What Happens When People Actually Check a Certificate

Checking whether a certificate is real: a person at a laptop with a verified certificate and checklists shown as an overlay
August 13, 2026

TL;DR
Between April and August 2026, people uploaded documents to TRUE Verify to find out whether they were real. Nearly nine in ten came back with the same answer: no origin, no security, nothing to check against. Not forged. Unverifiable. Fewer than one in twenty carried any proof at all.

What does it mean when a certificate cannot be verified?

It means the document makes a claim and offers no way to test it. There is no issuer to ask, no signature to check, no record it can be compared against. The document is not proven false. It is simply unproven, and it stays that way.

That is a different problem from forgery, and it is far more common. A forged certificate is a crime someone committed. An unverifiable certificate is a gap nobody noticed, usually left by an organisation that did nothing wrong except send a PDF.

Anyone who has hired knows the moment. An application arrives with a diploma attached. The name is right, the logo looks right, the layout looks like every other diploma. And there is no way to find out whether the person actually completed the course, short of calling the school and hoping somebody answers.

How often does this happen?

In our own data, nearly nine times in ten.

TRUE Verify is a free tool. Anyone can paste a document link or upload a file and get an answer, with no account. Between 20 April and 13 August 2026, people outside our company uploaded documents to it. We excluded our own monitoring, our own infrastructure and every document issued through TRUE, so what remains is other organisations' paperwork, brought in by whoever was holding it.

Almost all of it came back at the lowest level our system reports: no origin, no security. Fewer than one in twenty carried real proof, meaning a cryptographic signature, an issuer record or a seal that would survive a check.

The uploads matter more than the links. Someone with a verification link clicks it and gets an answer. Someone uploading a file has been handed a document, has no link to click, and is trying to work out what it is worth.

One caveat belongs here, and we would rather say it than have it pointed out. People who take the trouble to check a document often already suspect something. This is what arrives at a verification tool, not a random sample of every certificate in circulation. The number describes the documents people question, which is the population that matters if your job is to hire.

Is this a new problem?

No, and the numbers that exist have been pointing the same way for years.

Prospects, which runs the United Kingdom's official degree verification service, reports that 49 percent of large businesses and 48 percent of small and medium businesses have been hit by a degree lie. Their research also found that 66 percent of employers ask for a certificate, and 76 percent of those never check it with the awarding body. Prospects press office

HireRight's 2025 global benchmark report found that more than 75 percent of businesses discovered a discrepancy in a candidate's background during a single year. HireRight

The Council for Higher Education Accreditation and UNESCO have published on degree mills since 2009, and the reference case is still Axact, the Pakistani company that ran more than 370 fake university and accreditation websites and sold over 3,000 fake qualifications into the United Kingdom alone, including to people working in healthcare. Its executive was charged in a 140 million dollar fraud by the US Attorney for the Southern District of New York. Department of Justice

What our data adds is the other side of that story. The published research asks employers what they found. Ours records what happens when someone finally tries to check.

What does a verifiable certificate actually look like?

It carries its own proof. The document points back to the organisation that issued it, and that organisation confirms it, without the reader having to phone anyone.

In practice that means one of a few things. A cryptographic signature that fails if a single character changes. A record held by the issuer that a checker can query. A hash anchored to a public ledger, so the document can be shown to be the same one issued on the day it was issued.

None of that requires the reader to trust the sender. That is the whole point. A PDF asks to be believed. A verifiable document asks to be checked.

Why do organisations still send unverifiable documents?

Because a PDF works, right up until the moment it does not.

A training provider finishes a course, generates certificates, emails them out. Everyone is satisfied. The participant has proof, the provider has delivered, and the file looks professional. The failure happens somewhere else entirely, months later, in a hiring process the provider never sees, when someone cannot tell that document apart from one made in a design tool in twenty minutes.

The organisation issuing the certificate carries none of the cost of it being uncheckable. The person holding it does.

How do you check a certificate you have been sent?

Start with the document itself. Look for a verification link or a QR code that leads to the issuer's own domain, not to a file host and not to a page that simply displays the same information again. A link that leads back to a PDF proves nothing.

Then check the issuer, not the document. Go to the organisation's own website and find their verification page. If they have one, use theirs. It will be more authoritative than any third party, because it is the only source that knows what they actually issued.

If neither exists, you can paste the document or upload the file into TRUE Verify and see what it contains. It is free and requires no account. It will tell you what proof is attached, and often the answer is none, which is itself the finding.

What you cannot do is judge by appearance. Layout, seals, signatures and watermarks are all trivially reproducible, and they are what a forger spends their effort on.

What should an issuer do about it?

Issue documents that can be checked without you.

The test is simple. If someone receives a certificate from you today and wants to confirm it is real in two years, when the person who signed it has left and the course has been retired, can they? If the answer depends on somebody at your organisation answering an email, the document is not verifiable. It is a document you would vouch for if asked.

"Nearly two years ago I spoke to a student at Karolinska Institutet. She said she was glad they had moved to verifiable certificates, because otherwise nobody would know in five years that she had done the programme. With everything happening in AI, she was right."

Patrik Slettman, co founder of TRUE

The number that stays

Of the documents people brought us to check, fewer than one in twenty could be verified.

Get started with TRUE

Save time, increase traffic and insights and build trust, by upgrading to blockchain secured diplomas and course certificates, which are loved by recipients and always verifiably authentic.

Book a demo

More insights

Not sure where to start? Let us help!

You have questions, we have answers. Fill out the form to speak to our experts.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Hand holding smartphone with glowing floating digital document overlay symbolizing mobile document verification against blurred background

Trusted by leading organisations worldwide