Manav.id
Regulated ยท 17 min read

The degree is real. The university is a mailbox.

Degree verification answers one question: was this credential issued? It does not answer whether the issuer was legitimate, or whether the person presenting it is the person who earned it. Digitising diplomas without fixing both gaps will make credential fraud cheaper rather than harder, because a perfectly signed fake is more convincing than a bad PDF.

Picture a screener at a background check vendor working through a queue. The candidate is applying for a clinical role. Attached to the file is a bachelor's degree from an institution with a reasonable name, the kind that sounds like it has a campus and a library and an athletics programme. There is a transcript as a PDF, a seal that renders correctly, and a registrar's email address on a domain that matches the institution's website.

The screener does what the process says to do. They check the institution against the list of recognised bodies. It appears. They send a verification request to the registrar. A reply comes back within two days confirming that the named individual graduated in the stated year with the stated qualification.

Everything checks out. The file is cleared. The candidate is hired.

Now consider four different ways that outcome could be wrong, because they are genuinely different problems requiring genuinely different remedies, and the industry collapses all four into the phrase "diploma mill" in a way that makes clear thinking almost impossible.

Short answer: To verify a degree properly you need three separate things, and today's checks provide only the first: that the credential was issued, that the issuer is recognised through a chain terminating in a body you actually trust, and that the person presenting it is the person who earned it. A credential that carries an accreditor to issuer chain and is presented from the holder's enrolled device closes all three.

What actually counts as a diploma mill?

The term is used for at least four distinct frauds. They fail different checks, so lumping them together guarantees that any control you deploy will miss most of them.

1. The forged certificate from a real institution

The oldest and simplest version. A real university, a fabricated graduate. The document is a lie about a legitimate issuer. This is the only variant that current verification reliably catches, because a call or query to the registrar returns no matching record. It is also the variant that generative document tools have made trivially easy to produce at high visual quality, which matters less than people assume, because visual quality was never what defeated this check.

2. The real certificate from an institution that exists only to sell them

The classic diploma mill. An entity that is genuinely incorporated, genuinely operates a website, genuinely maintains a registrar function, and genuinely issues credentials, to anyone who pays. Every fact it asserts about the credential is true. The candidate did receive this degree from this institution. What is false is the implication that the degree represents education. A registrar check passes cleanly, because there is a registrar and there is a record.

3. The real certificate from an institution with genuine but marginal accreditation

The uncomfortable middle. An institution that is accredited, by a body that exists and has procedures, but whose standards are weak or whose recognition is not accepted in the jurisdiction where the candidate is applying. This is not fraud at all in many cases. It is a quality and equivalence judgment, and it is the single largest source of contested outcomes in credential evaluation, particularly for qualifications earned abroad. Any system that treats this as fraud will do real harm to real graduates.

4. The accreditation mill

The recursion, and the part almost every article on this subject skips. If your control for variant 2 is to check accreditation, then the operator's counter is to be accredited. Accreditation bodies can themselves be created for the purpose. An institution can display accreditation from an organisation that exists solely to confer it, whose website is professional, whose standards document is well written, and whose only member institutions are the ones it was set up to legitimise.

So you check the accreditor. But by what standard? You need a recogniser: a body that recognises accreditors. In the United States this role is played by the Department of Education and by the Council for Higher Education Accreditation; in other jurisdictions by national quality agencies or ministries. And that is where the chain terminates, not because recognisers are infallible, but because it terminates in an entity whose authority comes from law rather than from self assertion.

Why is the accreditation recursion the hard part?

Because trust has to bottom out somewhere, and the entire question is where.

The analogy that makes this click is the one from web security. Your browser trusts a website's certificate because it was signed by a certificate authority. It trusts that authority because the authority's certificate is in a root store. It trusts the root store because the operating system or browser vendor curated it, applying published criteria, with a process for removing authorities that misbehave. The chain does not terminate in mathematics. It terminates in a governance decision by an entity that has to answer for it.

Credential verification needs the same shape and mostly does not have it. There is no equivalent of a root store that an employer can consult programmatically. There are lists, maintained by different bodies, in different countries, in different formats, with different inclusion criteria, covering different sectors, updated on different schedules. An employer verifying a degree from another country is often reduced to reading a website and forming an impression.

