Skip to content
Tell Me About Peptides

is it real questions 2

Is a QR Code on a COA Proof of Anything?

On its own, no. A QR code is an address printed as a pattern, and it proves only where it points. What it can do is take you to a record the issuing laboratory controls — which is worth something only if you check where you landed and compare what you find.

No, not by itself. A QR code is a web address printed as a pattern of squares, and all it proves is where it points. If it points to a record held by the laboratory that issued the certificate, it is a convenient shortcut to a real check. If it points anywhere else, it proves only that someone put a file on a server and printed a way to reach it.

So the question worth asking is not whether a certificate has a code but where the code resolves, and whether what you find there matches the page in your hand. How a specific laboratory's lookup works is covered in the companion piece on verifying a named laboratory's reports. This one is about the code itself: what it carries, how it can mislead, and why its presence adds less than its appearance suggests.

An abstract diagram on an off-white ground showing a small square grid of slate blocks with two thin lines leaving it, one solid teal line ending at a document outline and one dashed slate line ending at an identical outline.
Two routes can end at documents that look identical. The pattern of squares does not tell you which route you are on.

What is a QR code actually carrying?

A short string of data — on a certificate, almost always a web address. The international specification for the symbology defines how characters are encoded into the grid, how the symbol is laid out, and how error correction lets a damaged or partly obscured code still be read 1. It is a very good way of getting a string off paper and into a phone.

What the specification does not contain is anything that proves who made the code. There is no signature, no certificate chain and no way for a scanner to tell whether the grid was produced by a laboratory, a seller or anyone else. Free generators produce a working code for any address in seconds. The code is a pointer, and a pointer's trustworthiness is entirely borrowed from its destination.

This is also why the code's appearance carries no information. A crisp, well-placed code in a laboratory-style corner looks official because of the layout around it, and layout is the easiest part of any document to reproduce.

Why do certificates carry QR codes at all?

Mostly for convenience, and the convenience is real. A long web address with a report identifier and a key attached is tedious to type and easy to get wrong by one character. A code removes the typing and the typos, and on a phone it turns a lookup that might take a minute into one that takes a few seconds. Laboratories that operate a lookup system have every reason to make it easier to use.

The second reason is less comfortable. A code has become part of what an official-looking document is expected to have, in the same way that a logo, a signature line and a reference number are. A document that carries one borrows some of the credibility of the documents that carry them for good reasons. That borrowing is where the misunderstanding starts, because the credibility never belonged to the code in the first place. It belonged to the record at the other end, and to whoever checked that record against the paper.

Where does the code resolve, and why does it matter?

Because the destination is the whole of the evidence. A code that opens a record on the issuing laboratory's own domain is putting you in front of a party who is not the seller and who has no reason to show you a different result. A code that opens anything else is putting you in front of whoever controls that anything else.

The code opensWhat it showsWhat it does not show
A record on the issuing laboratory's own domainThat the laboratory holds a matching record, if the details agreeThat the vial in your hand is the sample tested
A PDF on the seller's own websiteThat the seller uploaded a fileWho produced the file, or whether it has been edited
A file-sharing or cloud-storage linkThat someone shared a fileAnything about its origin
A link shortener or redirectNothing until you see the final destinationWhere you will end up, until you get there
A domain resembling the laboratory'sA page designed to look like a laboratory'sAnything a real laboratory record would show
What each kind of destination can and cannot tell you.

The last row is the one to take seriously. Consumer-protection guidance on QR fraud describes exactly this pattern — a code leading to a spoofed site that looks real but is not — and advises inspecting the address before opening it, watching for misspellings or a switched letter 2. A lookalike domain hosting a convincing replica of a laboratory's verification page defeats every other check, because it controls the answer you are given.

What does a hosted PDF prove?

That someone with access to that server put a file on it. If the server belongs to the seller, a code linking to it is functionally the same as the seller emailing you the PDF: a convenient delivery method with no independent confirmation attached.

