How to Spot a Fake Certificate

Accredify Logo Cropped

Accredify

How to spot a fake certificate: two identical certificates overlapping, indistinguishable in appearance, with only one carrying a verified indicator

A certificate arrives as an attachment. The candidate interviewed well, the offer is due this week, and someone has to decide whether the qualification on the CV is real. The document looks right. It has a crest, a seal, a signature and a plausible date.

In a YouGov survey carried out for Hedd in April 2025, 45% of large companies said they had discovered a job applicant giving false information about their qualifications, and 67% reported an increase in application fraud that they put down to AI tools. That fieldwork ran before the current generation of document-generation tools became widely available.

This article sets out the checks worth running on a certificate, what each one actually proves, and the point at which inspection stops being reliable.

Learn more about Gen AI document fraud in our article below.

Read Document Fraud in the GenAI Era →

How do you spot a fake certificate?

You spot a careless fake by checking the existence of the institution, the wording of the award and the file itself. You cannot spot a competent one by looking at it, which is why the only reliable answer comes from the issuing institution through a channel you found independently, or from a Verifiable Credential carrying a cryptographic signature that anyone can check.

What follows is six checks, ordered by how much each one proves, and then an honest account of how much we can rely on these checks.

Six basic checks that catch careless forgeries

These checks catch forgeries made without much effort, which is still most of them.

  1. 1 Confirm the institution exists and can award the qualification. Check the national register of degree-awarding bodies rather than the institution’s own website, which a diploma mill controls. Most countries publish a regulator list, and in the UK, Hedd has investigated some 400 fake universities and helped close 85 of them down. A convincing certificate from an institution with no awarding powers is a diploma mill problem rather than a forgery problem, and it is the fastest thing on this list to catch.
  2. 2 Check the award wording against the institution’s own conventions. Institutions are consistent about how they name degrees, classify results and phrase the conferral. Compare the certificate against a specimen or an example published by the institution. Ornate lettering and archaic phrasing are a common tell, because forgers tend to produce what a certificate is imagined to look like rather than what that institution actually issues.
  3. 3 Check the institution’s name word by word. Fake institutions frequently use a near-miss of a real name, or the right words in the wrong order. This is a quick check that catches a specific, common family of fakes.
  4. 4 Check the dates against the academic calendar. Conferral dates cluster around graduation ceremonies. A date that falls outside them, or a programme length that does not match the institution’s published structure, is an anomaly that should be investigated.
  5. 5 Look at the file, not the picture. A PDF carries metadata: a creation date, the application that produced it, and whether text sits in editable layers over a scanned image. A certificate awarded in 2019 whose PDF was produced last week in an image editor tells you something worth following up on. Treat it as a prompt to ask rather than as proof, because metadata is easy to edit and institutions reissue documents for entirely ordinary reasons.
  6. 6 Ask the issuer directly, through a channel you found yourself. Find the institution’s registrar through a search you run yourself, never through a contact route printed on the document: QR codes, verification URLs, email addresses and phone numbers on a forged certificate all lead where the forger chose. This is the only item on the list that confirms the award. Everything above it is triage to decide whether the wait is worth it.

The first five checks tell you whether to be suspicious. Only the sixth tells you whether the certificate is real.

Six checks on a certificate and what each one proves: five triage checks in neutral, and asking the issuer through a channel you found yourself marked as the only one that confirms the award

Why these checks now fail

Traditional methods of inspection were built for physical documents. Every feature that made a certificate hard to counterfeit is invisible in a digital scan, so it makes no practical difference whether the forgery was produced digitally or produced on paper and photographed.

Traditional security features are not digital. Embossed seals, holograms, security paper, microprint and wet-ink signatures are physical properties. A certificate submitted as a scan or a phone photograph has none of them. What this means is that we are really just inspecting a picture of a document.

Generative AI erases evidence of forgery. The classic markers of forgery were artefacts of people working by hand: misaligned text, substituted fonts, inconsistent spacing, spelling errors in the conferral wording. Document-generation tools do not make those mistakes. Check two above still works, but it now works only against careless forgers.

