Counterfeit products can harm a brand's reputation, reduce genuine sales and expose buyers to products that may be ineffective, defective or unsafe.
This risk affects pharmaceuticals, food and beverages, electronics, cosmetics, automotive parts, agricultural products and many other categories. Counterfeit packaging has also become more convincing, so appearance alone may not be enough to separate a genuine product from a copy.
QR code product authentication gives brands a practical way to connect a physical product with a secure digital record. A consumer, retailer or supply-chain team can scan the code with a smartphone and check whether the product identity exists in the manufacturer's system.
Counterfeit products can harm a brand’s reputation, reduce genuine sales and expose buyers to products that may be ineffective, defective or unsafe.
This risk affects pharmaceuticals, food and beverages, electronics, cosmetics, automotive parts, agricultural products and many other categories. Counterfeit packaging has also become more convincing, so appearance alone may not be enough to separate a genuine product from a copy.
QR code product authentication gives brands a practical way to connect a physical product with a secure digital record. A consumer, retailer or supply-chain team can scan the code with a smartphone and check whether the product identity exists in the manufacturer’s system.
An ordinary QR code, however, does not automatically protect a product. For authentication to work, the code must be unique, securely generated, connected to a controlled database and monitored for unusual activity.
QR code product authentication assigns a scannable digital identity to a product or package. The system then checks that identity against an authorised database.
When someone scans the code, the system may check:
· Whether the code exists
· Whether it belongs to the expected product
· Whether it has been activated
· Whether it has already been scanned
· Where earlier scans took place
· Whether it has expired or been deactivated
· Whether the related batch was recalled
· Whether the scan pattern looks suspicious
Based on those checks, the user may see a message such as:
· Product verified
· First successful scan
· Code previously scanned
· Invalid code
· Product recalled
· Product expired
· Verification unavailable
· Further investigation required
This gives the user more useful information than a standard barcode that identifies only the general product type.
A QR code is a two-dimensional, machine-readable pattern that stores or represents digital data.
A smartphone camera or scanner reads the pattern and opens the linked information. Depending on the setup, the code may:
· Open a website
· Display product details
· Connect to an authentication page
· Register a warranty
· Confirm a loyalty reward
· Show batch information
· Record a supply-chain event
· Provide usage instructions
The QR image is only the carrier. The actual security comes from the identity behind the code and the way the supporting platform verifies and manages it.
Not every QR code offers the same level of protection.
A static QR code sends every user to the same webpage or piece of information. For example, every pack may carry the same code linking to the brand’s website.
Static QR codes work well for:
· Product information
· Instructions
· Marketing campaigns
· Customer-support pages
· Promotional content
Their authentication value is limited because a counterfeiter can photograph the code and print the same image on copied packaging.
A serialized QR code represents a unique identity assigned to one product or a defined packaging unit. Each code should be different.
This allows the platform to separate one pack from another and identify activity such as:
· Duplicate scans
· Invalid identities
· Unexpected scan locations
· Codes scanned before dispatch
· Excessive verification attempts
· Products appearing outside authorised markets
For this reason, serialized QR codes are more useful for product authentication and anti-counterfeiting programmes.
A dynamic QR code allows the digital destination or content to be changed without printing a new physical code.
This can be useful for campaigns and content updates, but dynamic functionality is not the same as serialization. A dynamic code is not automatically unique or secure. Brands still need controlled identities, database checks and scan monitoring.
A QR code cannot physically stop someone from copying a box or label. Its value comes from making each product identity easier to check and suspicious behaviour easier to spot.
A brand can assign a unique code to each product during manufacturing or packaging.
That identity may be connected to:
· Product name
· Stock-keeping unit
· Batch number
· Manufacturing date
· Expiry date
· Production facility
· Destination market
· Distributor
· Warranty status
This creates an item-level record that authorised users can check later.
The serial numbers should also be difficult to predict. Simple sequences make it easier for counterfeiters to guess or generate apparently valid codes.
Consumers and channel partners can scan the QR code with a smartphone. The verification page then checks whether the identity matches an authorised product record.
