reverse-image-search.md (24102B)
1 --- 2 title: "Reverse Image Search" 3 description: "Find where an image came from and whether it predates the event it supposedly shows — the first check on any visual claim." 4 category: osint 5 subcategory: "Images & Video" 6 tags: [osint, images, verification, reverse-search] 7 tools: [google-lens, tineye, yandex, bing, invid, ffmpeg, imagemagick] 8 difficulty: beginner 9 updated: 2026-10-04 10 references: 11 - name: "Bellingcat's Online Investigation Toolkit" 12 url: "https://bellingcat.gitbook.io/toolkit" 13 author: "Bellingcat" 14 license: none 15 relation: derived 16 note: "Tool catalogue: names, descriptions, cost flags and links for this area." 17 - name: "OSINT Newsletter Tools Library" 18 url: "https://tools.osintnewsletter.com" 19 author: "The OSINT Newsletter" 20 license: none 21 relation: derived 22 note: "Second tool catalogue, cross-checked against the above." 23 --- 24 25 ## What this covers 26 27 Establishing whether an image is what it claims to be, by finding earlier copies of it. This is the 28 single highest-value check in visual verification and it takes under a minute, so it goes first, 29 always — most viral misinformation is old footage relabelled, and the relabelling is what a reverse 30 search catches. The engines disagree constantly, which is not a flaw to work around but the reason 31 you run more than one. 32 33 ## Method 34 35 1. **Run several engines on the unmodified file.** They index different corpora. One engine 36 returning nothing means that engine has nothing, and nothing more than that. 37 2. **Sort by oldest where the engine lets you.** Relevance ranking is actively unhelpful here — 38 you want the earliest appearance, not the most popular one. 39 3. **Preprocess and re-run.** Crop to the distinctive object, remove the overlay, flip it 40 horizontally, upscale it. Each of these is a different query against the same corpus and each 41 finds things the others miss. 42 4. **For video, extract keyframes and search each.** A video is only as findable as its most 43 distinctive still. 44 5. **Read the earliest hit's own context.** The oldest copy you can find is not necessarily the 45 original. Follow its caption and its sourcing before you call it the source. 46 6. **Archive what you found, with its date, before you cite it.** Search results are not stable — 47 see [Archiving & Evidence](/sheets/osint/archiving-and-evidence). 48 49 The judgement call that matters: decide what you are actually asking. "Where did this image come 50 from" and "does this image predate the event it is captioned with" are different questions, and 51 only the second one is usually answerable. The second is also the one that settles arguments, so 52 aim at it. 53 54 ## Key tools 55 56 ### Google Lens 57 58 Web only, free, no account needed for a one-off. The strongest engine for *objects* — products, 59 landmarks, vehicles, plants, architecture — and it has the best OCR of any of them, which means it 60 will often read a sign in your image and search the text without being asked. That is exactly what 61 you want for a photo with a shopfront in it, and exactly what you do not want for a photo whose 62 text is incidental. 63 64 ```text 65 1. lens.google.com, or the camera icon in Google Images. Upload the file; do not 66 paste a social-media URL, which searches the page rather than the image. 67 2. Drag the crop handles immediately. Lens defaults to the whole frame and the whole 68 frame is almost always the wrong query. Crop to one object and re-run. 69 3. Switch between the result modes. "Exact matches" is the one that answers the 70 verification question; the visual-similarity feed is for identifying the object. 71 4. "Find image source" (where offered) gives a dated list of pages carrying the image. 72 This is the closest Lens gets to TinEye's oldest-first view, and it is worth 73 scanning to the bottom rather than the top. 74 5. Capture: the result page as a screenshot plus the URLs of the earliest pages, and 75 the crop you actually searched -- a result is not reproducible without the crop. 76 ``` 77 78 You can also hand it a URL directly, which is useful for scripting a triage pass over a set of 79 images already hosted somewhere: 80 81 ```bash 82 # searches the image at that URL; the image must be publicly reachable 83 open "https://lens.google.com/uploadbyurl?url=https://example.org/photo.jpg" 84 85 # url-encode anything with query parameters or the search will be of the wrong file 86 python3 -c 'import sys,urllib.parse; print("https://lens.google.com/uploadbyurl?url=" + urllib.parse.quote(sys.argv[1], safe=""))' \ 87 "https://example.org/img?id=123&size=full" 88 ``` 89 90 Lens personalises, so two people searching the same image get different result sets and neither is 91 reproducible from the other's screenshot. It is also weak on faces by design — it will refuse or 92 deflect — and weak on anything that is mostly sky, water or crowd. Dates shown next to results are 93 the page's claimed date, not the image's, and content farms backdate. 