Skip to main content
Brands & ManufacturersPrinter Partners
GCC / EN:UAE/KSA/QA/KW/OM/BH
AIQR LogoFree GS1 QR codes

Authentication & engagement

How Serialized QR Codes Support Anti-Counterfeit Programmes

A step-by-step view of designing an anti-counterfeit programme around serialized QR codes, from threat model and factory to scan rules and honest warnings.

Updated 6 min readintermediate

The short answer

Serialized QR codes give every genuine unit its own identity, so the brand can see each code's scan history and spot copies as anomalies. A working programme surrounds the code with a clear threat model, factory controls that activate only properly printed codes, server-side scan rules, honest consumer messages for every result, and a team that investigates what the data flags.

  • Start with how your products are actually faked; the threat decides which controls are worth paying for.
  • Only codes that were printed and checked on the line should ever become active; rejects and leftovers must be cancelled.
  • Scan rules produce suspicion levels, not verdicts, so consumer messages must be calm, specific and helpful.
  • A programme without someone to investigate flagged scans is a dashboard, not brand protection.

A brand decides to fight counterfeits with QR codes. The codes go on the packs, consumers scan them, and a page says "genuine". Six months later a copied code is circulating on thousands of fakes, every one showing the same page. The codes were not the problem. The programme around them was missing.

This guide walks through how an anti-counterfeit programme built on serialized QR codes is designed from start to finish, including the part most brands skip: what to tell a consumer when a scan looks wrong.

Why serialization is the foundation

A single QR code printed on every pack of a product is one secret shared by millions of packs. Copy it once and you have copied it for all of them.

With serialization, each pack carries its own serial number, usually inside a QR code. In a GS1 Digital Link, the serial follows the product number in the web address (/01/ followed by the GTIN, then /21/ followed by the serial). Every scan now refers to one physical unit, and that changes the counterfeiter's problem: each copy duplicates one real pack, and duplicates leave a trail.

Serialization does not stop copying. It makes copying visible. Everything else in the programme exists to see that trail, interpret it fairly and act on it. For the underlying distinction between checking a code and proving an item, start with product verification vs authentication.

Step 1: Describe the threat you are facing

Different counterfeiting looks different in the data, so begin with how your products are actually faked:

  • Copied codes on lookalike packs. The classic case, and the one serialized scan rules are best at detecting.
  • Refilled genuine packaging. The code is genuine and was printed by you. Scan rules may see a second life for a serial; a seal or a hidden code inside the pack helps more.
  • Leaked codes. Codes stolen from a print supplier or scrapped stock. Factory controls matter most here.
  • Diversion of genuine goods. Not counterfeiting, but often discovered with the same data. See how consumer scans can reveal channel and diversion signals.

Write down which of these you expect, and in which markets. It decides whether you need a hidden second factor, physical security features, or simply good monitoring.

Step 2: Decide who will scan, and why

Scan rules only work on scans that happen. Consumers rarely scan just to check authenticity, so successful programmes give them other reasons: product information, usage guidance, a reward or a warranty. Retailers, distributors and field inspectors can be asked to scan at goods-in or during market visits.

The more genuine scans you collect, the faster copies stand out against normal behaviour.

Step 3: Design the code

A few design decisions are hard to change once packs are printed:

  • Random, non-sequential serials, so valid codes cannot be guessed.
  • A domain you control, so scans always reach your rules, even if your website or campaign changes.
  • Optional hidden second factor, such as a code under a scratch-off panel, inside the cap or inside the carton, which must match the outer code. It defeats copying by photograph, but values become copyable once revealed, so they should be accepted once.
  • Physical security features, if your threat model calls for them. These are a separate layer from the code and often what inspectors check during an investigation.

Step 4: Control the factory

Codes can leak or go wrong at the printer and on the packaging line, not only in the market. A sound programme makes a code active only when the line has confirmed it:

  • the serial is assigned from one authority, usually the ERP or a serialization platform;
  • the code is printed, then read by a camera to confirm it matches the expected serial;
  • confirmed codes are recorded as commissioned, and rejects or unused codes are cancelled so they can never appear "genuine" in the market.

Aggregation, which records which units went into which carton and pallet, adds a valuable link: each serial can be tied to the shipment and the market it was sent to. Read why "printed" is not the same as "verified" for the line-side detail, and what aggregation is for the packing side.

Step 5: Set the scan rules

The server applies rules to each serial's history. Typical rules include:

RuleWhat it looks forTypical response
Unknown codeSerial not found or never commissionedTreat as a possible fake or misprint; ask for details
First scanNo earlier scansRecord; show product information
Repeat, same contextRescan from a similar place soon afterNormal; show a gentle "checked before" note
Repeat, new contextRescan from a different region or long afterAsk where it was bought
High duplicate countMany scans of one serialFlag as probable copy; open a case
Impossible travelDistant places within a short timeFlag as probable copy
Outside intended marketScanned far from where it was shippedFlag for channel review
Inactive statusRecalled, cancelled or destroyed serialWarn; show recall or support information

Thresholds should reflect real behaviour. A family may scan a bottle several times; a shop may scan a demonstration unit dozens of times. Tune rules on real data and keep them private.

Step 6: Write honest messages for every result

Each rule needs a message, and suspicious results need the most care. False alarms hurt genuine buyers and retailers; false comfort helps counterfeiters. Good messages:

  • Say what was checked, not what was proved.
  • Ask rather than accuse. "Where did you buy this?" collects evidence; "This product is fake" may be wrong.
  • Offer a next step: a contact form, a support number, or how to return a product.
  • Ask only for the data you need, with consent. Precise location, a photo of the receipt or contact details should be optional and explained.

Example wording for a serial that has been scanned many times in other places:

"This code has been checked many times before, in several locations. That can mean the code has been copied. If you have just bought this product, please tell us where — it helps us investigate. You can also contact our support team."

This message is useful whether the person holds the copy or the genuine pack whose code was copied.

Step 7: Investigate and act

Flagged serials should open a case, not just colour a dashboard. A typical workflow groups related flags, adds consumer reports about where products were bought, checks the shipment history of the original unit, and decides on follow-up: a test purchase, a conversation with a distributor, a marketplace takedown request or, where justified, involving authorities.

Record the outcome of each case. Confirmed copies and false alarms both tell you how to tune the rules.

Step 8: Measure what matters

Useful measures include how many units are scanned at least once, how quickly copies are flagged after first appearing, how many flags turn out to be genuine products, and how many cases lead to action. Avoid quoting a "counterfeit rate" from scan data alone: scans are not a random sample of the market.

See how serialized codes and scan rules support product authentication

Frequently asked questions

How many scans does a programme need before it detects anything?

Detection depends on people scanning, so programmes that give buyers a reason to scan, such as product information, rewards or warranty, see copies sooner. A copied code that nobody scans stays invisible.

Should we publish our scan-rule thresholds?

No. Explain to consumers what a warning means and what to do next, but keep the specific thresholds and rules internal so counterfeiters cannot tune their behaviour around them.

Can we add serialized codes to an existing marketing QR programme?

Usually yes, by moving from one shared code per product to one code per unit. That requires variable-data printing and line checks, so it is a packaging-line project as well as a software change.

What if the genuine buyer is the one who sees the warning?

That can happen when a counterfeiter copied the code and scanned it first. It is one reason warnings should ask questions and offer help rather than declare the product fake.

Sources and further reading

Standards references last reviewed 1 October 2026.