A certificate of analysis (CoA) is a laboratory document that records what a specific batch of material contained at the moment it was tested. A fake or edited CoA is one where that record has been altered, fabricated, or detached from any real test - a purity figure typed over an image, a lab name that does not exist, or a generic sheet reused across every product. This guide walks through the physical and documentary tells you can check yourself, without any lab equipment. Everything here concerns documentary transparency for research-use-only materials, not medical, safety, or usage advice.
Why would a certificate of analysis be faked in the first place?
A CoA is the single easiest piece of a vendor's story to fabricate, because for most of its history it has been a static PDF that anyone can host and anyone can edit. Purity and identity are expensive to measure but cheap to claim. The whole value of the document rests on a chain: an independent lab ran a method, produced raw data, and issued a signed result tied to a batch. Break any link in that chain and the paper still looks the same. That is why transparency is a documentary property, not a marketing claim - a real CoA is verifiable back to its source, while a fake one only asks you to trust the vendor who handed it to you. The PeptideTrust scoring methodology exists precisely because a printed percentage, on its own, proves nothing.
What visual tells give away an edited CoA?
Editing a PDF almost always leaves seams. When someone types a new number over an original document, the substituted text rarely matches the surrounding characters. Scan the page for these inconsistencies:
- Mismatched fonts or weights - a purity value in a slightly different typeface, size, or boldness than the labels around it.
- Broken alignment - a figure that sits a pixel or two off the baseline of its row, or a column that no longer lines up.
- Uneven backgrounds - a faint white or grey box behind an edited value where the original text was painted over.
- Fuzzy versus crisp text - a scanned document is uniformly soft, so sharp, native-rendered digits dropped into it stand out.
- Ghosting or double edges around numbers that were pasted from another source.
None of these is proof on its own, but two or three together on the same value - almost always the purity figure - is a strong reason to treat the whole sheet as unverified.
Is a purity percentage without a chromatogram a red flag?
Yes, and it is one of the most reliable tells. High-performance liquid chromatography (HPLC) is the method that measures purity: it separates a sample into peaks and reports the target peak as a percentage of total peak area, such as 99.0%. The chromatogram - the plotted trace of those peaks - is the actual evidence. The percentage is only a summary of it. A CoA that states a purity number with no chromatogram behind it is asking you to accept the conclusion without the data, and a fabricated number is far easier to type than a plausible trace is to forge. Remember too that purity and identity answer different questions: HPLC tells you the sample is clean, while mass spectrometry (LC-MS) confirms it is the right molecule. Our guide on HPLC versus mass spectrometry explains why a clean peak of the wrong compound still passes a purity-only sheet.
How do I check whether the lab is real and independent?
A credible CoA names the laboratory that performed the analysis - independent third-party labs such as Janoshik or MZ Biolabs, not a vague "tested by a US lab" with no name attached. An unnamed lab cannot be verified, and a named one that you cannot find to exist is worse: it is a specific, checkable claim that fails the check. Take these steps:
- Search the lab name and confirm it has a real presence, a working domain, and a way to be contacted.
- Look for ISO/IEC 17025 accreditation, the international standard for testing-laboratory competence. It is a stronger signal than an unaccredited or anonymous lab, though its absence alone is not proof of a fake.
- Check that the analysis is signed and dated, since results describe a batch at a single point in time.
What counts as genuine independence is worth understanding in full; our explainer on independent third-party testing labs covers the distinction between a vendor's in-house sheet and an arms-length result.
What do reused batch numbers and dead verification codes tell me?
Two of the clearest signs of a fabricated document are a batch number that never changes and a verification path that leads nowhere. A real result is tied to a lot or batch number that matches the number printed on the vial. When one generic certificate is reused across every product, or carries no batch number at all, it is describing nothing in particular - it is decoration, not evidence. The strongest CoAs also carry a verification mechanism: a code or QR that resolves on the lab's own domain, where you can pull up the original result independently of the vendor. Treat these as failures:
- A verification code, QR, or portal link that resolves nowhere, times out, or returns an error.
- A QR that simply reopens the same vendor-hosted PDF instead of a lab record.
- CoAs offered only "by email on request" after purchase, where no independent copy exists.
A result you can only see through the seller, and never at the source, has not really been verified at all.
Can PDF metadata reveal an edited certificate?
Often, yes, and it costs nothing to look. Every PDF carries hidden metadata: a creation date, a modification date, and the software or author that produced it. In most reader applications you can open the document properties or "info" panel to see these fields. A certificate that claims to come from an accredited laboratory but was, by its own metadata, last saved in a consumer image editor or a generic PDF tool is telling you something the visible page does not. Useful things to check:
- Producing software - lab systems and photo editors leave different fingerprints.
- Modified-after-created gaps - a document edited long after its stated analysis date deserves scrutiny.
- Author or title fields that name a person or vendor rather than the lab.
Metadata can be stripped or spoofed, so a clean set of fields is not a guarantee of authenticity. But metadata that contradicts the document's own story is a meaningful, low-effort tell that pairs well with the visual and verification checks above.
How do these tells fit together into one check?
No single flag condemns a document, and no single green light clears it. The point is to read the CoA as a chain of evidence and see how many links actually hold. The table below summarises the contrast between a certificate that is verifiable at the source and one that is not.
| Signal | Credible CoA | Fake or edited CoA |
|---|---|---|
| Purity | Percentage backed by a chromatogram | Bare number, no trace |
| Lab | Named, findable, ideally ISO/IEC 17025 | Unnamed or non-existent |
| Batch | Lot number matches the vial | Reused or missing |
| Verification | Code resolves on the lab's domain | Resolves nowhere or to the vendor |
| Metadata | Consistent with a lab origin | Consumer editor, mismatched dates |
To see the full anatomy of a legitimate document field by field, read how to read a peptide CoA, and note that a purity or identity CoA describes composition only - it is never a sterility or safety guarantee.