This is a governance problem wearing a technical costume, and it is the same shape as the trust registry problem we described in you verified them in Berlin, now prove it in Singapore. Formats interoperate long before institutions agree whose attestations they will accept.

Why can we not simply measure the size of this problem?

An honest paragraph, because you will find plenty of confident numbers elsewhere and most of them do not survive being chased.

Estimates of the annual revenue of the diploma mill industry circulate widely, in the range of several billion dollars, usually as part of a larger figure for academic fraud overall. When you trace these back, they generally lead to vendor publications or press coverage citing other press coverage, and the underlying methodology is rarely stated. Similarly, survey findings that a large majority of employers encountered at least one candidate scam in a given year come from vendors who sell screening services to those same employers, which does not make them wrong but does mean the sampling and the incentive both deserve mention.

Treat all of these as directional. The more reliable evidence that this is a substantial problem is structural rather than statistical: entire national infrastructures exist to verify enrollment and degrees, credential evaluation is a professional service with established firms and multi week turnaround times, licensing boards run enforcement functions, and federal prosecutors periodically bring cases. Nobody builds that much machinery around a small problem.

Why does the insider issued credential defeat everything?

The strongest single illustration is the federal investigation known as Operation Nightingale, in which prosecutors described a scheme selling fraudulent nursing education documents that were then used to sit licensing examinations and obtain genuine nursing licences across multiple states. Reported figures for the number of credentials involved have varied across coverage, commonly given in the region of several thousand, so treat the precise count as reported rather than settled.

The mechanism is what matters. These were not forgeries of documents from institutions that had never heard of the candidates. They were documents issued through real, accredited institutions, by people inside those institutions who sold them. Every downstream check succeeded because every downstream check was asking the wrong question.

Walk it through. A verification query to the registrar returns a positive match, because the record exists. An accreditation check passes, because the institution is genuinely accredited. A licence check with the state board returns a valid licence, because the licence is valid: it was issued by the board after the candidate sat and passed the examination. Every link in the chain is formally correct and the outcome is a person in a clinical role who did not do the training.

This is the credential equivalent of a supply chain compromise, and it teaches the same lesson: when trust is transitive, a compromise at any hop is inherited by everything downstream, and the downstream parties have no way to see it. It also shows why the two problems in this post are separable. Provenance would not have caught Nightingale, because the provenance was real. Only the issuer's own controls could have caught it at issuance, and revocation as a class is the only remedy afterwards, which we covered in the licence was revoked in March, the credential still verifies.

How does verification actually work today, and why is it so slow?

The mechanics explain the economics, and the economics explain where the fraud goes.

In the United States, a national clearinghouse holds enrollment and degree records for a large share of institutions and can answer queries quickly. Coverage is broad but not total, and it is a United States institution. Outside that, verification means contacting the registrar directly, by email or telephone, and waiting for a human to respond. For international qualifications, employers typically engage a credential evaluation service, which produces an equivalence report over a period commonly measured in weeks, at a cost per credential that is meaningful.

Now the consequence. Verification costs money and time per candidate, so employers apply it selectively. They verify for senior roles, for regulated roles, and for roles with fiduciary or safety exposure. They skip it, or accept a cheaper partial check, for junior roles and high volume hiring.

Fraud is not stupid. It concentrates exactly where verification is thinnest, which is entry level and high volume roles, and then rides the internal promotion process upward, because almost no employer re verifies credentials for an internal promotion. The person whose degree was never checked at hire because they were junior becomes the person whose degree is assumed to have been checked because they are senior.

That single sentence is the most actionable thing in this post for most employers, and it costs nothing to fix. Re verify on promotion into any role where the credential matters.

What would credential provenance actually look like?

Two changes, addressing two different failures. They are frequently conflated and they are not the same.

Change one: the credential carries its chain

Instead of a PDF that asserts things, the credential is a signed object that can be verified against a published key, and it carries or references the chain that establishes the issuer's standing.