This makes basic verification possible without specialist equipment and supports checks at several stages, including:
· Distributor receipt
· Retailer onboarding
· Product delivery
· Warranty registration
· Consumer purchase
· Returns inspection
The result should say clearly what has been verified. A generic message such as “Thank you for scanning” should never be presented as proof that a product is genuine.
A counterfeiter may copy one genuine QR code and print it on many fake packages.
The first copied package may still show a valid response if nobody has scanned the original code. Once the same identity appears repeatedly, however, the system can detect an unusual pattern.
It may flag:
· A high number of scans
· Scans from distant regions within a short period
· Repeated scans from unrelated devices
· Scans from markets where the product was never distributed
· A code scanned before official activation
A repeated scan does not prove that a product is fake. A genuine owner may scan the same pack more than once. Brands should review the time, location, frequency and distribution history before deciding what the scan means.
Brands can also use QR codes to record selected events as products move through the supply chain.
These events may include:
· Code generation
· Printing
· Packaging
· Aggregation
· Dispatch
· Warehouse receipt
· Distributor transfer
· Retail receipt
· Consumer authentication
· Product return
· Recall
· Decommissioning
This history can help a brand see where an unusual product or code first appeared.
A track-and-trace solution can connect serialized identities with manufacturing and distribution events.
Consumers can become an extra verification point when the scan process is easy to understand and quick to use.
A scan may help someone:
· Confirm basic product information
· Check whether the code is valid
· See whether it has been scanned before
· Review manufacturing or expiry details
· Report a suspicious product
· Contact the brand
· Register a warranty
The page should load quickly, work well on mobile devices and support the languages used in the target market.
Scan activity can also give brands useful operational information.
Subject to consent, privacy rules and system design, combined scan data may show:
· Markets with frequent invalid-code scans
· Regions with duplicate-code activity
· Unauthorised distribution
· Consumer engagement patterns
· Products scanned outside expected territories
· Possible diversion routes
Investigation teams can use these patterns to decide where to sample products, inspect channels or take enforcement action.
A reliable system needs cooperation between packaging, manufacturing, software, supply-chain and brand-protection teams.
Before creating codes, decide what the system needs to achieve.
Common objectives include:
· Consumer authentication
· Distributor verification
· Counterfeit detection
· Warranty activation
· Supply-chain traceability
· Market diversion detection
· Recall communication
· Loyalty programme participation
The objective will shape the code format, verification process and data requirements.
Each product or packaging unit should receive its own identity.
The code-generation process should:
· Prevent duplicates
· Avoid predictable sequences
· Restrict unauthorised access
· Record when each code was generated
· Link each code to the correct product
· Support activation and deactivation
· Maintain an audit trail
Codes should not be treated like ordinary packaging artwork that can be copied from one file to another.
The database should contain the authorised product record and its current status. Access should depend on the user’s role and responsibilities.
Useful security controls may include:
· Encryption
· User authentication
· Access logs
· Database backups
· Rate limiting
· Anomaly detection
· Secure application programming interfaces
· Regular vulnerability testing
The right setup depends on the sensitivity of the product, system and data.
A valid code is useful only when people can scan it throughout manufacturing, distribution and use.
Print-quality checks should cover:
· Contrast
· Code size
· Quiet zone
· Resolution
· Surface curvature
· Label position
· Ink spread
· Packaging material
· Expected scanning distance
· Environmental exposure
A code may be correct in the database but still fail in practice if poor printing or placement makes it unreadable.
A business may activate codes when they are:
· Printed
· Applied
· Packed
· Quality approved
· Dispatched
The timing should match the actual operating process.
Codes that were created but never used should not remain valid. Unused, damaged and rejected codes must be reconciled and deactivated.
The verification page should use the brand’s verified domain and explain the result in simple language.
A successful response may show:
· Product name
· Product image
· Pack size
· Batch number
· Manufacturing date
· Expiry date
· First-scan status
· Verification time
· Customer-support details
When a code is invalid or suspicious, the page should tell the user what to do next.
At the same time, it should not reveal sensitive information that could help counterfeiters recreate valid identities.