94 95 ### Yandex Images 96 97 Web only, free. The one that finds what Google misses, consistently enough that skipping it is a 98 real gap in a verification. It is markedly better at faces, at crops of faces, and at Eastern 99 European, Russian and Central Asian content of every kind — if the image has Cyrillic in it or is 100 plausibly from that part of the world, Yandex is your first engine rather than your third. 101 102 ```text 103 1. yandex.com/images -> the camera icon -> upload, or paste an image URL. 104 2. The results page splits into "Similar images" and "Sites containing this image". 105 The second list is the evidential one; the first is a lookalike feed and will 106 cheerfully show you a different person with the same haircut. 107 3. Use the size filter in the left rail. Filtering to larger-than-your-copy is a fast 108 way to find an earlier, less-compressed version, which is usually closer to source. 109 4. Re-run on a tight crop of a face or a patch, separately. Yandex handles partial 110 matches far better than the others and a crop frequently returns hits the full 111 frame does not. 112 5. Read the result page titles even when the thumbnails look wrong -- its indexing of 113 Russian-language forums and VK is better than anything else available. 114 ``` 115 116 The same URL pattern works if you want to fire it from a script: 117 118 ```bash 119 open "https://yandex.com/images/search?rpt=imageview&url=https://example.org/photo.jpg" 120 ``` 121 122 The face matching is good enough to be an ethical question rather than a technical one: it will 123 identify private individuals from a crowd shot. Decide before you run it what you will do with a 124 hit, and whether the person in the frame is a subject of your investigation or a bystander. Beyond 125 that, Yandex's similarity feed is the most confident and the most wrong of any engine — it will 126 return a visually similar image with total assurance, so never treat a "similar" result as a match 127 without comparing fixed detail yourself. 128 129 ### TinEye 130 131 Web only. Free for interactive use with no account; the published free API tier is **100 searches 132 per day and 300 per week** for non-commercial use, with paid tiers above that. The index is smaller 133 than Google's and it does not do visual similarity at all — it does exact and near-exact matching 134 of the same image, including crops, resizes and recolours. 135 136 That narrowness is the whole point: **TinEye's "Oldest" sort is the single strongest piece of 137 evidence available for "this image predates the event it claims to show."** If TinEye returns a 138 copy indexed in 2019 and the caption says the photo is from last week's protest, the caption is 139 false, and no amount of argument about context changes that. 140 141 ```text 142 1. tineye.com -> upload the file, or paste an image URL. 143 2. Change the sort from "Best Match" to "Oldest". This is the only control on the page 144 that matters for verification. The options are Best Match, Most Changed, Biggest 145 Image, Newest and Oldest. 146 3. Read the first result's crawl date and open the page it sits on. TinEye's date is 147 when it first saw the image at that URL, not when the image was made -- it is a 148 latest-possible-creation date, which is the useful direction. 149 4. "Most Changed" is the second-most-useful sort: it surfaces the versions that have 150 been cropped, overlaid or edited, which shows you how the image has been used. 151 5. "Biggest Image" finds the least-compressed copy, which is what you want to hand to 152 the other engines and to any forensic step. 153 6. Capture: the oldest result's URL, TinEye's stated date for it, the total match 154 count, and an archive snapshot of that oldest page before it moves. 155 ``` 156 157 Absence from TinEye is close to meaningless — its crawl is much narrower than Google's and it does 158 not index most social platforms, so a genuinely viral image can show zero results. The date is a 159 crawl date and a page can have been republished at a new URL, so an "oldest" of last month does not 160 mean the image is from last month. And it is defeated by heavy re-editing in a way the 161 similarity-based engines are not: a mirrored, re-captioned, re-encoded repost may not match at all, 162 which is why the preprocessing step below exists. 163 164 ### Bing Visual Search 165 166 Web only now. The Bing Search APIs — including Visual Search — were **retired on 11 August 2025** 167 and pre-retirement endpoints return HTTP 410, so any tutorial or script that calls a Bing visual 168 search API is dead; Microsoft's replacement is a grounding feature inside Azure AI Agents rather 169 than an image-match endpoint. The web interface still works and is still worth a minute, because 170 its regional coverage differs from both Google's and Yandex's. 171 172 ```text 173 1. bing.com/images -> the camera icon in the search box. (bing.com/visualsearch now 174 redirects to a Microsoft marketing page, not the tool.) 175 2. Upload, paste a URL, or drag a file in. 176 3. Use the on-image crop box, which Bing exposes more prominently than Google does -- 177 it is the best of the three for "search just this one object in the picture". 