{
  "credential": "degree",
  "issuer": "did:web:example-university.edu",
  "award": "BSc Nursing",
  "conferred": "2019-06-14",
  "holder_binding": "sha256:7c4a...",   // one way key, not a name or face
  "status": "https://example-university.edu/status/2019#4412",
  "issuer_chain": [
    { "recognised_by": "national-quality-agency.gov",
      "accreditor": "regional-accreditor.org",
      "valid_from": "2021-01-01",
      "valid_to":   "2027-12-31" }
  ]
}

The verifier's job changes shape entirely. Today the question is "does this document look genuine", which is a judgment about pixels that a human makes badly and that generative tools have made unanswerable. With a chain, the question becomes "do I recognise the body at the end of this chain", which is a governance decision an organisation makes once, writes down, and reuses across every candidate forever.

That shift is the whole prize. You are not checking a document. You are checking a policy you already wrote.

Verification also stops requiring a call to the registrar. The signature verifies against a published key, and status is fetched as an aggregate list rather than a query that tells the issuer which employer is asking about which graduate, which is a privacy property worth having. The mechanics are the same as those described in can you verify a credential without phoning the issuer, and the chain structure is the attestation chain pattern we set out in what is an attestation chain.

Change two: the credential is bound to its holder

Provenance solves the issuer question and does nothing about the second failure, which is that a genuine credential can be presented by someone who did not earn it. Buying a real graduate's documents, or using a relative's, defeats every provenance check ever designed, because the credential is entirely genuine.

Holder binding means the credential contains a commitment to the graduate as a one way key established at issuance, and presentation requires a live proof from the enrolled human's device. The employer learns that the presenter is the holder. They do not receive a face template, and the institution does not store one either.

$ manav verify credential.jwt --require-holder-presence

  issuer        example-university.edu     [key published, signature valid]
  chain         regional-accreditor.org
                -> national-quality-agency.gov   [recognised: yes, per policy v3]
  status        active                     [status list fetched 2026-09-22]
  award         BSc Nursing, conferred 2019-06-14

  holder        presence proof valid       [signed 14s ago, enrolled device]

  RESULT: credential verified, presented by its holder.

Which control fixes which fraud?

Fraud typeCaught by registrar check?Caught by provenance chain?Caught by holder binding?
Forged certificate, real institutionYesYes, no valid signature existsNot relevant
Real certificate, credential selling institutionNo, the record existsYes, chain does not reach a recognised bodyNo
Real certificate, marginal accreditationNoSurfaces it as a policy decision rather than a pass or failNo
Accreditation millNoYes, the recogniser is the terminating checkNo
Insider issued genuine credentialNo, everything is realNo, provenance is genuineNo, the holder is the buyer
Stolen or purchased genuine credentialNoNoYes, presenter is not the holder
Credential revoked after issuanceSometimes, if you re queryYes, via status listNo

Read the insider issued row carefully, because it is the honest one. Nothing in this post catches it at the moment of issuance. That failure is inside the institution, and the only controls that address it are the institution's own separation of duties and audit. What provenance and status add afterwards is the ability to revoke an identified batch as a class rather than chasing individual holders for years.

Why does digitisation make this urgent?

Because the sector is currently digitising credentials at scale, and digitisation without provenance actively worsens the problem.

Digital badge and credential platforms verify that an issuer signed something. National and regional programmes are moving academic records into digital wallets. All of this is good work and the standards underneath it, principally the W3C Verifiable Credentials data model and the Open Badges specification, are serious and well designed.

But consider what a diploma mill does in that world. It becomes an issuer. It signs its credentials properly. It presents a cryptographically valid, machine verifiable credential that renders with a green check in every wallet and every checking tool. Compared to today's slightly wrong PDF, this is a substantial upgrade in credibility for the fraud, delivered by the infrastructure built to prevent it.

The green check answers "was this signed by the key it claims to be signed by". Users will read it as "this qualification is real". The gap between those two statements is where the next decade of credential fraud will live, and it will be worse than the current decade because the fraud will look better than the truth used to.

What are the honest limits?

