Skip to main content
Brands & ManufacturersPrinter Partners
GCC / EN:UAE/KSA/QA/KW/OM/BH
AIQR LogoFree GS1 QR codes

Serialization

Why a QR Code Does Not Automatically Prove Authenticity

Any QR code can be copied in seconds. Learn why a scan alone can't prove a product is genuine, and which controls make anti-counterfeit programmes work.

Updated 5 min readbeginner

The short answer

Because a QR code is just printed data, and anyone can photograph and reprint it. A scan proves only that a code was read and, at best, that the identifier it carries is valid. Authenticity comes from what surrounds the code: unique serials, server-side scan rules that flag copies, hidden second factors, physical packaging security and follow-up investigations.

  • Copying a QR code is trivial; a perfect copy scans exactly like the original.
  • A valid GTIN, a working Digital Link or a 'verified' identifier status says the number is real — not that the item in your hand is.
  • Unique serials plus server-side rules turn copies into detectable anomalies, such as duplicate or geographically impossible scans.
  • Strong programmes layer digital checks with physical security features and human investigation.

Many brands add a QR code to their packaging and tell consumers to "scan to check it's genuine". It feels like a security feature. But a QR code is simply a pattern of printed squares, and anything printed can be copied. This article explains why a scan alone cannot prove a product is genuine — and what actually helps.

Copying is the easy part

A QR code stores data, usually a web address. Anyone with a phone can read that data, and anyone with a printer can print the same data in a new code. The copy is not a degraded imitation: it carries exactly the same content and scans exactly the same way.

So a counterfeiter does not need to break anything. They buy one genuine pack, photograph its code, and print it on a thousand fake packs. Every one of those fakes will open the same page as the original.

This applies equally to marketing QR codes, codes with a GS1 Digital Link and any other 2D barcode. The format describes what data is carried and how to read it; it is not a security mechanism.

What a scan actually tells you

It helps to separate three things a scan can establish, because they are often blurred:

What is checkedWhat it showsWhat it does not show
The code decodesThe printed pattern is readableAnything about the product
The identifier is validThe GTIN or serial exists and is correctly formed; it may be registered to the brandThat this physical item is the one that number was assigned to
The item is authenticThe physical product came from the brand— this needs more than a scan

Standards bodies are careful about this line. Verified by GS1 checks whether a number is properly structured, issued by GS1 and licensed to a particular company — it is about the number, not the item. The GS1 Web Vocabulary includes a link type, gs1:verificationService, that a resolver can point to; it is for verifying the status of an identifier, not the authenticity of a product. GS1 does not define a link type that proves authenticity.

We draw the full distinction between verification and authentication in product verification vs authentication.

What does help

No single control proves authenticity. What works is a set of layers, each making counterfeiting harder, riskier or easier to catch.

1. Unique, random serials

With serialization, every genuine unit carries its own serial number. That changes the counterfeiter's position: instead of copying one code that is legitimately printed on millions of packs, they must copy individual unit codes — and every copy is a duplicate of one real unit.

Serials should be random and non-sequential, so that valid ones cannot be guessed. Random serials do not stop copying; they stop invention. See what is product serialization?

2. Server-side scan rules

Because every scan reaches the brand's server, the server can apply rules to the scan history of each serial:

  • First-scan logic. The first scan of a serial is recorded; later scans of the same serial can be shown a different message ("this code has been scanned before — where did you buy it?").
  • Duplicate detection. One genuine pack is scanned a handful of times. A serial scanned hundreds of times is a strong sign it has been copied.
  • Geographic and time anomalies. The same serial scanned in two distant cities within a short window cannot be one physical pack.
  • Channel signals. Scans in markets a unit was never shipped to can reveal diversion. See how consumer scans can reveal channel and diversion signals.

Note the limit: these rules detect copies after they are scanned. The first scan of a copied code may look perfectly normal. That is why the response to a flagged scan matters as much as the flag.

3. A hidden second factor

Some programmes add something the counterfeiter cannot see by photographing the outside of the pack — for example, a second code under a scratch-off panel or inside the carton, which must match the outer code. A copied outer code without the matching hidden value fails. This raises the cost of copying; it does not make copying impossible, especially if hidden values are exposed at retail.

4. Physical packaging security

Tamper-evident seals, special inks, holograms and hard-to-reproduce printing can make the pack itself harder to fake. These are separate from the code, and they are often what inspectors and investigators check when a scan raises an alarm.

5. Investigation and enforcement

Data only matters if someone acts on it. Flagged scans should feed a process: review the pattern, test-purchase from the suspicious location, involve distributors or authorities. Many anti-counterfeit programmes succeed because they turn consumer scans into leads for investigators, not because any one scan is decisive.

A worked example

Maison Ardent, a fictional perfume house, prints a unique, random serial in a QR code on every bottle. A consumer in one city scans a bottle and sees the product page with "first verification of this code". Two days later, the same serial is scanned 140 times across three other cities.

The server flags the serial as a probable copy. Later scanners see a warning and are asked where they bought the product. Maison Ardent's brand-protection team sees most reports name one online seller, makes a test purchase, and confirms counterfeits.

Notice what happened. The QR code did not prove anything about any single bottle. The combination of a unique serial, a server watching the scan history, consumers reporting where they bought, and a team following up is what found the counterfeits. For how brands design these programmes, see how serialized QR codes support anti-counterfeit programmes.

How to talk about it honestly

What you tell consumers matters, both for trust and because overclaiming can backfire when a copied code shows "genuine".

  • Describe what the check does: "This code is registered to us and this is its first scan."
  • Explain what a warning means and what to do: where to report, how to get help.
  • Avoid wording such as "100% authentic" or "guaranteed genuine" next to a scan result.
See how serialized codes and scan rules support product authentication

Frequently asked questions

Can a QR code be made impossible to copy?

Not by its content alone, because its content is just data that a camera can read and a printer can reproduce. Some programmes combine codes with physical features that are hard to reproduce, but the code itself should be treated as copyable.

If the scan page says the code is valid and has not been scanned before, is the product genuine?

It means that serial had not been scanned before and is a valid, active unit in the brand's records. A counterfeiter who copies a code from a genuine pack before it is first scanned could still produce that result, which is why programmes also watch for later duplicates and other signals.

Does Verified by GS1 tell me whether a product is genuine?

No. Verified by GS1 confirms facts about the number — that it is correctly structured, issued by GS1 and licensed to a particular company. It cannot see the physical item.

Should we tell consumers a scan proves authenticity?

Avoid it. Say what the check actually does — for example, 'this code is registered and has not been scanned before' — and tell consumers what to do if they get a warning.

Sources and further reading

Standards references last reviewed 1 October 2026.