178 4. "Pages with this image" is the evidential list; "Related content" is not. 179 5. Capture the same way as the others: screenshot, URLs, and the crop you used. 180 ``` 181 182 Scriptable as a URL, with the usual caveat that it is an undocumented web parameter rather than a 183 supported interface and may change without notice: 184 185 ```bash 186 open "https://www.bing.com/images/search?view=detailv2&iss=sbi&q=imgurl:https://example.org/photo.jpg" 187 ``` 188 189 No oldest-first sort, no date on most results, and a strong pull toward commercial and stock 190 imagery. Treat it as a third opinion that occasionally produces the one hit nobody else had, 191 rather than as a primary tool. 192 193 ### Preprocessing with ImageMagick 194 195 The step that separates a reverse search that works from one that returns nothing. Engines match on 196 what is visually dominant, so an overlaid caption, a platform watermark or a wide establishing shot 197 all push the match toward the wrong thing. Each transformation below is a *separate query* — run 198 them all, do not pick one. 199 200 ```bash 201 brew install imagemagick # or: apt install imagemagick 202 203 # what you are actually working with: dimensions tell you how much has been lost already 204 magick identify -verbose photo.jpg | head -40 205 206 # crop to the distinctive object. percentages, or pixels as WxH+X+Y 207 magick photo.jpg -crop 40%x40%+30%+20% +repage crop-sign.jpg 208 magick photo.jpg -crop 640x480+120+80 +repage crop-vehicle.jpg 209 210 # mirror it. reposts are flipped constantly to defeat exact matching, and the engines 211 # do not try both orientations for you 212 magick photo.jpg -flop flipped.jpg 213 214 # cut off a burned-in caption bar or platform watermark along the bottom 215 magick photo.jpg -gravity south -chop 0x90 nobar.jpg 216 217 # upscale a small crop so an engine has pixels to work with. lanczos then a light 218 # unsharp is the combination that does not invent edges 219 magick crop-sign.jpg -filter Lanczos -resize 300% -unsharp 0x1 crop-up.jpg 220 221 # pull detail out of a dark or flat region before cropping to it 222 magick photo.jpg -auto-level -sigmoidal-contrast 3,50% enhanced.jpg 223 224 # strip metadata from anything you are about to upload to a third-party engine -- 225 # you are handing them the file, and the file may carry a source's GPS 226 magick photo.jpg -strip clean.jpg 227 ``` 228 229 `+repage` after a crop is not optional: without it the file keeps the original canvas geometry and 230 some tools will re-expand it. Upscaling adds no information — it makes a small crop palatable to an 231 engine's minimum-size requirements, and anything it appears to reveal is interpolation, so never 232 read a plate number off an upscale. And every enhancement you apply is a change to evidence: keep 233 the original untouched, work on copies, and record the exact command alongside the result, the same 234 way [Image & Video Forensics](/sheets/osint/image-video-forensics) handles hashing and the chain 235 from received file to analysed file. 236 237 ### ffmpeg 238 239 Video does not reverse-search. Frames do. Pull the frames that are worth searching and you have 240 turned an unsearchable clip into eight or ten image queries. 241 242 ```bash 243 brew install ffmpeg # or: apt install ffmpeg 244 245 # every encoded keyframe, decoded fast because P- and B-frames are skipped outright. 246 # this is the cheapest first pass and usually enough 247 ffmpeg -skip_frame nokey -i video.mp4 -fps_mode vfr -q:v 2 key-%03d.jpg 248 249 # frames at scene changes: 0.3 is a sane threshold, lower it to 0.1 for static footage 250 ffmpeg -i video.mp4 -vf "select='gt(scene,0.3)'" -fps_mode vfr scene-%03d.jpg 251 252 # one frame every five seconds, as a fallback for a single unbroken shot that has no 253 # scene changes to detect 254 ffmpeg -i video.mp4 -vf fps=1/5 every5-%03d.jpg 255 256 # a contact sheet, to pick the searchable frame by eye instead of opening fifty files 257 ffmpeg -i video.mp4 -vf "select='gt(scene,0.1)',scale=320:-1,tile=4x4" -fps_mode vfr sheet.png 258 259 # the exact frame at a timestamp, once you know which second carries the readable sign 260 ffmpeg -ss 00:01:12.500 -i video.mp4 -frames:v 1 frame.png 261 262 # crop, upscale and sharpen that frame in one pass, ready to hand to an engine 263 ffmpeg -i frame.png -vf "crop=400:300:820:460,scale=iw*4:ih*4:flags=lanczos,unsharp=5:5:1.0" search-me.png 264 265 # mirror a frame, for the flipped-repost case 266 ffmpeg -i frame.png -vf hflip frame-flipped.png 267 268 # blank out a burned-in platform logo rather than cropping the frame down 269 ffmpeg -i frame.png -vf "delogo=x=20:y=20:w=160:h=60" nologo.png 270 ``` 271 272 `-vsync vfr` appears in most tutorials for this and has been **removed** in ffmpeg 9 — it now fails 273 with "Option not found". Use `-fps_mode vfr`, which replaced it in ffmpeg 5. Scene detection also 274 fires on camera pans and on cuts to black as readily as on a genuine change of location, so expect 275 a third of the frames to be useless; conversely a single-shot clip yields no scene frames at all, 276 which is why the `fps=1/5` fallback is there. Downloading the video in the first place, and reading 277 its container metadata, are on [Social Media Platforms](/sheets/osint/social-media-platforms) and 278 [Image & Video Forensics](/sheets/osint/image-video-forensics) respectively. 