The goose is not real. The reason forty thousand people would share it anyway is worth more than the joke.

For a few years there was a comfortable folk method for spotting synthetic images. Count the fingers. Look for melted text on signs. Check whether the jewellery makes sense. That method worked because early image models were bad at exactly those things, and it has aged badly for the same reason: they got better, and the checklist did not.

What has not aged is provenance. The durable question was never “does this look generated.” It was “where did this come from, and who is willing to stand behind it.”

There is now real infrastructure for answering that. The Coalition for Content Provenance and Authenticity — C2PA — publishes an open technical specification for attaching tamper-evident metadata to a piece of media: what device or software created it, what edits were applied, and who signed the record. Content Credentials, the consumer-facing name for those signed manifests, are supported by a growing set of cameras, editing tools and generative systems. When the data is present and the signature verifies, you are no longer guessing.

The durable question was never “does this look generated.” It was “where did this come from, and who is willing to stand behind it.”

The limitation matters as much as the capability. Provenance metadata can be stripped, and routine handling strips it. A screenshot destroys it. Some platforms remove metadata on upload as a matter of course. So the absence of Content Credentials tells you almost nothing, while their presence and validity tells you quite a lot. That asymmetry is the whole practical shape of the tool.

Automated detectors that examine pixels for synthetic artefacts are the other half of the field, and they should be handled carefully. Guidance from the U.S. National Institute of Standards and Technology on reducing the risks posed by synthetic content is explicit that detection is one control among several rather than a solved problem, and that provenance and detection are complementary. Detector confidence scores degrade when images are compressed, resized or re-shared — which is to say, under the exact conditions in which you actually encounter a suspicious picture.

So the working method, in order.

Find the earliest instance. A reverse image search that surfaces the picture on an account created last week, with no prior history, is a stronger signal than any artefact in the pixels. Ask who is publishing it, and whether that outlet corrects itself in public.

Check for Content Credentials where the platform exposes them, and treat a valid manifest as meaningful and a missing one as inconclusive.

Then look at the physics rather than the anatomy. Shadows that disagree about where the light is, reflections that do not contain the scene, and repeated texture in what should be unique detail are still the most reliable visual cues, because they require a model to be consistent about a whole scene rather than a single object.

And keep the last question in reserve: what would have to be true for this to be real? A goose cannot hold a microphone. That one was never going to need a detector.