This is not an accusation. Plenty of sellers host their certificates for convenience, and the files may be entirely faithful copies of what a laboratory issued. The point is narrower. The code has not added verification. It has added a route to the same document you could already see, and the question of whether that document is genuine is exactly where it was before you scanned.

The distinction becomes clear if you ask who could change the result. A record on a laboratory's system can be changed only by the laboratory. A file on a seller's website can be replaced by the seller at any time, and a code pointing at it will faithfully deliver whatever is there today.

Can a genuine QR code be copied onto a different certificate?

Yes, and this is the most important limitation. A code is just an image. Lift it from a genuine certificate, place it on an edited one, and it will still open the genuine record — which then appears to vouch for the edited document.

Call it replay. The code works exactly as intended; it is simply attached to the wrong document. The defence is also simple, and it is the same one that protects any laboratory lookup: once the record opens, compare it with the paper in your hand line by line. Sample description, client, date and every numerical result should agree. A code that resolves correctly but shows a record that differs from your document is not verification. It is evidence of alteration.

A gentler version of the same problem involves no editing at all. A genuine code on a genuine certificate for one batch, supplied alongside material from another batch, resolves perfectly and describes something you do not have. The code cannot help here, because nothing is wrong with the document. The only check is whether the batch identifier on the vial connects to the sample the record describes.

Does a screenshot of a verification page prove anything?

No. A screenshot is a picture of a page, and a page can be edited in a browser before it is photographed, or captured from a lookalike site, or captured from a genuine lookup of a different task. Everything that gives a live lookup its value — that you reached the page yourself and saw the laboratory's answer directly — is removed when someone else does the lookup and sends you an image of it.

The same applies to a video of someone scanning a code, and to a certificate that prints a phrase such as "verified" next to its code. Each is a claim that verification happened. None is verification.

How should you check a code properly?

Treat the code as a hint about where to go, then go there by a route you control. The same guidance that applies to codes on parcels and parking meters applies to codes on documents: do not act on a code you did not expect, check the destination before you open it, and when it matters, reach the organisation through an address you already know to be real 2 3.

  1. Scan the code with a reader that shows the full address before opening it, and read the domain carefully.
  2. Ask whether that domain belongs to the laboratory named on the certificate, or to the seller, a file host or a shortener.
  3. Even if it looks right, open a fresh tab and reach the laboratory's site by typing its address yourself.
  4. Look the report up from there using the identifiers printed on the certificate.
  5. Compare the record with your document on every field, including each result.
  6. Check that the batch identifier on the vial matches the sample the record describes.

Done this way, the code becomes almost irrelevant, which is the point. The check depends on the laboratory's record and your comparison, not on the square of pixels that suggested where to start.

Is a certificate without a QR code less trustworthy?

No. Codes are a convenience that some laboratories offer and many do not. A great deal of excellent analytical work is reported on plain documents, and the absence of a code says nothing about the quality of the testing behind it.

What matters is whether a report can be connected back to its issuer by some means you control. The international standard for testing laboratories requires every report to carry a unique identification and the name and address of the laboratory 4. Those two things are enough to make a document checkable: find the laboratory independently, quote the report's identifier, and ask whether it issued that document. A code can make that quicker. It cannot make it unnecessary.

The honest summary is that QR codes on certificates solved a convenience problem rather than a trust problem. They made it easier to reach a document and did nothing to establish who wrote it. Where they point to a laboratory's own system they are genuinely useful. Everywhere else, they are a well-designed way of making a file look more official than the file on its own would.

References

  1. ISO/IEC 18004:2024 Information technology — Automatic identification and data capture techniques — QR code bar code symbology specificationInternational Organization for Standardization, 2024
  2. Scammers hide harmful links in QR codes to steal your informationUS Federal Trade Commission, Consumer Advice, 2023
  3. Scam alert: QR code on an unexpected packageUS Federal Trade Commission, Consumer Advice, 2025
  4. ISO/IEC 17025:2017 General requirements for the competence of testing and calibration laboratoriesInternational Organization for Standardization, 2017