279 280 ### InVID / WeVerify 281 282 A browser extension, free, from an EU research project. It collapses the whole video path above 283 into a few clicks and — the part that genuinely saves time — it extracts keyframes from a platform 284 URL without you downloading the file at all, then fires each keyframe at several engines in one go. 285 286 ```text 287 1. Install from weverify.eu/verification-plugin (Chrome and Firefox builds). 288 2. "Keyframes": paste the video URL. It fetches, segments and returns a grid of 289 keyframes with reverse-search buttons under each one. 290 3. Click through Google / Yandex / Bing / TinEye per keyframe. The buttons open the 291 engines in new tabs -- you still read the results yourself, it just saves the 292 upload step for each of the four. 293 4. "Magnifier": loads a still into a zoom-and-enhance panel, for reading a sign 294 without leaving the browser. 295 5. "Analysis": pulls the platform's own upload metadata for a YouTube/Facebook/X URL, 296 which gives you a latest-possible date for the upload -- not for the footage. 297 6. "Image forensics" runs ELA and noise filters. Use it for triage only; the real 298 version of that work is on the forensics sheet. 299 ``` 300 301 Platform integrations break whenever a platform changes its markup, so expect at least one tab of 302 the plugin to be dead at any given time; the keyframe extraction and the reverse-search buttons are 303 the durable parts. It gives you no reproducible command and no file hash, so anything you intend to 304 publish should be re-done with `ffmpeg` and recorded properly. And it uploads frames to third-party 305 engines, which is the same exposure question as any web tool — for sensitive material, extract 306 locally and decide deliberately what leaves your machine. 307 308 ### The smaller engines 309 310 Worth a minute each when the big four come back empty, because they index corpora the others do not 311 touch. 312 313 | Tool | What it is good for | 314 | --- | --- | 315 | [RootAbout](https://rootabout.com/) | Reverse image search across Internet Archive holdings — old web, scanned books and ephemera that no live-web crawler has. | 316 | [Search by Image](https://addons.mozilla.org/en-US/firefox/addon/search_by_image/) | Browser extension that fires one image at a configurable list of engines at once. The fastest way to run the full set without uploading four times. | 317 | [Karma Decay](http://karmadecay.com/) | Reverse search restricted to Reddit, which is where a surprising share of recycled images surfaces first. | 318 | [Pimeyes](https://pimeyes.com/) | Face search specifically, and paid beyond a teaser. Powerful, legally fraught in several jurisdictions, and a tool to think hard about before using on anyone who is not a subject. | 319 320 None of these replaces the main four. Reaching for them is a sign that your query is wrong more 321 often than it is a sign that the image is unindexed — go back and crop harder before you go 322 further down this list. 323 324 ## Tool reference 325 326 | Tool | What it does | Cost | 327 | --- | --- | --- | 328 | [InVID](https://weverify.eu/verification-plugin/) | A toolkit that supports the verification of videos and images. | free | 329 | [Google Lens](https://lens.google.com/) | Object, landmark and text matching with strong OCR. | free | 330 | [TinEye](https://tineye.com/) | Exact and near-exact matching with oldest-first sorting. | free / paid API | 331 | [RootAbout](https://rootabout.com/) | Reverse image search across Internet Archive holdings. | free | 332 333 ## Pitfalls 334 335 - **Cropped, mirrored or filtered images defeat exact matching.** Flip horizontally and re-run; 336 recompressed and mirrored reposts are extremely common and TinEye in particular will miss them. 337 - **Absence of results is not originality.** It usually means the original lives on a platform the 338 engine cannot index. Say "not found by X, Y and Z", never "original". 339 - **The oldest hit can still be a repost.** Read its context rather than treating the crawl date as 340 the answer. 341 - **Dates on result pages are the page's claim.** Content farms backdate, CMSs rewrite timestamps 342 on edit, and an archive snapshot is the only date you can stand behind. 343 - **Screenshots of screenshots** lose the detail engines match on. Ask for the original file. 344 - **Results are personalised and are not reproducible.