peptidetrust
home / Guides / How to Spot a Fake or Edited Certificate of Analysis
guide

How to Spot a Fake or Edited Certificate of Analysis

A practical, non-medical field guide to the tells that separate a real lab document from an edited or invented one.

By Marcus Vela · 2026-08-02 · 6 min read

A certificate of analysis (CoA) is a laboratory document that records what a specific batch of material contained at the moment it was tested. A fake or edited CoA is one where that record has been altered, fabricated, or detached from any real test - a purity figure typed over an image, a lab name that does not exist, or a generic sheet reused across every product. This guide walks through the physical and documentary tells you can check yourself, without any lab equipment. Everything here concerns documentary transparency for research-use-only materials, not medical, safety, or usage advice.

Why would a certificate of analysis be faked in the first place?

A CoA is the single easiest piece of a vendor's story to fabricate, because for most of its history it has been a static PDF that anyone can host and anyone can edit. Purity and identity are expensive to measure but cheap to claim. The whole value of the document rests on a chain: an independent lab ran a method, produced raw data, and issued a signed result tied to a batch. Break any link in that chain and the paper still looks the same. That is why transparency is a documentary property, not a marketing claim - a real CoA is verifiable back to its source, while a fake one only asks you to trust the vendor who handed it to you. The PeptideTrust scoring methodology exists precisely because a printed percentage, on its own, proves nothing.

What visual tells give away an edited CoA?

Editing a PDF almost always leaves seams. When someone types a new number over an original document, the substituted text rarely matches the surrounding characters. Scan the page for these inconsistencies:

  • Mismatched fonts or weights - a purity value in a slightly different typeface, size, or boldness than the labels around it.
  • Broken alignment - a figure that sits a pixel or two off the baseline of its row, or a column that no longer lines up.
  • Uneven backgrounds - a faint white or grey box behind an edited value where the original text was painted over.
  • Fuzzy versus crisp text - a scanned document is uniformly soft, so sharp, native-rendered digits dropped into it stand out.
  • Ghosting or double edges around numbers that were pasted from another source.

None of these is proof on its own, but two or three together on the same value - almost always the purity figure - is a strong reason to treat the whole sheet as unverified.

Is a purity percentage without a chromatogram a red flag?

Yes, and it is one of the most reliable tells. High-performance liquid chromatography (HPLC) is the method that measures purity: it separates a sample into peaks and reports the target peak as a percentage of total peak area, such as 99.0%. The chromatogram - the plotted trace of those peaks - is the actual evidence. The percentage is only a summary of it. A CoA that states a purity number with no chromatogram behind it is asking you to accept the conclusion without the data, and a fabricated number is far easier to type than a plausible trace is to forge. Remember too that purity and identity answer different questions: HPLC tells you the sample is clean, while mass spectrometry (LC-MS) confirms it is the right molecule. Our guide on HPLC versus mass spectrometry explains why a clean peak of the wrong compound still passes a purity-only sheet.

How do I check whether the lab is real and independent?

A credible CoA names the laboratory that performed the analysis - independent third-party labs such as Janoshik or MZ Biolabs, not a vague "tested by a US lab" with no name attached. An unnamed lab cannot be verified, and a named one that you cannot find to exist is worse: it is a specific, checkable claim that fails the check. Take these steps:

  • Search the lab name and confirm it has a real presence, a working domain, and a way to be contacted.
  • Look for ISO/IEC 17025 accreditation, the international standard for testing-laboratory competence. It is a stronger signal than an unaccredited or anonymous lab, though its absence alone is not proof of a fake.
  • Check that the analysis is signed and dated, since results describe a batch at a single point in time.

What counts as genuine independence is worth understanding in full; our explainer on independent third-party testing labs covers the distinction between a vendor's in-house sheet and an arms-length result.

What do reused batch numbers and dead verification codes tell me?

