Fake cannabis COAs, the quick checks that catch most scams (QR codes, lab IDs, batch info)

MJP Editors
11 Min Read

A Certificate of Analysis should be the product’s “receipt from the lab.” It tells you what’s in the jar, what’s not in it, and who tested it. When that paperwork is real, it builds trust. When it’s fake, it’s just a costume.

In 2025, counterfeit and misleading lab reports keep showing up across legal and gray markets. Some are sloppy. Others look polished enough to fool busy shoppers, budtenders, and even small brands moving fast. The good news is that most fake cannabis COA attempts break under a few quick checks.

This guide focuses on fast, practical verification steps you can do in under two minutes, plus a simple SOP section for dispensaries and brands.

What a COA is supposed to prove (and what it can’t)

A real COA ties one specific batch of product to one specific lab test. It usually includes potency (THC, CBD), and safety panels like pesticides, heavy metals, residual solvents, microbials, and mycotoxins (exact panels vary by state or country).

Rules aren’t the same everywhere. COA layout, required analytes, and even naming conventions can change by jurisdiction. Many U.S. states require batch testing before retail sale, but the details differ, and regulators update rules often. If you want an example of how a state frames lab testing and listings, California’s Department of Cannabis Control maintains a page for state-licensed testing laboratories.

A COA also has limits. It doesn’t prove perfect storage, shipping, or that the item in your hand wasn’t swapped. That’s why matching identifiers matters so much.

The fastest way to spot a fake cannabis COA: the 60-second triage

Close-up illustration of a hand holding a smartphone scanning a QR code on a cannabis COA document, with split screen showing successful verification versus fake scan warning.
Phone-based QR verification on a COA, showing “real vs fake” outcomes, created with AI.

Think of a COA like a passport. You don’t start by reading every line. You start by checking the photo, the stamp, and the number.

Here are the three checks that catch most scams.

1) QR code: where does it really go?

A QR code is useful only if it resolves to a page you can trust.

Quick checks

  • Scan the QR and look at the full domain (not just the page design).
  • Prefer the lab’s official domain or a known lab portal the lab controls.
  • Watch for shortened links (bit.ly-style) that hide the destination.
  • Watch for lookalike domains, like extra hyphens, swapped letters, or odd endings.

Red flags

  • The QR goes to a Google Drive PDF, random file host, or a parked domain.
  • The QR opens a page with no lab contact info, no test method notes, or no report verification tools.
  • The QR works once, then redirects somewhere else later.

If you’re unsure, don’t trust the QR alone. Go to the lab’s official website through your browser and look for their COA verification page, then compare what you see.

2) Lab identity: does this lab exist, and are they authorized where you bought it?

A fake report often borrows a real lab name, or invents one that sounds legit.

What to confirm

  • Lab name, address, phone, and website are consistent.
  • Lab license ID (or state registration number) is present if your market uses one.
  • Accreditation info is plausible (many labs list ISO/IEC 17025).

How to verify fast

  • Check the lab’s official website and look for a “Report Verification” or “COA Lookup.”
  • Cross-check the lab in your state regulator’s listings when available (again, requirements vary).

In 2025, enforcement and recalls tied to testing problems have pushed more retailers to tighten COA checks, and more scammers to get creative. Staying calm and checking the basics beats guessing.

3) Batch, lot, and sample info: do the numbers match the product?

This is the part scammers hate, because it’s hard to fake consistently across packaging, invoices, and portals.

Look for these identifiers and make sure they line up with the label:

  • Batch/Lot number (on the jar or box and on the COA)
  • Sample ID (the lab’s internal identifier)
  • Product name and type (flower, pre-roll, vape, edible)
  • Package size (1 g cart vs 0.5 g cart errors are common)
  • Production date, packaged date, or UID fields (where used)

If the COA shows a different product type than what you’re holding, treat it as a mismatch, even if the THC number looks “close.”

A quick reference table (save this for training)

CheckWhat “good” looks likeCommon scam tell
QR codeResolves to lab-controlled page, stable domainShort link, file host, lookalike domain
Lab IDLab appears on official site and regulator list (if applicable)Missing license ID, no real contact info
Batch matchBatch/lot on packaging matches COACOA has generic or blank batch fields
DatesLogical timeline (received, tested, reported)Dates missing or oddly identical
PanelsRequired panels for that product typeSafety sections missing or copied

COA details that don’t pass the “sniff test” (even if the QR works)

Scammers know people look at THC first. So you also want a few reality checks that take seconds.

Dates and timelines that don’t make sense

A normal COA shows a flow: sample received, testing date(s), report date. A fake cannabis COA may show:

  • All dates identical, with no received date
  • A report date that predates the sample receipt
  • A batch “tested” long after the product was supposedly sold

Potency that reads like a billboard

Unusually high THC isn’t automatically fraud, but it should trigger a pause. If every strain is “top shelf” numbers with perfect round decimals, ask for verification through the lab portal and confirm the batch.

In 2025, potency inflation and testing integrity are hot topics in the broader discussion on cannabis regulation and reform. For more context on why testing disputes keep surfacing, Undark’s reporting on cannabis testing reform is a useful background read.

Missing panels, vague methods, or copy-paste formatting

A legitimate COA usually includes methods, LOQ/LOD notes, and clear pass/fail language where required. Red flags include:

  • Contaminant panels shown as blank, “ND” everywhere, or missing entirely
  • Fonts and spacing that change mid-page, like it was stitched together
  • No page numbers on multi-page reports, or no analyst/lab sign-off

For a deeper list of common red flags, Adams Independent Testing has a clear guide on how to tell if your COA is fraudulent.

For dispensaries and small brands: a simple COA SOP that holds up in 2025

If you stock products or ship wholesale, treat COA checks like receiving inventory, not like reading marketing.

Acceptance checklist (what staff should verify before intake)

  • COA matches SKU, product type, and package size
  • Batch/lot on COA matches packaging and manifest paperwork
  • QR resolves to a lab-controlled domain (no short links)
  • Lab is authorized for the jurisdiction of sale (where listings exist)
  • Required panels are present for that category in your market
  • Dates look reasonable and consistent

Vendor validation (set it once, then re-check on a schedule)

  • Keep a list of approved labs and vendor contacts
  • Confirm lab identity through the lab’s official website, not emailed links
  • Re-validate labs quarterly, or after any recall news in your state
  • Consider spot re-testing for high-risk categories (vapes, concentrates)

Recordkeeping that saves you during audits

  • Store COAs by batch/lot, not just by brand name
  • Keep the URL used for verification (screenshot helps)
  • Document who verified, when, and what they checked

Conclusion

Fake paperwork works only when people feel rushed. A fake cannabis COA usually falls apart when you verify the QR destination, confirm the lab’s identity where you bought it, and match batch details to the package. Those three checks stop most scams without turning shopping into detective work.

If something doesn’t match, pause the purchase or pause intake, then verify using the lab’s official site and regulator listings where available. Trust is earned in small steps.

Printable mini-checklist (COA scam quick checks)

  • QR code resolves to a lab-controlled domain (no short links)
  • Domain spelling looks right (no lookalike or odd endings)
  • Lab name and contact info match the lab’s official website
  • Lab is listed by the state regulator (where applicable)
  • Batch/lot on COA matches the product label exactly
  • Sample ID is present (not blank or generic)
  • Dates follow a logical order (received, tested, reported)
  • Required safety panels are included for this product type
  • COA file looks consistent (no obvious copy-paste formatting)
  • If still unsure, ask for lab portal verification or request a re-test

Share This Article