Credential fraud
How to Spot a Fake Certificate: 9 Red Flags
What to examine when a certificate looks wrong, which warning signs carry no information at all, and why inspection narrows the question without ever settling it.
Last updated · 8 min read
Nobody sets out to inspect a certificate. It happens because something snagged: a date that does not fit the rest of the CV, an institution nobody in the room has heard of, a PDF that arrived looking slightly wrong. The flags below are what to look at once that has happened, in the order that gets you to an answer fastest.
One thing to settle first, because it governs everything else. Inspection narrows; it does not confirm. A certificate that passes every check below can still be fraudulent, and a genuine one can trip several flags for boring administrative reasons. What inspection buys you is knowing whether this is worth the hours that confirming it will cost.
Three different things called "fake"
They need different responses, and the response is usually the reason you are checking at all.
Forged. A real certificate from a real body, altered: typically the name, sometimes the grade or the year. The issuer exists, the template is authentic, the record does not match. Editing a downloaded PDF or PNG takes minutes, which is why the document is a poor place to look for the answer.
Fabricated. Invented wholesale, usually from a body that does not exist or exists only as a website selling certificates. These are the easiest to catch, because the fiction has to extend past the document to an institution that will not survive ten minutes of searching.
Fraudulently obtained. A genuine record, genuinely issued, for a programme nobody completed. This is the hardest, and no amount of looking at the certificate will find it. Verification returns a clean result because the record is real. Only the issuer's own controls catch it.
Nine red flags
1. The issuing body barely exists
Search the institution independently, ignoring anything printed on the certificate. A legitimate awarding body has history: named staff, a physical address, other people mentioning it, a domain older than the certificate. A site registered eight months ago, with stock photography, no named individuals, and a fee schedule for "express processing", is not an institution. It is a shop.
2. The verification link opens a file, not a record
A verification link should return a live record generated from the issuer's data. If it opens a PDF, a JPEG, or a folder in cloud storage, it has verified nothing. You have been shown a second copy of the same document by the same person. This is easily the most common form of fake verification, precisely because it looks like the real thing to anyone who does not click.
3. The domain is not the issuer's, and not a platform you can name
Read the address bar before you read the page. You want the issuing organisation's own domain or a credentialing platform you can identify. Watch the near misses: a hyphen inserted into a familiar name, an unexpected country suffix, a well-known university sitting on free hosting. A convincing replica of a verification page costs about an hour to build, and it is the single most effective forgery available.
4. Typography breaks around the name and the dates
The fields a forger changes are the fields that go wrong. Look at the recipient's name, the award title, and the dates specifically, and compare them with the rest of the document: a slightly different weight or size, baselines that do not sit level, letter spacing that tightens to fit a longer name into a fixed space, a patch of background that does not match. On a scan, look for a texture change confined to one line. Nobody re-typesets a whole certificate; they edit four words.
5. The award does not appear in the issuer's programme list
Institutions publish what they offer. If the exact award title returns nothing on the issuer's own site, that is worth an explanation. Some are innocent: programmes get renamed, discontinued, delivered under an awarding-body arrangement where the teaching college and the certifying body differ. But "we do not run that programme and never have" is a complete answer, and it arrives in one email.
6. The credential number follows no format
Issuers number things systematically. If you hold two certificates from the same body, compare them for length, structure, and a year component that agrees with the issue date. A number that matches nothing, or a certificate with no identifier at all, means there is nothing for the issuer to look up even when they are willing to help.
7. The timeline does not survive arithmetic
Put the certificate beside the CV and check the dates actually work. A two-year programme completed inside eight months, a qualification issued during a period the candidate describes as full-time employment elsewhere, an award dated before the institution was founded. This is the cheapest check on the list and it catches more than document inspection does, because forgers control the certificate and not the rest of the story.
8. The holder manages the contact
Someone who offers to introduce you to their registrar, supplies a direct mobile number for "the person who handles verifications", or discourages you from contacting the institution, has told you something. Always reach the issuer through details you found yourself. Contact details printed on a fraudulent certificate lead back to whoever produced it, and that arrangement produces a very warm, very convincing confirmation call.
9. The award grants a title the body cannot award
Authenticity and authority are separate questions and people merge them constantly. A certificate can be genuinely issued, by a real organisation, that was never approved to award what it awarded. Degrees and diplomas are where this bites. In Nigeria the NUC publishes the list of approved universities and periodically names institutions operating without approval. Checking the register answers a question document inspection never will: not "is this real?" but "does this mean anything?"
Things that look like signals and are not
Several of the things people are proudest of noticing carry no information at all.
Seals, holograms, embossing, watermarks, ribbons. All of it prints, and a forger gets it right first, because it is what people look at. Security printing raises the cost of a fake; it does not let you detect one by eye.
A QR code. A QR code is a link. Anyone can generate one pointing anywhere. It means something only once you have scanned it and examined where it landed.
A signature that looks right. Signatures on certificates are reproduced mechanically. Yours is compared against nothing. Note that this is the handwritten kind. A digital signature is a different object entirely, is not visible on the document, and is the one thing on this list that can actually be checked.
A photograph of the graduation. Evidence of attending a ceremony, which is not evidence of completing a programme.
Poor English or an unfamiliar layout. Genuine institutions produce clumsy documents all the time, and this heuristic fails hardest against smaller and foreign issuers, which is a bias worth not building into a hiring process.
What to do when a certificate fails inspection
Flags are a prompt to check, not a verdict. Four steps, in order.
- Write down what you saw. Specifics, not impressions: which field, what was inconsistent, which link went where. A note saying "looked off" is useless in a fortnight when somebody asks you to justify a decision.
- Go to the issuer. This is the only step that resolves anything. Verifying a certificate online covers how to reach a registrar, what to ask, and what to do when the institution no longer exists.
- Ask the holder, plainly and without accusation. Most discrepancies are administrative: a name changed after marriage, a mis-keyed record, a certificate reissued after a correction. Someone who completed a programme also has coursework, an assessment record, the name of a course leader, an admission letter. Someone who bought one has a single document and a reason why nothing else survived.
- Decide against a written standard. Whatever your organisation does about a credential that cannot be confirmed should be written down before the case arrives, not improvised around a particular candidate. That is what makes the outcome defensible, and consistent between the candidates you liked and the ones you did not. How employers verify certificates sets out the three states worth recording, and why "could not be verified" and "contradicted by the issuer" must never collapse into one.
Why none of this settles it
The uncomfortable fact underneath the whole exercise: fake certificates are not especially hard to spot, but genuine ones are genuinely hard to confirm. Everything on this page narrows the field. Only the issuer's records close it.
That asymmetry is what makes credential fraud work. Confirming a real certificate through a registry office costs days or weeks, so most people quietly skip it, and at the moment the decision is made an honest certificate and a forged one look identical. Fraud does not thrive because forgeries are good. It thrives because checking is expensive.
For issuers: make your certificates hard to fake
If your organisation issues certificates, every flag on this list is something a stranger has to do because you left them no better option. You cannot stop anyone from producing a convincing image of your certificate. That is a printing problem and it has no solution. What you can do is make the image irrelevant.
A credential signed at issuance and hosted at a permanent verification URL moves the question off the document entirely. Alter the PDF all you like: the verification page still shows what the issuer signed, and the check runs against a cryptographic signature rather than against somebody's eye for typography. How the signing and verification works sets out the mechanism, including what it does not cover, and credential verification covers what changes for the people who currently phone you.
The wider version of that argument, why forgery persists at all and what being the institution on a forged document actually costs, is in certificate fraud in Nigeria.