An authentication system needs regular monitoring after launch.
Brands should create alerts for:
· Invalid codes
· Duplicate scans
· Unusual scan volumes
· Unexpected countries or cities
· Scans before production
· Scans after deactivation
· Codes linked to recalled products
· Automated scanning attempts
Each alert should connect to a defined investigation process. Collecting scan data without reviewing it provides little protection.
Teams need a clear process for dealing with suspicious activity.
This may involve:
1. Reviewing the scan history
2. Confirming production records
3. Checking distributor movement
4. Requesting product photographs
5. Purchasing samples from the market
6. Inspecting physical security features
7. Conducting laboratory or forensic analysis
8. Informing relevant channel partners
9. Reporting confirmed cases to the authorities
Technology can identify an unusual pattern. Trained people still need to investigate and decide what it means.
A QR code can be printed on a tamper-evident label that changes or leaves a visible sign when someone tries to remove or transfer it.
Possible formats include:
· Destructible labels
· VOID labels
· Full-transfer materials
· Partial-transfer materials
· Frangible seals
· Tamper-evident holograms
Where appropriate, the label can be placed so that opening the package or removing the label damages the code or changes its appearance.
The two features serve different purposes:
· The QR code checks the digital identity
· The label material helps show physical interference
Tamper evidence cannot prove that a package was never opened. It tells the user that interference may have occurred and that the pack needs closer inspection.
A QR code hologram combines a machine-readable digital feature with visible optical authentication.
The hologram may contain:
· Brand-specific optical effects
· Microtext
· Hidden images
· Demetallised areas
· Serial numbers
· Tamper evidence
· Covert features
This gives different users different ways to check the product:
· Consumers can scan the QR code
· Retailers can inspect visible holographic effects
· Investigators can examine covert or forensic features
· Brands can review scan and distribution data
Read how hologram stickers with QR codes can support authentication, warranty and loyalty functions.
Brands comparing the two methods can also review hologram labels versus QR-code authentication.
| Feature | Traditional product barcode | Serialized authentication QR code |
| Main purpose | Product and inventory identification | Item-level verification |
| Identity | Often shared by the product type | Unique to each unit |
| Smartphone scanning | Sometimes supported | Commonly supported |
| Duplicate detection | Usually limited | Possible through database monitoring |
| Consumer verification | Limited | Can provide current verification status |
| Scan-location analysis | Usually unavailable | Can be recorded where permitted |
| Digital content | Limited | Can provide detailed product information |
| Counterfeit detection | Limited on its own | Stronger when securely implemented |
Traditional barcodes remain useful for retail and logistics. They simply perform a different job from serialized authentication codes.
The QR image itself is not secure. Someone can photograph it, copy it or use a fake code that opens a fraudulent website.
Security comes from the complete system, including:
· Unique and unpredictable identities
· Controlled code generation
· Secure printing
· A verified domain
· A protected database
· Duplicate-scan monitoring
· Tamper-evident integration
· Physical security features
· Investigation procedures
Brands should not describe an ordinary QR code as counterfeit-proof.
Yes. Counterfeit packaging may carry:
· A copied genuine QR code
· A newly created QR code
· A code linking to a fake verification website
· A code sending users to the brand’s public homepage
· A code copied from another product
Consumers should check that the scan opens the manufacturer’s correct domain and provides a product-specific result.
Brands can reduce the risk through customised security labels, verified domains, unpredictable serial identities and clear instructions for consumers.
No. A QR code authentication system can work without blockchain.
A well-managed central database can support product verification, serialization and traceability.
Blockchain may be useful when several independent organisations need a shared record and the governance model supports it. Even then, blockchain does not automatically:
· Prove that the physical product is genuine
· Prevent incorrect information from being entered
· Stop people from copying a QR code
· Replace tamper-evident packaging
· Remove the need for audits
The physical product, its digital identity and the recorded events must still remain correctly connected.
Serialized codes may support:
· Pack authentication
· Batch verification
· Expiry checks
· Recall communication
· Distributor verification
· Supply-chain traceability
A QR code does not replace regulatory testing, quality controls or professional medical verification.
