Qualified Electronic Timestamp: How Your Registered Mail is Protected

Behind every electronic registered mail, cryptographic mechanisms guarantee the integrity of your document and the certification of its date. Here is how they work — simply explained.

Why digital trust needs technical proof

When you send postal registered mail, trust rests on physical mechanisms: the sealed envelope, the post office stamp, the recipient’s signature on the acknowledgement of receipt. These are tangible, familiar forms of proof.

Electronic registered mail needs digital equivalents that are just as reliable. How can you prove a document existed on a specific date? How can you prove it has not been modified since sending? How can you prove the recipient actually received it?

The European eIDAS Regulation answers these questions by defining qualified trust services. This article explains concretely how they protect your registered mail — without unnecessary technical jargon.

The digital fingerprint (hash): your document’s DNA

🧬 The simple analogy

The digital fingerprint is to documents what the fingerprint is to people: a unique, tamper-proof identifier. Two different documents — even if they differ by a single comma — have completely different fingerprints. And it is mathematically impossible to reconstruct a document from its fingerprint.

🔧 How it works

A hashing algorithm (SHA-256 in the case of e-Signature.eu) transforms the entire content of your document into a fixed-length character string. This operation is deterministic (the same document always produces the same fingerprint) and irreversible (the document cannot be recovered from the fingerprint).

🔍 A concrete example

Original document: “The monthly rent is 1,200 euros.”
Fingerprint: a7f3b2c8d1e5… (64 hexadecimal characters)

Modified document: “The monthly rent is 1,500 euros.”
Fingerprint: 9e2d4f7a8b1c… (completely different)

→ A single digit changed and the fingerprint changes entirely. The slightest alteration is detected.

The digital fingerprint is the technical foundation of the whole mechanism. It is what makes tampering detectable: if someone modifies your document, the fingerprint embedded in the timestamp will no longer match the modified document, and verification will fail immediately.

The Qualified Electronic Timestamp: proof of date and integrity

🕐 The simple analogy

Imagine depositing a document with a notary. The notary records the exact date and time, affixes their seal and signs it. From that moment on, no one can dispute that the document existed on that date, nor claim that its content has changed since.

The Qualified Electronic Timestamp does exactly the same thing, but digitally and automatically.

🔧 How it works

When you send electronic registered mail on e-Signature.eu, here is what happens behind the scenes:

  • Fingerprint calculation — The digital fingerprint (SHA-256 hash) of your document is calculated, as explained above.
  • Certification by a QTSP — This fingerprint is sent to a Qualified Trust Service Provider (QTSP), certified and audited at European level. The QTSP associates the exact date and time from its certified time source, then signs the whole with its qualified certificate.
  • Timestamp token — The result is a timestamp token embedded in your PDF document. This token constitutes legal proof that your document existed in this exact form at that precise date and time.

💡 What the Qualified Electronic Timestamp proves

  • ✅ Your document existed at the indicated date and time
  • ✅ Its content has not been modified since that date
  • ✅ The date is certified by an independent trusted third party (not by you)

⚖️ Legal value

Article 41 of the eIDAS Regulation is explicit: a qualified electronic timestamp benefits from a presumption of accuracy of the date and time it indicates, and a presumption of integrity of the data to which it is linked. This presumption is recognised across all 27 EU Member States.

In practice: if your counterparty disputes the date of your registered mail before a court, it is up to them to prove the timestamp is wrong — not up to you to prove it is right.

The signed acknowledgement of receipt: proof of receipt

✍️ The simple analogy

This is the digital equivalent of the acknowledgement of receipt that the recipient signs at the post office counter. Except that here, identification relies on an eIDAS-compliant electronic signature — far harder to contest than a handwritten initial.

🔧 How it works

A separate document, titled “Acknowledgement of receipt”, is generated automatically. It includes:

  • The Qualified Electronic Timestamp details (date, time, timestamping authority)
  • The digital fingerprint of the registered document
  • The details of the sender and the recipient
  • The legal notices on consent to electronic communication

The recipient must sign this acknowledgement of receipt in order to access the registered document. They choose from the methods you have authorised: OTP by email (SES), Veriff (AES), itsme® or Evrotrust (QES).

💡 What the signed acknowledgement of receipt proves

  • ✅ The recipient received the document
  • ✅ Their identity is established by an eIDAS electronic signature
  • ✅ They expressly consented to communication by electronic means

⚠️ As long as the acknowledgement of receipt is not signed, the registered document is not transmitted to the recipient.

The dual protection of your registered mail

On e-Signature.eu, two complementary layers create a complete chain of trust:

🔒 The 2 layers of protection

  • 1 — The Qualified Electronic Timestamp certifies the date and time, and protects the integrity of the content through the embedded digital fingerprint → proof of when and what
  • 2 — The signed acknowledgement of receipt proves receipt by the recipient, identified by an eIDAS electronic signature → proof of received by whom

The Qualified Electronic Timestamp is applied automatically to your document as soon as the registered mail is sent, with no action required on your part. It is embedded in the PDF file that you and your recipient receive.

What about process traceability?

A third element completes the evidence file: the Audit Trail. This timestamped log automatically records every step of the registered mail — creation, invitation sent, automatic reminders, viewing, signature of the acknowledgement of receipt, or explicit refusal by the recipient.