Two of the clearest signs of a fabricated document are a batch number that never changes and a verification path that leads nowhere. A real result is tied to a lot or batch number that matches the number printed on the vial. When one generic certificate is reused across every product, or carries no batch number at all, it is describing nothing in particular - it is decoration, not evidence. The strongest CoAs also carry a verification mechanism: a code or QR that resolves on the lab's own domain, where you can pull up the original result independently of the vendor. Treat these as failures:

  • A verification code, QR, or portal link that resolves nowhere, times out, or returns an error.
  • A QR that simply reopens the same vendor-hosted PDF instead of a lab record.
  • CoAs offered only "by email on request" after purchase, where no independent copy exists.

A result you can only see through the seller, and never at the source, has not really been verified at all.

Can PDF metadata reveal an edited certificate?

Often, yes, and it costs nothing to look. Every PDF carries hidden metadata: a creation date, a modification date, and the software or author that produced it. In most reader applications you can open the document properties or "info" panel to see these fields. A certificate that claims to come from an accredited laboratory but was, by its own metadata, last saved in a consumer image editor or a generic PDF tool is telling you something the visible page does not. Useful things to check:

  • Producing software - lab systems and photo editors leave different fingerprints.
  • Modified-after-created gaps - a document edited long after its stated analysis date deserves scrutiny.
  • Author or title fields that name a person or vendor rather than the lab.

Metadata can be stripped or spoofed, so a clean set of fields is not a guarantee of authenticity. But metadata that contradicts the document's own story is a meaningful, low-effort tell that pairs well with the visual and verification checks above.

How do these tells fit together into one check?

No single flag condemns a document, and no single green light clears it. The point is to read the CoA as a chain of evidence and see how many links actually hold. The table below summarises the contrast between a certificate that is verifiable at the source and one that is not.

SignalCredible CoAFake or edited CoA
PurityPercentage backed by a chromatogramBare number, no trace
LabNamed, findable, ideally ISO/IEC 17025Unnamed or non-existent
BatchLot number matches the vialReused or missing
VerificationCode resolves on the lab's domainResolves nowhere or to the vendor
MetadataConsistent with a lab originConsumer editor, mismatched dates

To see the full anatomy of a legitimate document field by field, read how to read a peptide CoA, and note that a purity or identity CoA describes composition only - it is never a sterility or safety guarantee.

Research & education only. PeptideTrust rates documentary transparency, not product quality or safety. Nothing here is medical advice or a recommendation to purchase or use any substance. Research peptides referenced are for laboratory use.

Frequently Asked Questions

Does a genuine CoA guarantee the product is safe?
No. A certificate of analysis reports composition - typically purity by HPLC and identity by mass spectrometry - for a specific batch at the time of testing. It does not measure sterility or endotoxins unless those tests are explicitly included, and it makes no claim about safety. These are research-use-only materials, and a clean purity sheet answers only what the sample contained, not how it may be handled or used.
Is a missing chromatogram enough to call a CoA fake?
Not by itself, but it is a serious weakness. The chromatogram is the actual evidence behind a purity percentage; a bare number is only a summary that is trivial to fabricate. A missing trace means the central claim cannot be checked. Combined with an unnamed lab or a dead verification code, it moves a document from weak to untrustworthy.
How can I verify a CoA myself without lab equipment?
Check four things you can confirm from a phone or laptop: that the lab is named and actually exists, that the batch number matches the vial, that any verification code resolves on the lab's own domain rather than the vendor's, and that the PDF metadata is consistent with a lab origin. Each check is free, and a document that fails several of them should be treated as unverified.
Why do some vendors only share a CoA by email after purchase?
It removes the one thing that makes a CoA meaningful: independent, at-the-source verification. When a certificate exists only as a file the seller emails you, there is no way to confirm it came from the lab it names or that it describes the batch you received. Transparency is a documentary property, and a result you can only see through the seller has not really been verified. The PeptideTrust methodology weights source-verifiable, batch-level CoAs accordingly.
See the full scoreboard → 11 vendors ranked by CoA transparency.

Related guides