** Archive the result page, and always record 345 the crop you searched — without it, nobody can repeat your query. 346 - **Uploading is disclosure.** Every web engine on this page keeps what you give it. For a file 347 from a source, strip it first and think about whether it should be uploaded at all. 348 349 ## Worked example 350 351 One datum: a photograph circulating with the claim that it shows a named street during a protest 352 three days ago. 353 354 1. **Unmodified file, four engines.** Lens returns stock-photo lookalikes. Bing returns news 355 aggregators from this week. Yandex returns a Russian-language forum thread. TinEye, sorted 356 **Oldest**, returns a first crawl dated **four years ago** on a regional news site. 357 2. **Open the oldest page.** It carries the same image, uncropped, with a caption naming a 358 different city and a different event. The claim is already broken at this point, and everything 359 after this is confirming rather than discovering. 360 3. **Confirm it is the same image, not a lookalike.** Crop both copies to the same corner — a shop 361 awning with a readable name — and compare. Identical awning, identical crack in the paving, 362 identical parked van. Fixed detail agreeing is the test; general resemblance is not. 363 4. **Explain why the other engines missed it.** The circulating version is mirrored and has a 364 caption bar burned along the bottom. `magick circulating.jpg -flop -gravity south -chop 0x90 365 fixed.jpg` undoes both, and a re-run gets Lens to the same original — which demonstrates the 366 edit and shows the preprocessing step earning its place. 367 5. **Date the circulating version, not just the original.** TinEye's "Newest" sort and the 368 aggregator pages put the relabelled version's first appearance at four days ago, a day before 369 the protest it is captioned with — which is itself a finding. 370 6. **Archive before citing.** The four-year-old page, the aggregator pages, and the TinEye result 371 page all go to the Wayback Machine, because the regional news site is exactly the kind of 372 source that reorganises its URLs. See [Archiving & Evidence](/sheets/osint/archiving-and-evidence). 373 374 What you can assert: the image was indexed on a named site four years before the event it is 375 captioned with, the circulating copy is a mirrored and cropped derivative of it, and specific fixed 376 details match between the two. 377 378 What would falsify it: the two images being different photographs of the same unchanged street — 379 which is what the awning crack and the parked van rule out, and which is why you compare fixed 380 detail rather than overall appearance. A crawl date that TinEye got wrong would also do it, so the 381 archived copy of the four-year-old page, with its own publication date, is the thing worth having. 382 383 ## Broader catalogues 384 385 - [Image and Video Analysis OSINT](https://tools.osintnewsletter.com/tool-categories/image-and-video-analysis-osint) 386 - [Fact-checking/verification OSINT](https://tools.osintnewsletter.com/tool-categories/fact-checking-verification-osint) 387 388 389 ## More tools 390 391 Further tools for this area from the OSINT Newsletter Tools Library ([Fact-checking/verification OSINT](https://tools.osintnewsletter.com/tool-categories/fact-checking-verification-osint)), excluding those already listed above. 392 393 | Tool | What it does | 394 | --- | --- | 395 | [Fact Check](https://www.factcheck.org/) | A non-partisan fact-checking platform that investigates political claims, public statements and misinformation (US focused). | 396 | [Google Fact Check Tools](https://toolbox.google.com/factcheck/explorer/search/list:recent;hl=en) | A free Google verification tool that helps users search existing fact-checks from trusted organisations worldwide. | 397 | [Politifact](https://www.politifact.com/) | An independent fact-checking platform that verifies claims made by politicians, public figures, organisations, and viral online… | 398 | [Snopes](https://www.snopes.com/) | Fact-checking and investigative journalism platform used to assess the accuracy, origin and context of online claims, rumours… | 399 | [StopFake Tools](https://www.stopfake.org/ru/glavnaya-2/) | A fact-checking and verification resource focused primarily on identifying and debunking disinformation, misleading claims, and… | 400 401 ## Sources 402 403 Both catalogues below are maintained by other people and are considerably larger than 404 this page. Use them as the canonical index; this sheet is a working route through them. 405 406 - [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own 407 review page covering cost, difficulty, requirements and limitations. 408 - [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal. 409 410 Neither publishes a licence, so nothing here is copied from them: tool names, one-line 411 descriptions, cost flags and links are catalogue facts, and the method and commentary are 412 this site's own. See [credits](/credits).