QR codes may help verify:
· Spare-part identity
· Manufacturing batch
· Warranty eligibility
· Authorised distribution
· Installation records
Brands may use serialized codes for:
· Component verification
· Warranty registration
· Service history
· Distributor checks
· Duplicate-code monitoring
QR codes can provide:
· Source information
· Batch details
· Manufacturing information
· Recall alerts
· Consumer engagement
Authentication claims should remain separate from broader quality or food-safety claims unless those claims are supported by suitable controls.
A verification scan may show:
· Product identity
· Batch details
· Expiry information
· Usage instructions
· Authorised seller guidance
QR code authentication may support products such as:
· Chemicals
· Lubricants
· Seeds
· Fertilisers
· Tools
· Machine components
· Safety equipment
Most modern smartphones can scan QR codes without specialist equipment.
Brands can print QR codes on labels and packaging through established variable-data printing processes.
The full cost still depends on the software, integration, code volume, monitoring and support required.
Unique codes allow brands to distinguish one unit from another instead of identifying only the general product type.
The system can change a product’s status after a recall, expiration, code deactivation or detected anomaly.
A clear verification process can help buyers make better-informed decisions.
The brand should still avoid claiming that every valid scan proves authenticity beyond doubt.
The same serialized identity may support:
· Authentication
· Warranty registration
· Loyalty rewards
· Product information
· Customer support
· Recall communication
Marketing features should be designed carefully so they do not weaken the authentication process.
A shared code cannot separate genuine units from packaging that has copied the same image.
Opening the brand’s homepage proves only that the QR code contains that website address.
Counterfeiters may generate apparently valid codes when the numbering pattern is easy to understand.
The system cannot detect suspicious behaviour when scan data is collected but never reviewed.
Codes printed on damaged packaging, rejected labels or production waste must be reconciled and deactivated securely.
A copied genuine code may show a valid result the first time it is scanned.
Products with higher risks should combine QR verification with tamper evidence, secure holograms or covert security features.
Slow pages, unclear messages and unnecessary registration steps discourage people from checking products.
Veritech provides physical and digital solutions that connect products with secure identities and controlled verification records.
Depending on the product, packaging and level of risk, the solution may include:
· Unique serialized QR codes
· Product authentication software
· Variable-data printing
· Security barcode labels
· QR code holograms
· Tamper-evident labels
· Secure holograms
· Track-and-trace integration
· Packaging aggregation
· Duplicate-scan detection
· Consumer verification interfaces
Veritech’s product authentication and verification solution can help brands create a controlled digital verification process for products and packaging.
For a wider layered strategy, explore Veritech’s anti-counterfeiting solutions.
Unique QR codes allow brands and buyers to check product identities against an authorised database. The system can also identify duplicate, invalid or geographically unusual scans.
Not always. A standard QR code may simply open a webpage. Product authentication requires a unique code linked to a secure product record.
A serialized QR code represents a unique identity assigned to one product or a defined packaging unit.
Yes. Anyone can copy the visible image. Unpredictable identities, duplicate-scan monitoring and physical security features help brands identify or reduce this risk.
The system records the repeated scan and can review its time, location and frequency. A second scan alone does not mean the product is fake.
It should show a clear verification status and useful product details without exposing information that could help counterfeiters reproduce valid identities.
A static code has a fixed destination. A dynamic code allows the destination or content to be updated. Neither type is automatically unique or secure.
No. Many systems use a mobile webpage that opens directly after the user scans the code.
Yes. A serialized QR code can connect to manufacturing and distribution records when supply-chain participants scan it at defined checkpoints.
They serve different purposes. QR codes support digital verification and data collection, while holograms provide visible physical authentication. Using both can create stronger protection.
No. Blockchain may protect selected digital records, but it cannot stop someone from copying the QR image or the surrounding packaging.
The right solution depends on the product, risk level, packaging surface, distribution model and people who need to verify it. Higher-risk products usually need serialization, a secure database, active monitoring and layered physical security.