The verification route can be forged along with the document. A QR codes are just links to a page that “confirms” the authenticity of a document. But anyone can build a site that confirms the authenticity of a fraudulent document. The same applies to a verification link or a registry phone number printed on the certificate itself.

The issuer may no longer exist. Check six assumes someone is still there to answer, and sometimes, there is not. Institutions close, merge and rebrand. Private training providers go out of business. Departments are absorbed, and their records sometimes transfer with them and sometimes do not. A qualification awarded by a college that shut in 2015 can be entirely genuine yet entirely unconfirmable, because the office that would confirm it no longer exists. The problem is greatest where a national registry has been damaged or destroyed, which is the position facing many refugee and displaced graduates, and it is the reason a genuine qualification can be worth nothing in practice.

That last point is important to consider, because it is an impossible problem to answer with traditional verification tools. A certificate’s provenance should last with the certificate, or the value of that credential is completely, and unfairly, erased for the holder.

For the underlying numbers on how AI changed document forgery, see our statistics page.

Read Deepfake and AI Document Fraud Statistics →
What a security feature is worth on a screen: embossed seal, hologram, security paper, microprint and wet-ink signature present on a physical certificate, all struck through in what the verifier receives as a PDF or photo

What employers actually do

Most employers check some qualifications, fewer check all of them, and fewer still take the check to the institution. In the same April 2025 Hedd survey, 52% of large businesses said they check all academic credentials, against 37% of medium-sized firms and 29% of small ones. On whether that check goes as far as confirming authenticity with the issuers themselves (e.g. universities, training providers), through a screening agency or a verification platform, the split was 85% of large firms, 76% of medium and 39% of small.

The gap between checking and confirming a credential is what this article is focused on, and it exists for practical reasons rather than careless ones. A graduate vacancy now attracts around 140 applications on average, according to the ISE Student Recruitment Survey 2025. Confirming a degree with a registry usually entails the time taken to put in a formal request, a processing fee, and a wait period that can stretch up to weeks. Under that constraint, the process of confirmation is understandably done only for final candidates, senior hires, and regulated roles.

A risk emerges from this behaviour. With confirmation typically happening only at the end of a long and costly hiring process, should it be found that a candidate’s credentials are fraudulent, the hiring party is then faced with an excruciating process of re-qualifying candidates. Individuals on their waitlist may have already moved on to other opportunities, while the pool of relevant talent in the job marketplace might have shrunk during the weeks spent on interviewing the fraudulent candidate. These are additional business and opportunity costs to the hirer which can be entirely avoided in the first place, if the process of confirming credentials is made easy, cheap, and scalable.

A format that makes confirmation scalable: Verifiable Credentials

A Verifiable Credential answers the question traditional inspection cannot. It carries a cryptographic signature from the issuing institution, so anyone who receives it can confirm in seconds who issued it, that nothing in it has been altered since, and whether it has since been revoked, without contacting the institution and without relying on how the document looks.

The question changes from whether the document appears genuine to whether the issuer’s cryptographic signature checks out.

Three things a Verifiable Credential proves that a PDF cannot:

  1. 1 Who issued it. The signature is tied to the institution’s cryptographic identifier, not to a crest that anyone can copy from a website.
  2. 2 Whether it changed. Altering the name, the classification or the date breaks the credential’s cryptographic hash, and this is detectable by anyone.
  3. 3 Whether it is valid. Revoked and rescinded credentials can be checked, which is something that cannot be proven on paper or even e-Signed documents.

VCs also provides a workable solution to the provenance problem above, with some limitations to note. As the authenticity check runs against the issuer’s published public key rather than against the issuer’s inbox, a credential stays verifiable even after the institution stops existing or functioning. It is why credentials are anchored to a public registry/trust anchor (e.g. a blockchain) rather than to a university’s own web server. In the case of an institution vanishing entirely, along with its website that hosts its public key, then even the verification of its issued VCs can no longer prove provenance.

The other advantage is that the check does not depend on the verifier’s expertise. A registrar in Kuala Lumpur, a recruiter in Dubai, and an immigration officer in Singapore all get the same answer, and none of them needs to know what that institution’s certificates are supposed to look like or even have the skills to inspect a certificate.

For the underlying concept, see our explainer on Verifiable Credentials. For the mechanics of the check itself, see How Verification Works for a Verifiable Credential.

