Credential verification
How to Verify Any Certificate Online: The Complete Guide
A step-by-step guide to checking whether a certificate is genuine: for digital credentials with a verification link, and for paper certificates carrying nothing but an issuer's name.
Last updated · 12 min read
Verify a Certifications.ng credential
Paste the verification link from the certificate, or the credential ID printed on it. You will land on the credential page, where the signature is checked and the issuer, award, and issue date are shown.
Holding a certificate that was not issued through Certifications.ng? This box cannot check it. Use the steps for a certificate with no verification link instead.
The short answer
Check the certificate against the issuer, not against the document. If it carries a verification link or a QR code, open it and confirm two things: that the page sits on a domain you can trace to the issuing organisation, and that every detail on it matches the copy in your hand. If there is no link, find the issuer's website yourself, look for a public register or a verification portal, and write to the registrar with the holder's full name, the credential number, and the year of issue.
Seals, watermarks, embossed logos, signatures: all of it prints. A forger gets those right first, because those are the parts people look at. The only question that settles anything is whether the issuer's own records agree, which is why the useful distinction is not paper versus electronic but whether you are holding a digital credential or a picture of one.
Why verification is harder than it should be
Think about what a paper certificate actually is. An organisation prints a claim about someone and hands it to the person the claim benefits. Nothing about the object connects back to the records that would confirm it.
So confirming it means reaching a human being at the institution who is willing to look something up, able to find a file that might be eight years old, and authorised to tell you what it says. Any one of those can fail. Together they make verification slow enough that most people quietly skip it.
Fake certificates are not especially hard to spot once someone actually looks. Genuine ones are hard to confirm. That asymmetry is what breaks the market: checking costs a hiring manager a week they do not have, so nobody checks, and honest and fraudulent certificates end up indistinguishable at the exact moment the decision gets made.
Verifiable digital credentials go at the root of this. Rather than asking the verifier to chase the issuer, they put the proof inside the credential, so the document can answer for itself. The proof is a digital signature, which is checkable by anyone and by nothing that resembles an eye for typography.
Which kind of certificate are you holding?
Four broad categories, and the method is completely different for each. Work out which one you have before doing anything else.
| Type | How to recognise it | How to verify | Typical time |
|---|---|---|---|
| Verifiable digital credential | A permanent verification URL, usually with a QR code and acredential ID; the page performs a signature check | Open the link and compare the details | Seconds |
| Platform-hosted badge | Hosted on a credentialing platform, often shared from a LinkedIn profile | Open the hosted page; confirm the issuer named there is the real issuer | Seconds |
| Institutional certificate or transcript | Issued by a university, examination board, or professional body; paper or PDF | The institution's verification portal, public register, or registrar | Days to weeks |
| Unverifiable printout | No identifier, no link, no traceable issuer; often a training provider with no online presence | Contact the issuer if they can be found; otherwise treat as unconfirmed | Often impossible |
Verifying a credential that has a verification link
The easy case, though there are still four or five ways to get it wrong. Work through these in order.
1. Open the link from the credential, not from the covering email
Someone sends you a certificate and, in the same email, a helpful "click here to verify" link. Use the QR code or the URL printed on the certificate instead. Email is trivially forged, and a link inside a forged email points wherever the sender wants it to point, including at a very convincing replica of a verification page.
2. Check the domain before you read the page
Read the address bar first, then the content. Does that domain belong to the issuing organisation, or to a credentialing platform you can name? Watch for the near misses: a hyphen dropped into a familiar name, an unexpected country suffix, a well-known university's name sitting on a free hosting subdomain. A fake verification page is the most effective forgery available and costs about an hour to build.
3. Confirm the issuer is the organisation you expect
The page should name the issuing body outright. If the CV says one organisation and the credential page names a different one, get that explained before going further. Sometimes it is a legitimate rebrand, or an awarding-body arrangement where a college delivers a programme certified by someone else. Sometimes it is the entire trick.
4. Match every detail against the document
Full name, exact award title, issue date. Small discrepancies matter more than large ones. When a genuine credential shows a date a year off from the copy you were handed, the usual explanation is that the copy was altered, not that the registrar mistyped.
5. Look for an actual cryptographic check
Plenty of verification pages simply pull a row from a database and print a green tick. That tells you a record exists in that platform's database. Useful, and weaker than it looks. A stronger implementation signs the credential's details with the issuer's private key and checks that signature in your browser, so altering the record breaks the check. Where a page explains what it checked, read the explanation.
6. Check dates, status, and expiry
Credentials expire. Credentials get revoked. A verification page should tell you the status right now, not merely that something was issued at some point in the past. A lapsed professional licence and a current one look identical on paper, and the difference is usually the whole reason you are checking.
A credential you can verify in seconds is worth more than one you cannot verify at all. That holds for the person carrying it as much as for the person checking it, which is the argument that actually moves issuers.
Verifying a certificate with no link
Most certificates in circulation fall here. Slower, but not hopeless.
1. Find the issuer's real website yourself
Search for the institution independently. Do not use the phone number or the email printed on the certificate. If the document is fraudulent, those contact details may lead straight back to whoever produced it, and that arrangement produces a very warm, very convincing confirmation call.
2. Look for a public register or verification portal
Professional bodies often publish a searchable register of members in good standing, and examination boards usually run some form of result checker. Where these exist they are the fastest route available: a name or membership number typed into the body's own site, returning a record nobody had to be asked for.
