When someone redacts a passport scan by hand, they almost always cover the same things: the photo, the passport number in the top right corner, and sometimes the date of birth. Then they send it on, believing the document is safe.

It is not. At the bottom of the data page are two lines of capital letters, digits and < characters. That is the machine-readable zone, or MRZ. It holds almost everything printed above it, in a format built to be read by any scanner in the world.

What the MRZ contains

A standard passport uses the TD3 format defined by ICAO Document 9303: two lines of 44 characters. Read left to right, they contain:

FieldWhere
Document type and issuing countryLine 1, characters 1–5
Surname and given namesLine 1, the rest
Passport number, with a check digitLine 2, characters 1–10
NationalityLine 2, characters 11–13
Date of birth, with a check digitLine 2, characters 14–20
SexLine 2, character 21
Expiry date, with a check digitLine 2, characters 22–28
Optional personal number and a composite check digitLine 2, the rest

So a passport with the number and birth date covered in the visual zone but the MRZ left intact still gives away both, along with the full name and nationality. Decoding it needs no special tools. The format is public, and free MRZ readers exist for every phone.

The rule is simple: if you redact any field on a passport data page, redact the MRZ too. Otherwise you have only hidden the field from people who do not know where else to look.

Why automatic tools miss it

Most redaction tools look for identifiers one pattern at a time: something shaped like a passport number, something shaped like a date. The MRZ defeats this. The passport number has no spaces around it and runs straight into the check digit and the nationality code. The dates are written as YYMMDD with no separators. The name is joined with < characters. A pattern written for the visual zone finds none of it.

The opposite approach goes wrong as well. A rule that flags "any long string of capitals and digits" will flag product codes, reference numbers and base64 fragments, and a tool that redacts half of every document gets switched off within a week.

Detecting the MRZ properly

The MRZ has a built-in way to tell it apart from look-alikes: check digits. ICAO 9303 adds a check digit after the document number, the birth date and the expiry date, plus a composite check digit over the whole second line. Each one uses a 7-3-1 weighting over the characters before it.

That gives a detector something solid to test. A real TD3 MRZ passes five out of five checks. A random string of the right length almost never passes even one. So the reliable method is to find text with the right structure, then confirm it with the check digits before treating it as a passport. MaskAadhaar's global endpoints do exactly this, and they report which fields were found and how many checks passed. That way you can see why a block was redacted, not just that it was.

Scans and photos

Most passports reach a business as a phone photo or a scanned PDF, not as text. The MRZ was designed to be read by OCR and is printed in a dedicated typeface, OCR-B, so it usually OCRs well, often better than the rest of the page. The usual causes of failure are glare across the bottom of the page and a photo cropped just above the MRZ. In the second case the MRZ is not in the image at all, which is fine.

Note what "we found nothing" means on a scan. If a page could not be read, a tool should say so instead of returning the document as clean. Our API includes an ocr block with confidence for every page it had to read, so a low-confidence scan is flagged for a person to check rather than passed through.

A checklist for passport copies

  • Data page: photo, passport number, date of birth, place of birth, personal number if present.
  • MRZ: both lines, in full. Covering only the number segment still leaves the name, nationality and birth date.
  • Signature: if the copy is going anywhere it might be misused.
  • Metadata: photos carry EXIF data, including GPS coordinates from the phone that took them. Strip it.
  • Visa and stamp pages: visas carry their own MRZ in the two-line TD2-style or MRV format, and the same rule applies.

MaskAadhaar's global redaction endpoints find and remove passport MRZs on PDFs and scans, validated against the ICAO 9303 check digits, along with SSNs, IBANs, card numbers and more. Same API key as the Aadhaar endpoints.