Everything can be forged. As you send it to the user, text or graphic, he gains possibility to edit it, with whatever editor may be applied. If it's graphic, one may use graphic editor. It will be harder to forge, but still possible. The only solution is to store the list of certificates at your server, and make it possible for everyone to check whether this or that certificate (e.g. identified by ID, or by the owner) is genuine or forged.