What to do this week

  1. Re verify credentials on internal promotion into any role where the credential is load bearing. This is the cheapest meaningful control available and almost nobody does it.
  2. Write down, as a policy document, which recognisers your organisation accepts and why. Most organisations discover this has never been written and lives in one person's judgment.
  3. Separate your four fraud types in your own screening policy, and check that you have a distinct control for each rather than one check you believe covers all of them.
  4. Ask your background screening vendor a precise question: for a given verified degree, did they confirm issuance, the issuer's recognition chain, or that the candidate is the person named. Most will confirm the first only. Get the answer in writing.
  5. Audit where you skip verification for cost, then check whether any of those roles are promotion paths into roles where you do verify. That is where your exposure is.
  6. If you issue credentials, publish a verification key and a status list, and plan holder binding for your next cohort rather than retrofitting the last twenty years.
  7. Build the alternative evidence path for candidates with no reachable issuer before you need it, not after you have rejected someone who deserved the role.

The developer documentation covers the presentation receipt format, and there is a working demonstration of holder bound verification in the verification lab.

Frequently asked questions

How can an employer verify that a degree is real and belongs to the candidate? Three checks, not one. Confirm the credential was issued, by signature or registrar query. Confirm the issuer's standing through a chain that terminates in a recogniser you accept as a matter of written policy. Confirm the presenter is the holder, which requires a live proof from an enrolled device, because a genuine credential presented by someone else passes both of the first two checks.

What is a diploma mill? Strictly, an entity that sells credentials without requiring the education they represent. In practice the term is used for four distinct frauds: forged documents from real institutions, genuine documents from credential selling institutions, genuine documents from marginally accredited institutions, and institutions legitimised by accreditation bodies created for that purpose. They fail different checks and need different controls.

Can a digital badge or verifiable credential be faked? The signature cannot be forged without the issuer's key. But a diploma mill can become an issuer and sign its own credentials properly, producing a cryptographically valid credential that displays as verified. The signature proves who signed, not that the signer is legitimate, which is why the accreditor chain matters more once credentials go digital, not less.

Why did the Operation Nightingale credentials pass verification? Because they were genuine at every checkable point. The documents came from real accredited institutions through insiders who sold them, the candidates sat and passed real licensing examinations, and the resulting state licences were validly issued. Every downstream check asked whether the record existed. None could ask whether the education happened.

Does accreditation prove an institution is legitimate? Only if the accreditor is itself recognised. Accreditation bodies can be created to legitimise the institutions that fund them, so checking accreditation without checking the accreditor's recognition simply moves the fraud up one level. The chain has to terminate in a body whose authority comes from law rather than from self assertion.

How long does credential verification take today? A domestic query against a national clearinghouse can return quickly where coverage exists. A direct registrar query depends on a human replying, typically days. International credential evaluation commonly takes weeks and carries a per credential cost, which is why employers apply it selectively and why fraud concentrates in the high volume roles where it is skipped.

What happens to people whose university no longer exists? This is the hardest equity problem in the area. Refugees and graduates of closed or inaccessible institutions cannot obtain a signed credential from an issuer that cannot be reached. Any deployment needs an alternative assessment route treated as a normal path, or it will systematically exclude displaced people while appearing neutral.

Sources

  1. United States Department of Justice, press releases of the Southern District of Florida, covering prosecutions in the fraudulent nursing credential investigation known as Operation Nightingale. justice.gov/usao-sdfl/pr
  2. Council for Higher Education Accreditation, on recognition of accrediting organisations and the distinction between accreditation and recognition. chea.org
  3. National Student Clearinghouse, degree and enrollment verification services and coverage. studentclearinghouse.org
  4. W3C Verifiable Credentials Data Model 2.0, the credential format underpinning digital academic credentials. w3.org/TR/vc-data-model-2.0
  5. W3C Bitstring Status List, the mechanism for revocation and suspension without per query calls to the issuer. w3.org/TR/vc-bitstring-status-list
  6. 1EdTech Open Badges specification, the badge and micro credential standard. 1edtech.org/standards/open-badges
  7. Europass Digital Credentials, the European framework for signed academic credentials. europa.eu/europass/en
A diploma mill that learns to sign its credentials properly does not get caught by digitisation. It gets a green check.