Inspection and verification answer different questions: inspection ends in a question mark, while a signature check confirms the issuer, that contents are unaltered, and that the credential is not revoked

TrustView lets your team check a credential’s authenticity and validity in seconds, all without contacting the issuing institution.

Learn more about TrustView →

What about digitally signed PDFs?

A common question most people ask are: what makes a Verifiable Credential different from an e-Signature? A digital signature applied through Acrobat, DocuSign or a national e-signing service binds the file to a signing certificate, so a verifier can establish that the file has not been edited since it was signed, and that it was signed by whoever holds that certificate. So technically, an e-signed digital document is just as tamper-proof as a Verifiable Credential.

The question it answers is narrower than most people assume. A digital signature is a statement about a file and a signer. It is not a statement about a qualification. Four questions still remain when checking a digitally signed document.

  1. 1 Who signed it, and what they were entitled to award. An e-signature is attributed to a person or a company account, and does not reflect an institution’s authority to confer a qualification. A certificate bought for a few dollars from a forger, and signed with the name of a company that sounds like a registrar, creates the illusion that the document was issued by a real university. An e-signature does not offer a complete check.
  2. 2 Whether the award still stands. An e-signature has no revocation status for the claim it sits on. Revoked e-signed documents do not have its status reflected in real time, and a rescinded award carries a perfectly valid signature for as long as the file exists. A Verifiable Credential is checked against a status list at the moment of verification, making it a more reliable way to check for credential and skill currency.
  3. 3 Machine-readability & data obfuscation. A signed PDF is still a picture of a document: the qualification, the classification, and the dates have to be read off the page by a human. A Verifiable Credential carries them as structured data, so eligibility can be screened automatically by a machine, and the holder can disclose required information, such as holding a current registration, without revealing other unnecessary yet potentially sensitive data (e.g. National ID number or home address).
  4. 4 Whether it will still verify in ten years. Signed certificates expire, and keeping a signature verifiable well beyond that takes trusted timestamping and archival that very few issuers set up. Credentials anchored to a public trust registry can continue to be verified after the point of issuance, and in some cases, when the institution have ceased to exist.

The two formats were built for different jobs. E-signing was designed for agreement: did this party consent to this document, on this date. Credentialling asks something else entirely: does this claim about this person hold, and does it hold today. A Verifiable Credential is the second question expressed as a file format, which is why it carries an issuer identifier, a status list and machine-readable claims, and an e-signed PDF does not.

What an e-signature settles and what it leaves open: a four-row comparison of an e-signed PDF against a Verifiable Credential on signer authority, revocation status, machine-readability and long-term verifiability

Where verification is already mandatory

Several governments have stopped leaving this to employer discretion, and the pattern across Southeast Asia and the Gulf is indicative of a legislative wave: each has concluded that looking at a certificate is not an adequate basis for a decision that carries immigration consequences.

Singapore requires verification proof of declared diploma-level and above qualifications for Employment Pass applications, in force since 1 September 2023 and extended to renewals from 1 September 2024. The key thing to note is what the Ministry of Manpower (MOM) will not accept. Educational certificates certified by a notary public, and letters from the school, are explicitly rejected as verification proof. A notary certifies that a copy matches an original and says nothing about whether the award was truly an authentically issued award (i.e. not from a diploma mill). What MOM accepts instead is proof from an approved screening company, verification through a government or institution portal, or a Verifiable Credential issued in the OpenCerts standard. That last route counts as proof on its own because the credential carries its own verifiable signature, so no third party has to be paid to confirm it.

Saudi Arabia went further and made verification a condition of entry. The Ministry of Human Resources and Social Development launched its Professional Verification service on 1 October 2023, covering 62 countries in its first phase, and expanded it in January 2025 to 160 countries and 1,007 professions. Expatriate workers in the covered occupations must have their academic qualifications verified before they arrive.

The UAE has long required foreign educational certificates to be attested, a chain in which, as the Ministry of Foreign Affairs puts it, “certifies the authenticity of the signatures and seals on documents”. In June 2023 the Ministry of Education launched an automated attestation service that attests certificates from UAE higher education institutions in under an hour, delivered to graduates through the UAE Pass app. The Gulf’s answer to certificate fraud is moving from a sequence of physical stamps to a verified digital credential that is issued and stored in a national wallet.

