What a QR code does and does not prove
A QR code is a way of storing a short piece of text, usually an address, in a pattern a camera can read. Nothing in the pattern says that the text is true. A forged diploma can carry a perfectly scannable code that leads to a page designed to look genuine. The code is therefore a convenience for reaching a page, never evidence in itself.
The symbology is standardised as ISO/IEC 18004, and it includes error correction in four levels that can restore roughly 7%, 15%, 25% or 30% of the data. That is why a code printed on a slightly creased or smudged sheet still scans. It also means that a damaged code that scans is not proof of anything either.
The three checks after scanning
- Read the address before the page. The page should be on the issuing institution's own domain or on the domain of the verification service the institution named. A lookalike domain that differs by one letter is the usual trick.
- Match the page to the paper. The page shows the recipient's name, the course or award, the issuer and the date. Each must agree with the document in hand, letter for letter.
- Read the status. A certificate may be valid, expired or withdrawn by the issuer. A page that reports a withdrawal or an expiry is a negative result even though the certificate exists.
How Emitcert's verification page behaves
The verification page opened by the QR code is the issuer's record, served from the same system that granted the certificate. It names the recipient, the award, the issuer and the dates, and states whether the certificate is valid, has expired, or was withdrawn by the issuer. The certificate's wording is signed with the institution's own Ed25519 key at the moment of issue, and the page reports the record that signature covers.
The W3C model for verifiable credentials adds a caution worth keeping: verifiability shows that a credential has not been altered, and the verifier still applies its own rules to decide whether to rely on what it says. A page that confirms the certificate does not decide, on the reader's behalf, whether the course satisfies the requirement in question.
When scanning fails
Printing, folding and screen glare all defeat cameras. The verification page of Emitcert accepts the certificate's code typed by hand, or the full link pasted in, and also offers to scan a QR code with the device's camera or from an image file. A code from another system is reported as such: the page states that the QR code does not contain an Emitcert verification link or code, which is a prompt to look for the issuer's own verification method.
For issuers: printing a code that scans
- Print it at a size a camera can read at arm's length, with a clear margin of plain paper around it.
- Print the code and the verification address in text beside it, for the day the printed pattern is damaged.
- Test one printed copy on two phones before printing the run.
- Keep the QR code off a dark or textured background.
A checklist for the reader
- Scan, then read the address.
- Compare name, award, issuer and date with the paper.
- Read the status line: valid, expired or withdrawn.
- If the QR code will not scan, type the printed code into the issuer's verification page.
- If anything disagrees, contact the issuer through a channel found independently of the document.
Frequently asked questions
Does a QR code that scans prove a certificate is genuine?
No. A QR code only carries an address. The proof is the page it opens, on the issuer's domain, showing details that match the document and a valid status.
What if the QR code is damaged and will not scan?
Type the code printed beside it, or paste the verification link, into the issuer's verification page. The result is the same as for a scan.
What does a withdrawn certificate look like on the page?
The certificate exists, but the page states that the issuer withdrew it, and in the case of a correction it points to the replacement. A withdrawn certificate is not valid.
Sources
The factual statements on this page rest on the documents listed below. Legislation and services change; consult the current version before relying on any of them.
