QR Photo Verification: How Recipients Check a Photo
How QR photo verification works for recipients: what the page shows, why the area is rounded, what integrity flags mean and how to compare files.
QR photo verification lets anyone who receives a photo scan the code printed on it and open an independent record of when and roughly where it was taken, plus the checks the server ran when the photo arrived. If that record matches what is printed on the image, you have a solid reason to trust it; if it does not, or the code cannot be found, you have a reason to ask questions. This guide walks through what the recipient sees, how to read each part, and how to get clients into the habit of checking.
Why a printed date is not enough
A line like “08:15 · 12 Jul 2026 · District 7” in the corner of a photo is just pixels. Anyone with a photo editor can type an identical line onto an old picture. The EXIF metadata inside the file is just as easy to change with free tools, and it is usually stripped when the photo goes through social networks or chat apps.
So the value of a proof photo does not come from the text on it. It comes from a record kept somewhere else that the photographer cannot quietly rewrite. The QR code is simply the bridge to that record. The difference is covered in more depth in timestamp vs verifiable photos.
| Method | Can anyone change it? | Can the recipient check it? |
|---|---|---|
| Date text burned onto the photo | Yes | No |
| EXIF metadata in the file | Yes, and often lost when shared | Hard, needs tools |
| QR code linking to a server record | The record cannot be edited by the sender | Yes, with any phone |
How a recipient verifies a photo with the QR code
The recipient does not need an app or an account:
- Scan the QR code with the phone camera (most phones read QR codes straight from the camera app). If the photo is open on that same phone, view it on a laptop and scan, or type the code instead.
- Or type the code printed on the photo, in the form
SNP-XXXX-XX, atsnapidmark.com/v/CODE. - Check the domain in the address bar before trusting anything. A fake QR code can point to a convincing fake page.
- Compare the capture time and area on the page with what is printed on the photo.
- Read the integrity checks, and if it matters, compare the file you hold with the original.
You can try this with a sample photo in the verify demo on our home page.
What the verification page shows
The public SnapID Mark verification page answers one question, “was this really taken then, around there?”, without exposing more than it needs to.
Capture time
This is the trusted time recorded at capture. It is synced with the server rather than read from the phone clock, so winding the phone back a few hours does not change it. The mechanism is explained in trusted time vs phone time.
A rounded area, not exact coordinates
The public page does not show precise coordinates. It shows a rounded area, for example at district level. This is a privacy choice: photos are often taken at a client’s home or an employee’s location, and anyone holding the photo should not learn the exact spot. The full coordinates and GPS accuracy remain on the stamped photo itself and in the photographer’s or company’s own records.
When comparing, just check that the area on the page contains the address printed on the photo. A photo stamped “Thao Dien, Thu Duc City” with a verification area in Hanoi is an obvious red flag.
Workspace name
If the photo belongs to a business workspace and the business allows it, the page shows the workspace name, so you know which company’s team took it.
Other states
- Still uploading: the code was issued but the file has not reached the server yet, usually because the photographer was offline. Check again later.
- Deleted: the workspace removed the photo; the page shows the date.
- Not found: no photo has that code. Re-check each character or ask the sender.
Reading the integrity flags
Every upload is re-checked on the server instead of trusting the phone blindly. The results appear as a list of passes and warnings. A photo with no flags is labelled “Verified”; one with flags is labelled “Has warnings”.
| Flag | What it means | What to do |
|---|---|---|
| Mock location | The phone reported a location coming from a spoofing app | Treat the location as unreliable and ask |
| Rooted or jailbroken device | The phone’s system protections were unlocked | Be more cautious, look for other evidence |
| Clock drift | The phone clock disagreed with server time | Rely on trusted time, not phone time |
| Outside geofence | A clock-in photo was taken outside the site’s allowed radius | The business reviews it under its policy |
| Late upload | The photo reached the server more than 15 minutes after capture | Often just no signal; ask before judging |
| Invalid app build | The photo did not come from an official build | Do not rely on it as evidence |
A flag does not mean the photo is fake. A late upload may simply mean the technician was working in a basement with no coverage. Equally, no flags is not an absolute guarantee. Flags tell you whether a follow-up question is worth asking. See how businesses use them in stop attendance fraud.
Comparing your file with the original
The page has a compare with my file button. You pick the image on your device, your browser computes its SHA-256 fingerprint locally, without uploading the photo, and checks it against the fingerprint the server stored when the original arrived.
- Match: your file is byte-for-byte identical to the original. Nothing was edited.
- No match: the file differs from the original. That could be an edit, but very often it is simply a chat app recompressing the image. Zalo, Messenger and many others shrink photos when you send them, which changes the file even though it looks the same.
When the comparison matters, ask the sender for the original through a channel that does not recompress: send as a “file” rather than a “photo”, use email, or a shared folder. More detail in detect edited photos with SHA-256.
Training clients to check your photos
A QR code only helps if people actually scan it. If you run a construction crew, a cleaning company, a delivery service or field technicians, make checking a habit for your clients:
- Say it once, up front. In the contract or first message: “Every report photo carries a QR code. Scan it to see the capture time and area recorded by the system.”
- Send the link along. When you share a photo from the app, the verification link goes with it, so the client can tap instead of scan.
- Demonstrate at handover. Scan one photo together and point out three things: time, area, flags.
- Send originals when there is a dispute. Save the JPEG to your device and send it as a file or by email so the client can compare fingerprints (a PDF is handy for records but cannot be used for the comparison).
- Welcome questions. If a client sees a warning, explain the real reason (for example, no signal so the upload was late). Openness builds more trust than a green badge.
| Industry | Typical photos | What the client should check |
|---|---|---|
| Construction | Inspection and progress photos | Time and area match the inspection day |
| Building cleaning | Before/after shift photos | Time falls inside the shift window |
| Delivery | Proof-of-delivery photos | Area matches the delivery address |
| Rentals | Move-in and move-out condition photos | Date matches the handover |
How SnapID Mark supports verification
Every photo taken with SnapID Mark gets its own SNP-XXXX-XX code and a QR code on the stamp, alongside trusted time, weather, GPS coordinates with accuracy, the address and a mini map. Offline, the photo still receives a pre-issued code and trusted time, then uploads automatically when signal returns; the verification page works once the upload completes. Recipients need no account, and inside the app you can scan the QR on someone else’s photo to see its result. See security and how it works on our home page.
To be clear about the limits: SnapID Mark gives recipients a quick, well-grounded check, but it is not a legally certified timestamp such as one from a qualified timestamping service or digital signature. How much weight a photo carries in a given case is for the relevant authority to decide.
If you want clients to be able to check every report photo themselves, download SnapID Mark and send yourself a QR-stamped photo to try it.
FAQ
Does the recipient need to install an app?
No. Scanning with the phone camera or opening snapidmark.com/v/CODE in any browser is enough, with no account required.
Why doesn’t the page show the exact address?
To protect the privacy of the photographer and the location’s owner. The page shows a rounded area, which is enough to check against the address printed on the photo.
Can I still scan the QR code after the photo was sent through Zalo?
Usually yes, because the QR code is part of the image. The SHA-256 comparison will not match, though, since Zalo recompresses the file. Ask for the original if you need to compare.
Does “still uploading” mean the photo is fake?
Not necessarily. The code exists but the file has not arrived yet, typically because the photographer was offline. Check again later.
Should I reject a photo that has a warning?
Ask for the reason first. Flags differ: a late upload is usually harmless, while a mock location or an invalid app build deserves much more caution.