A consumer scans a code on a bottle of perfume and sees a green tick with the word "Verified". What, exactly, was verified? The paper of the label? The number in the code? The bottle? The words verification and authentication are used as if they meant the same thing, and that confusion is where most overclaiming in brand protection starts.
This guide separates the two, sets out the levels of assurance that lie between "the code scanned" and "this item is genuine", and suggests how to describe each level honestly.
Two words, two questions
Verification answers a question about a code or an identifier. Is it printed well enough? Is the number valid? Does this serial exist in our records? These are questions about data, and they can be answered precisely.
Authentication answers a question about a physical item. Is the bottle in this person's hand the one the brand made, rather than a copy, a refill or a tampered pack? That is a question about the real world, and data can only ever be evidence towards it.
The two are connected. Good verification is usually the first step in authentication. But a code is just printed data, and anyone can photograph and reprint it, so passing every data check does not make an item genuine. We explain that copying problem in detail in why a QR code does not automatically prove authenticity.
Three things people mean by "verification"
The glossary entry for verification notes that the word has more than one meaning. In practice there are three, and a programme should always say which one it means.
Print-quality verification
On a packaging line or in a quality lab, "verified" means a barcode has been graded against ISO/IEC 15415 (2D codes) or ISO/IEC 15416 (linear barcodes). For retail checkout, GS1 sets a minimum grade of 1.5 (C). This tells you the code will scan reliably. It says nothing about who printed it. See why "printed" is not the same as "verified".
Identifier verification
Here "verified" means the number is real. Verified by GS1 can confirm that a GTIN is correctly structured, was issued through GS1 and is licensed to a particular company. The GS1 Web Vocabulary also defines a link type, gs1:verificationService, which a resolver can point to; it is for checking the status of an identifier. Neither service sees the physical item, and GS1 defines no link type that claims to prove authenticity.
Record verification
In brand programmes, "verified" often means the brand's own system recognised the code: the serial number exists, belongs to this GTIN and batch, and is active rather than recalled or destroyed. This is stronger than identifier verification because only the brand holds the list of real serials. It is still a check on data.
What authentication asks
Authentication is establishing whether the physical item is genuine. Counterfeiters do not need to invent anything to defeat a data check. They can:
- copy the code from one genuine pack onto many fakes;
- refill genuine, used packaging with something else;
- move labels or caps from genuine goods to fakes;
- buy genuine codes that leaked from a print shop or a scrapped production run.
Each of these produces a pack whose code passes verification. Authentication therefore needs evidence that is harder to copy than printed data: patterns in scan history, information the counterfeiter cannot see, and properties of the physical pack and its contents.
The levels of assurance
The most useful way to think about authentication is as a ladder. Each level adds a check, and each check defeats a more capable counterfeiter. No level is absolute.
| Level | What is checked | Who can usually check it | What it rules out | What it cannot rule out |
|---|---|---|---|---|
| Baseline: the code scans | The pattern can be decoded | Anyone with a phone | Nothing about the product | Everything |
| 1. Identifier valid | The GTIN is well formed and licensed to the brand; the identifier's status is active | Anyone, via public lookups | Invented or misused product numbers | An exact copy of a genuine pack's identifier |
| 2. Known serial | This serial exists in the brand's records, matches the GTIN and batch, and is active | Anyone scanning into the brand's system | Invented serials (if serials are random), codes from rejected or destroyed stock | An exact copy of one real serial |
| 3. First or expected scan | The serial's scan history fits one physical unit: first scan, few scans, in the market it was shipped to | The brand's server, applied to every scan | Mass copies once they are scanned; impossible travel; stock far outside its intended market | The first scan of a copy, or a copy scanned before the genuine pack |
| 4. Hidden second factor | A value not visible from outside (under a scratch-off panel, inside a cap or carton) matches the outer code | Consumers and trade partners after opening or purchase | Copies made by photographing the outside of the pack | Leaked or harvested hidden values; insider copying |
| 5. Physical or forensic | Tamper evidence, security print features, pack construction and contents, compared with genuine reference samples | Trained inspectors, investigators, laboratories | Most fakes, depending on the features and the examination | Little, but it is slow, costly and done one item at a time |
Two things follow from this table.
First, levels 2 and 3 rely on serialization. Without a unique, random serial on every unit, the brand cannot tell one pack's scan history from another's, and level 3 is impossible. That is why what is product serialization? is a prerequisite for most authentication programmes.
Second, level 3 is a detection level, not a prevention level. It turns copies into anomalies that the brand can see, such as one serial scanned in three cities in a day. It does not stop the first copied scan looking normal, and it cannot tell which of two identical scans came from the genuine pack.
A worked example: one bottle, five checks
Maison Ardent, a fictional perfume house, prints a random serial in a QR code on every carton and places a second, hidden code inside the cap collar. A shopper buys a bottle from a market stall and scans it.
- Identifier valid. The GTIN belongs to Maison Ardent. Of course it does: the code was copied from a real carton.
- Known serial. The serial exists and is active. Again, copied.
- First or expected scan. The page says the code was first checked nine days earlier, in a city in another country, and asks where the shopper bought it. This is a signal, not a verdict. The shopper might hold the copy, or might hold the genuine bottle whose code was copied by someone else.
- Hidden second factor. The page invites the shopper to enter the code from inside the cap collar. There is no collar code. That is strong evidence this bottle is not genuine.
- Physical and forensic. Maison Ardent's brand-protection team makes a test purchase from the same stall. An inspector compares the bottle, cap and print with reference samples and confirms a counterfeit.
No single check proved anything. The combination of a scan pattern, a missing hidden factor, a consumer report and a physical examination did.
Say what was checked
The wording on a scan result page is part of the control. Overclaiming backfires twice: a copied code earns the same reassuring message, and a genuine buyer who sees a false alarm loses trust.
| What the system actually checked | Honest wording | Avoid |
|---|---|---|
| Identifier valid only | "This is a registered Maison Ardent product number." | "Genuine product" |
| Known serial, first scan | "This code is registered to us and this is its first check." | "100% authentic" |
| Known serial, scanned before | "This code has been checked before. If you have just bought this product, please tell us where." | "FAKE" |
| Hidden factor matches | "The hidden code matches this pack's outer code." | "Guaranteed genuine" |
How to design the messages for each state, including suspicious ones, is covered in how serialized QR codes support anti-counterfeit programmes.
Matching the level to the product
Not every product needs every level. A sensible programme starts from the risk:
- Low-value, low-risk goods may need only levels 1 and 2, mainly to stop invented codes in a promotion.
- Products that are often copied, such as fragrances, cosmetics, lubricants or electrical goods, usually justify level 3 monitoring and, where buyers are motivated to check, a level 4 hidden factor.
- High-risk or high-value products, or products where a fake could harm someone, add physical security features and a standing investigation process, so that level 5 examinations follow quickly when the data raises an alarm.
The levels also serve different people. Consumers need a quick answer and a clear next step. Retailers and distributors need confidence at goods-in. Brand-protection teams need patterns across thousands of scans, which is where consumer scans as channel and diversion signals come in.
How this fits with product identity
Authentication sits on top of product identity; it does not replace it. The same GTIN and serial in a QR code can lead to product information, loyalty and warranty services as well as authenticity checks. Keeping identity stable and treating authentication as a separate set of rules means you can tighten those rules later, such as adding a hidden factor or changing thresholds, without reprinting the identity on every pack.
See how serialized codes and scan rules support product authentication