The Audit Trail is consultable in real time from your dashboard and downloadable as a PDF once the procedure is finalised. It does not replace the two layers of cryptographic protection, but it documents the full course of the send.

How to verify these protections?

The protections on your registered mail are not invisible — anyone can verify them.

With Adobe Acrobat Reader

Open the PDF document in Adobe Acrobat Reader. The “Signatures” or “Certificates” panel in the sidebar displays the protections:

  • Green check: timestamp or signature valid, document unmodified
  • ⚠️ Yellow triangle: partial verification (certificate expired but protection still valid)
  • Red cross: protection invalid or document modified after application

You can click on each element to see the details: signatory identity, certification authority, date and time of the timestamp.

With the European Commission’s DSS tool

For in-depth verification — in a legal context, for example — you can use the European Commission’s Digital Signature Service (DSS) tool. This free, independent tool verifies the eIDAS compliance of the signatures and timestamps in your document.

Open the European Commission’s DSS verification tool →

Qualified vs non-qualified: why it matters

The term “timestamp” also exists in a non-qualified version. The difference is fundamental and concerns legal value.

CriterionNon-qualified timestampQualified Electronic Timestamp
IssuerAny providerQTSP certified and audited at European level
Legal presumption❌ No — evidential weight assessed by the judge✅ Yes — presumption of accuracy and integrity (Art. 41)
Burden of proofOn you, to prove validityOn the challenging party, to prove invalidity
EU recognitionLimited to the issuing countryAutomatic across all 27 Member States
Audit and supervisionNo obligationRegular audits by a conformity assessment body

💡 On e-Signature.eu

All electronic registered mail sent via e-Signature.eu automatically benefits from a Qualified Electronic Timestamp. There is nothing to configure or select: it is applied by default, at no extra cost.

⚠️ An important point of vocabulary

e-Signature.eu integrates qualified components (the Qualified Electronic Timestamp, eIDAS signatures) into an accessible, subscription-free service. The service is not, however, a fully qualified electronic registered delivery service within the meaning of Article 44 eIDAS — a qualification that requires formal identification of the sender through KYC or eID, and generally translates into a subscription model.

In concrete terms: your registered mail is admissible as evidence before the courts of all Member States (Article 43.1 eIDAS), and the Qualified Electronic Timestamp benefits from its own legal presumption (Article 41). The full presumption of Article 43.2 remains reserved for fully qualified services.

Frequently asked questions

Is the Qualified Electronic Timestamp included in the price of the registered mail?

Yes. The Qualified Electronic Timestamp and the Audit Trail are included automatically in every electronic registered mail, at no extra charge. The price you pay (from 0.4 credit, i.e. less than €2 excl. VAT) covers the entire chain of trust.

What happens if my document is modified after sending?

This is precisely what the protection prevents. If someone modifies the document — even by a single character — the timestamp becomes immediately invalid. Any verification (Adobe Acrobat Reader, DSS tool) will display an alert indicating that the document has been altered after being protected.

How long do these protections remain valid?

The Qualified Electronic Timestamp remains valid indefinitely as evidence. QTSP certificates have a period of validity (generally several years), but protections applied during that period retain their legal value after the certificate expires. Your registered mail sent today remains protected and verifiable in 10, 20 or 30 years.

Why is there no Qualified Electronic Seal on my document?

A Qualified Electronic Seal identifies the author of a document — a legal entity. In electronic registered mail, the author of the document is you, the sender — not e-Signature.eu, which is merely the technical transmission provider. Affixing an e-Signature.eu seal to your document would therefore be inappropriate and would create confusion about the real origin of the content.

The Qualified Electronic Timestamp already fulfils the essential functions: it certifies the date and protects the integrity of the content through the digital fingerprint. A seal would be redundant on that count.

Are these protections recognised outside the EU?

The eIDAS Regulation is directly applicable in the 27 EU Member States. Outside the EU, recognition depends on bilateral agreements and local law. In practice, eIDAS protections are widely recognised by international courts as solid evidence, thanks to the universal technical standards (ETSI, ISO) on which they rest.

Key takeaways

  • Automatic dual protection: Every electronic registered mail on e-Signature.eu combines a Qualified Electronic Timestamp (proof of date and integrity) and a signed acknowledgement of receipt (proof of receipt). Everything is applied automatically, at no extra cost.
  • eIDAS legal presumption: The Qualified Electronic Timestamp benefits from a presumption of accuracy of the date and integrity of the data (Article 41), recognised across all 27 Member States — with a reversal of the burden of proof.
  • Any modification is detectable: The digital fingerprint (SHA-256 hash) makes the slightest alteration of the document immediately visible. A single character changed and the timestamp becomes invalid.
  • Complete traceability: The timestamped Audit Trail documents every step of the process, including automatic reminders and any refusal by the recipient. Consultable in real time, downloadable as a PDF.
  • Verifiable by anyone: The protections can be verified with Adobe Acrobat Reader or the European Commission’s free DSS tool. No specialised software or technical expertise required.
  • Valid indefinitely: The protections applied to your document retain their legal value even after the QTSP certificate expires.

Send registered mail protected by eIDAS

Qualified Electronic Timestamp, signed acknowledgement of receipt and complete Audit Trail — included automatically. For less than €2 excl. VAT, no subscription.

Send registered mail →

Shopping cart

0
image/svg+xml

No products in the cart.

Continue Shopping