3. Contact the registrar, and ask precisely
Vague requests get vague answers, or no answer at all. Give them the holder's full name exactly as printed, any certificate or matriculation number, the exact programme title, and the year of completion. Then ask three specific questions. Did this person complete that programme? Does the certificate number match your records? Is the award current? Write down who answered and when.
Some institutions charge a fee and route requests through a named office or an appointed third party. That is normal, and it is fine. A body with no process at all for confirming its own awards is not fine, and that absence is itself a finding.
4. Ask the holder for corroborating evidence
Someone who did a programme has debris from it: coursework, an assessment record, the name of a course leader, classmates they can name, an admission letter, receipts. Someone who bought a certificate has one document and a reason why nothing else survived. You do not have to accuse anybody to ask.
When the institution no longer exists
Records usually outlive the institution. Look for a successor body, the relevant regulator, or a national archive. For tertiary institutions, start with whoever accredited them, because that also answers the second question worth asking about an unfamiliar name: was this place ever approved to award the thing it awarded?
Verifying certificates in Nigeria
The mechanics above hold anywhere. A few things about the Nigerian context are worth knowing before you start.
There is no single place to check a person, though for one category that is now changing. Since October 2025, clearance through the National Credential Verification Service has been mandatory for appointments across ministries, departments, agencies and higher institutions, and it issues a National Credential Number against a verified academic record. Certificate fraud in Nigeria covers what it is and what it does not reach. It applies to tertiary academic credentials, it is a clearance an employer runs rather than a check anyone can run, and everything below is still true of the rest. Whether it covers professional certificates is settled by two definitions in the policy, and the answer is no. Secondary results go through WAEC or NECO, both of which run result checkers that need a scratch card or token. Tertiary admission runs through JAMB, and results and transcripts through each institution's own registry. The NYSC discharge certificate has its own verification route. Every professional body runs its own register: MDCN for doctors and dentists, COREN for engineers, ICAN for chartered accountants. One CV can easily need five separate checks across five unrelated systems, and the person doing them is usually an HR generalist with a map of none of it.
Plan for the wait. University transcripts and confirmations still move through registry offices working partly from physical files, and several weeks is a normal turnaround rather than a bad one. That is survivable if you start at shortlist. It is not survivable if you start after the offer letter has gone out, which is exactly where verification gets quietly dropped.
Accreditation is a different question from authenticity, and it is the one people forget. The NUC publishes the list of approved universities and periodically names institutions operating without approval. A certificate can be genuinely issued, by a real institution, that was never approved to award it. Both checks matter and they return different answers: one asks whether the record is real, the other whether the award means anything.
All that fragmentation has a second effect, on the institutions themselves rather than on the people checking: it is what makes forgery cheap and disproving it expensive. Certificate fraud in Nigeria covers that side of it, and what it costs the bodies whose names get copied.
All that fragmentation is also why verifiable credentials are worth more here than in markets with a functioning central register. An issuer that hands every graduate a permanent, instantly checkable link steps out of a queue everyone else is stuck in, and hands its graduates a real advantage in a market where employers have learned to discount claims they cannot confirm.
Signals that should make you look harder
None of these proves a certificate is fake. Each one justifies spending more time on it before committing to the slower route above.
- The verification link points at an image or a PDF rather than a live record.
- The domain in the verification URL is not the issuer's, and is not a credentialing platform you can identify.
- The issuing body has no findable website, or one that appeared recently and describes no staff.
- The holder discourages you from contacting the institution, or offers to arrange the contact for you.
There are another five worth knowing, along with the things that look like warning signs and carry no information at all. Seals, holograms, and QR codes are on that second list. Nine red flags on a fake certificate goes through the full set and what to do when one of them fires.
What verification proves, and what it doesn't
Even a clean verification result has edges. Being clear about them prevents false confidence in one direction and unfair rejections in the other.
It proves that the credential record is authentic: that the named organisation issued this award to this person on this date, and that the details have not changed since.
It does not prove that whoever sent you the link is the person named on it. Anyone can forward a URL. Identity is a separate check, normally against government-issued ID.
It does not prove the award is worth anything. A genuine certificate from an unaccredited outfit is genuinely issued and worth very little. Authenticity and value are different questions, and people conflate them constantly.
And a failed check is not automatically fraud. Records get mis-keyed. Names change after marriage. Systems get migrated badly and lose a year of records. Treat a failure as a question for the issuer, not a verdict on the candidate.
For employers: doing this at every hire
Everything above describes checking one certificate. Doing it consistently, across every hire, is a different problem: verification rarely fails in organisations because anyone disagrees with it, but because it is nobody's job in particular and because it was scheduled for a point in the timeline where there is no time left.
How employers verify certificates covers that side in full: the five routes compared on what each one proves and how long it takes, what to record and in which of three states, why "we could not verify it" is not "it is fake", and the four decisions that turn verification from an intention into a process.
For issuers: stop being the bottleneck
If your organisation issues certificates, every verification request is work your team absorbs, and every request you cannot answer quickly costs one of your graduates an opportunity. You are the bottleneck in a process that reflects on you.
The fix is to issue credentials that verify themselves: signed at issuance, hosted at a permanent URL, checkable by anyone without contacting you at all. That is what credential verification on Certifications.ng does, and the security page sets out the signing and verification mechanism in full, including what it does not cover.
If you are currently producing certificates in a design tool and emailing them out, the certificate generator covers what changes and what doesn't. Recipients get the same thing they got before, plus a verification page and a signature behind it.