How to verify a peptide COA — and spot a fake.
Forged certificates of analysis are not rare. They circulate in group buys, they get re-branded from one company to another, and entire look-alike websites exist to “verify” documents the real lab never issued. The fix is simple and takes thirty seconds — but you have to know where to look, because a PDF can never vouch for itself.
Step 1 — find the certificate ID
Every genuine third-party certificate carries a unique identifier tied to one physical sample. On a KMD Analytical certificate it's the ID printed on the document and encoded in the QR code (see the sample certificate for where it lives). No certificate ID at all — just a compound name and a purity number — is the first and loudest red flag.
Step 2 — verify on the lab's own site, never from the PDF
Type the certificate ID into the issuing lab's public verification page. For KMD certificates that's kmdanalytical.com/verify— anyone can use it, no account needed. A genuine ID returns the certificate's issue date, product, and cryptographic fingerprint; an unknown or altered document returns NOT VERIFIED, with no false positives.
Check the domain while you're there.A verification page is only meaningful on the lab's real website. Look-alike domains with an extra hyphen or different ending exist specifically to “confirm” forged documents — our only domain is kmdanalytical.com, and a certificate “verified” anywhere else was not verified by us.
Step 3 — understand what the seal proves
A sealed certificate is fingerprinted with SHA-256: a hash computed from the exact bytes of the issued PDF. Alter anything — a purity digit, a date, a company name — and the fingerprint changes completely, so the verification page flags the document as altered. When the hash matches, you know two things at once: the certificate ID is real, and the file in your hands is byte-for-byte the one the lab issued.
The red flags forged COAs keep showing
- No verification path. The issuing lab has no public page where the certificate can be checked.
- No chromatogram. A purity claim with no trace behind it is a number typed into a template.
- Uniform, too-good numbers. Every vial 99.9%, every batch identical. Real results vary.
- A missing or absurd retention time.The chromatographic details are where forgers get lazy — a “main peak” with no retention time, or one that contradicts the visible trace.
- The certificate is issued to nobody.A real cert names the submitter. Re-branded certificates — one company's results wearing another's name — are a known laundering pattern.
- The lab is unreachable. No phone, no address, no reply. A real lab answers questions about its own certificates.
If the lookup fails
Don't argue with the seller about it — go to the source. Contact the lab using the details on the lab's own website and ask them to confirm the certificate ID. We answer these inquiries directly (they're how more than one forgery has been caught), and any serious lab will do the same.
Frequently asked questions
How do I check if a peptide COA is real?
Verify it on the issuing lab's own website, never from the PDF alone. A genuine certificate carries a certificate ID you can enter on the lab's verification page; if the lab has no public way to confirm its own certificates, the document is only as trustworthy as whoever emailed it to you.
What does the SHA-256 seal on a COA mean?
It's a cryptographic fingerprint of the exact PDF the lab issued. Change anything in the file — one digit of purity, one letter of a name — and the fingerprint no longer matches, so the lab's verification page reports the document as altered. A matching hash means you're holding the same bytes the lab sealed.
What if the certificate ID isn't found on the lab's site?
Treat the document as unverified. Either it was never issued by that lab, the ID was mistyped, or the certificate was fabricated using the lab's branding. Contact the lab directly through the contact details on their website — not the ones printed on the PDF, which a forger controls.
Can a vendor's in-house COA be trusted?
An in-house COA reports what the seller says about their own product. It can be honest, but it isn't independent — the value of third-party testing is that the lab has no stake in the result. For any purchase that matters, look for a certificate from an independent lab, issued to a named submitter, that you can verify yourself.