded as signed in person, and, when the business has switched them on, the tablet offers to take the same ID photo and to record where the signing happened; the customer may skip either.

The certificate names the level used for each signer: reached by email, by text, in person, by a link handed over directly, or one of the first two with a code confirmed. None of them is described as an identity check. Passcodes and ID Evidence come with the membership and are drawn from credit as used. ID document checks by a provider are not available yet, and the signer identity page and pricing say so in the same words. Evidence and the audit trail covers the rest of what is kept.

SignSealer is not a law firm and this is not legal advice. What evidence a particular document needs, and how UETA applies where you operate, is a question for a lawyer.