Watermarks that actually do something, and the ones that come off in two clicks
People add a watermark for very different reasons and rarely say which one. A "DRAFT" stamp is there so nobody mistakes the version. A "CONFIDENTIAL" diagonal across a contract is there to make a leak feel like a leak. A subtle "Prepared for J. Smith, 14 Mar 2026" in the footer is there so that, if the file does leak, you know who leaked it. Each of these is a watermark; each works differently; and only one of them is undermined by the fact that a determined person can remove any of them.
What a watermark is, technically
In a PDF, a watermark is ordinary page content: a text or image object drawn onto each page, usually with reduced opacity, often rotated, placed either under the existing content (a true "watermark" in the printing sense) or on top of it (a "stamp"). Our watermark tool does the latter with pdf-lib: it takes your text or image, applies the transparency and rotation you choose (0, ±45 or 90 degrees), and draws it at the same position on every page. The result is baked into the page description. There is no separate "watermark layer" a viewer can toggle off.
That last point cuts both ways. Because it is content, it prints, it survives conversion to images, and it shows in every viewer. And because it is content, anyone who can edit page content can remove it, exactly as they could remove any other paragraph. A watermark has no cryptographic property and no access-control property. Whatever it achieves, it achieves by being seen.
Job 1: labelling — always works
The most common and most useful purpose is simply to say what the document is: DRAFT, SAMPLE, COPY, VOID, INTERNAL, or a version number and date. For this the watermark is cooperating with the reader, not fighting them, and removal is irrelevant: nobody strips "DRAFT" off a draft to pretend it is final, and if they do, the person who receives it can compare with the real final. The design goal is legibility without obstruction: a large, light-grey diagonal text at around 30–50 % opacity is readable at a glance and does not interfere with the body text. Our tool defaults to 50 % for this reason.
Job 2: deterrence — works on the honest, which is most people
"CONFIDENTIAL — do not distribute" does not stop anyone from forwarding the file. What it does is remove the excuse. A document that arrived plain can be forwarded thoughtlessly; one stamped across every page has to be forwarded knowingly. Most leaks are careless rather than malicious, and a visible marking reduces the careless kind measurably. It also establishes, if things go to a dispute, that the recipient was on notice — which is why lawyers like it.
For deterrence the mark should be unmissable: larger, more central, more opaque than a label, and on every page including attachments and blank pages. It should not be so heavy that people re-type the document to get a clean copy, because then you have lost both the deterrent and the traceability.
Job 3: tracing — the one where removal matters
If the goal is to identify who leaked a document, the watermark has to be unique per recipient and has to survive an attempt to remove it. The first part is easy: generate one copy per person with their name, email or a code in the mark. The second part is where naive watermarks fail. A single line of small grey text in the footer, drawn as a text object, can be found and deleted by any PDF editor in seconds, or cropped off, or covered with a white box. A large diagonal mark across the content is harder to remove cleanly — deleting it leaves gaps if it was drawn under the text, and covering it damages the text if it was drawn over — but it is still a single object.
Techniques that resist removal are correspondingly more invasive. Rasterising the page (converting it to an image with the mark blended into the pixels, which our pdf-to-image tool would do) means the mark cannot be separated from the content at all; the price is a file that is no longer text. Slightly varying the spacing between words or lines per recipient, so the layout itself encodes an identifier, survives rasterisation and screenshots but requires specialised software. Embedding the identifier in the metadata is worthless — it is the first thing a leaker strips — and so is placing it in an invisible layer, which any inspection reveals.
The honest summary: a per-recipient visible watermark deters and identifies against casual leaks, which is most of them. Against a motivated adversary with an hour and an editor, nothing you can put on the page is decisive, and the real controls are elsewhere: who receives the file, whether it needs to be a file at all, and what agreements the recipient signed.
Text versus image marks
A text watermark is small, stays crisp at any zoom, and can be generated per recipient trivially. Its limitation in our tool is typographic: it uses the standard PDF fonts, so you cannot match a brand typeface. An image mark — a logo, a scanned stamp — can be anything, but it is a bitmap: it adds to the file size on every page, it blurs when zoomed, and a low-resolution logo looks worse on a printout than the document around it. Use a PNG with transparency at least twice the pixel size it will be displayed at, and check the first page at print zoom before applying it to two hundred.
Practical settings
- Labels (DRAFT, COPY): diagonal, light grey, 30–50 % opacity, large enough to read at thumbnail size.
- Deterrence (CONFIDENTIAL): diagonal or centred, 40–60 % opacity, every page. Add the date and the recipient's name if you can.
- Tracing: per-recipient text in at least two places (a footer line and a large diagonal), and rasterise the pages if the document's sensitivity justifies losing selectable text.
- Always keep the unwatermarked original. The mark cannot be removed by this tool afterwards, and you will need a clean copy for the next round.
- Add the watermark last, after merging, page numbering and signing, so it lands on every page of the final document and is not covered by later additions.
- If the file is encrypted, unlock it first; encrypted pages cannot be modified. Re-protect afterwards if the document needs a password.