For institutions weighing up what this means for how they issue, our pillar guide covers the wider shift to VCs in Education.

Read Digital Credentials in Education: The Complete Guide →

Screening policies today

Set credential confirmation requirements by role. Decide in advance which roles require confirmed qualifications, confirm those with the issuer regardless of how the certificate looks, and use inspection only to risk assess and decide what to escalate.

  1. 1 Define the roles where the qualification is critical. Regulated, licensed, safety-critical, or where the qualification is the reason for the hire. Confirm those without exception.
  2. 2 Ask for verifiable formats at application. Where the institution issues Verifiable Credentials, request for the candidate to share the VC format of their credentials so you can easily confirm their qualifications in seconds.
  3. 3 Never confirm through a channel printed on the document. Registry contact details, QR codes, and verification links can all be spoofed.
  4. 4 Record what was checked and how. If a hire is challenged later, the record of the verification is the defence, not the certificate sitting in the file.

The part employers cannot fix

Hiring teams are stuck inspecting documents because many institutions still issue traditional documents that can only be inspected. That is not a screening problem, it is an issuance problem, and it is solved on the other side of the hiring equation.

An institution that issues Verifiable Credentials removes the work from every employer, registry and immigration officer who ever receives one. It also removes forged certificates circulating in its name, and protects its graduates by ensuring their credentials are usable forever. On the scale of the aforementioned problem of credential fraud, our degree fraud statistics page collects what the research currently supports.

Keen to issue certificates your learners and their employers can verify in seconds? Talk to our team about a pilot.

Schedule a demo →

Frequently asked questions

Can you tell if a certificate is fake just by looking at it?

Sometimes. Inspection reliably catches careless forgeries: wrong award wording, an institution with no degree-awarding powers, dates that do not match the academic calendar. It cannot catch a well-made one, and it gives you no way of knowing which kind you are holding.

What is the fastest way to check a certificate?

If the certificate was issued as a Verifiable Credential, checking its signature takes seconds and confirms the issuer, the contents and whether it has been revoked. To verify a Verifiable Credential, drag-and-drop the file into any supporting verification portal, such as TrustView. If you are not dealing with a Verifiable Credential, the only reliable way to check is by contacting the institution’s registry through contact details you found independently.

Are holograms and embossed seals a reliable sign a certificate is real?

Not on a scan or a photograph, where none of them are visible. They mean something only when someone is handling the physical document, and most certificates are sent as digital scans/files.

Can a QR code on a certificate prove it is genuine?

Only if you know who controls the page it leads to. A QR code can be spoofed by the forger, so a QR on a fraudulent certificate will most likely lead to a false verification page that the forger built themselves as part of their forgery service.

Is a digitally signed PDF good enough?

It is better than a plain scan, and it is not the same as a Verifiable Credential. A digital signature tells you the file has not changed since a particular certificate was applied to it. It does not tell you that the signer had the authority to award the qualification, whether the award has since been revoked, or what the document says in any form a system can read.

What if the institution no longer exists?

Then no amount of screening will confirm the award, because there is no one left to ask. This is a real and growing problem for graduates of closed providers and of institutions in conflict-affected countries. It is also the strongest argument for credentials that carry their own proof, since a signed credential can be verified without the issuer’s participation.

Do employers actually verify qualifications?

Not consistently, and checking is not the same as confirming. In the April 2025 Hedd survey, 52% of large businesses said they check all academic credentials against 29% of small ones, but on confirming authenticity with a university, screening agency or verification platform the split was 85% of large firms against 39% of small ones.

How do Verifiable Credentials stop certificate fraud?

During the verification process, the credential’s cryptographic hash is what is being checked, not its appearance. A cryptographic hash cannot be falsified, flags any tampering, and also contains the issuer’s signature, enabling you to confirm that the credential is authentic, untampered with, truly issued by the institution it claims to be from, and is still valid.

What Can We Do For You Today?

Whether you are looking to transform your business, have questions about our solution, or curious to explore new use cases with verifiable information, we are always happy to chat!