Email Scam Checker Email Scam Checker
Feature

QR Code Scam Checker: How to Check a QR Code Before You Scan It

A QR code hides an address. Decode it somewhere other than your phone, and the address can be judged before anything opens.

QR Code Scam Checker: How to Check a QR Code Before You Scan It
P

Pavel Demidovich

Developer and Founder of Email Scam Checker

How to check if a QR code is safe

The only way to check whether a QR code is safe or not is to decode it somewhere other than the device that would open it. Read the address first, and decide about the destination afterwards.

That is the entire idea behind the free QR code checker. Drop in a screenshot, a photo of the code, or a PDF with one embedded, and it is decoded in your browser and its destination reported. The phone that would have opened the page never goes near it, so nothing loads and nothing is asked of you.

Are QR codes safe? As a format, yes - a code is a picture of some text, and nothing about that picture runs on its own. QR code security is a question about the destination, which is why the rest of this page is about addresses rather than about codes.

  • A QR code holds text, not a program. Malware reaches you through the page a code points at, never through the code itself.
  • A malicious QR code is a misnomer. The code is only ever the carrier; the malicious part is what is waiting at the other end of the address it holds.
  • What a code hides is an address, and an address can be judged: how old the domain is, what it is dressed up to look like, and where it really goes.
  • The judgement that matters is about the destination. A domain registered days ago, or one that spells a bank with a switched letter, is the answer.

What a QR code actually carries

A QR code is a way of writing text down as a picture. That is all it is: the pattern of squares encodes a string, and a decoder turns the string back into text. Nothing inside the code runs, installs, or asks for permission.

Almost always the string is a web address. It can equally be a Wi-Fi network's join details, a contact card, a phone number, or a payment request - and a Wi-Fi code is the one most people meet, with nothing dangerous about it. An address is the reason codes are worth checking, because everything that happens next happens on the page that address names. QR codes were designed to carry data, not to hide it, and most of them do exactly that.

So the question a QR code raises is not whether the code is dangerous. It is where the code goes, and what is waiting there. Those are different questions, and only the second one has an answer you can act on.

Every QR code risk worth worrying about - and every QR code danger that gets reported - begins downstream of the code, at the address it carries: a stolen login, a payment that goes to the wrong place, a phone that picks something up on the way.

How QR code scams work

A QR code scam works by placing a code where one is expected and pointing it somewhere the reader would not knowingly go. The code itself is rarely the interesting part. The placement is.

The FTC's consumer alert on QR codes describes the bluntest version: scammers covering the code on a parking meter with one of their own. The replacement is printed on a sticker, laid over the original, and hard to tell from the real thing once it is down - the plainest of the fake QR code scams, and the one that needs no technical skill at all. The same trick works on a restaurant table, a bus stop, a poster, or an electric-vehicle charger, because in all of those places a code is the only way forward and nobody has a reference to compare it against.

By post is the second route. The FBI's Internet Crime Complaint Center warned about unsolicited packages containing QR codes that arrive with no sender information, on the reasoning that an unexplained parcel is hard to ignore. The QR code package scams work by making the code the only way to answer an obvious question - who sent this? - and the page that opens asks for personal or financial details instead.

Email is the third route: an invoice, a delivery notice, or a benefits update, with the code in the body or inside an attached image or PDF. There is no link to hover over, and the message asks you to finish the job on a phone that your email protections never see. That shape is what quishing detection exists to catch inside a message.

Whichever route it takes, the code does one thing. It moves you from a place where you were being careful to a page built to look like somewhere you trust.

What quishing is, and why codes slip past filters

What is quishing? The short definition: quishing is phishing delivered as a QR code - QR code phishing, in other words. The word is QR plus phishing, and it names the delivery method rather than a new kind of attack: the page at the end is the same fake login, fake invoice, or fake payment form phishing has always used.

What makes it work is that a code shows no address. A link in an email can be read, hovered over, or compared against the words around it; a QR code is a picture, and the address inside it exists only once something decodes it. A filter built to read the visible text of a message finds nothing to read.

The scale is not marginal. The APWG Phishing Activity Trends Report for the first quarter of 2025 recorded 1,003,924 phishing attacks, the highest number it had counted since late 2023, and noted that criminals are sending millions of emails a day containing QR codes that lead to phishing sites and malware.

The second half of the problem is where the scan happens. A code exists to be opened by a phone, so the message asks you to move off the machine your email defences are watching. That phone is usually signed in to the same accounts, and it never saw the warning. The background on the attack is in what quishing is and how QR scams work.

What a QR code scam checker looks for

A QR code scam checker decodes the code and reports what is known about the destination, because the code itself carries nothing to judge. Eight signals are reported, and all eight are about the address.

Signal What it means Why it counts
A bare IP address The code points at a numeric address such as 192.0.2.10, with no domain name in front of it Real services publish a name. A raw address has no registration date to look up
A high-risk suffix The domain ends in a suffix that is cheap to register and disproportionately used for abuse, such as .xyz or .top A suffix is not proof, but it changes what the rest of the address is worth
A brand inside an unrelated domain A well-known name appears in the address but not where it belongs - paypal.secure-billing.example.com rather than paypal.com The brand is decoration. What decides where you land is the part furthest to the right
Look-alike characters Letters drawn from another alphabet that render almost identically, so the domain reads as a familiar name while being a different string This is the trick that carries a fake domain past a glance. The FTC's advice is to look for misspellings or a switched letter
An internationalized domain A name written in non-Latin script, shown in its encoded form Legitimate, and also the usual vehicle for the look-alike trick above
A near-miss spelling A domain a character or two away from a real one: amaz0n, rnicrosoft, arnazon Typosquatting is cheap and needs no character tricks at all
A link that hides where it goes A shortened or wrapped address that reveals nothing about its destination Reported rather than followed. Following it would tell the shortener you visited and still not tell you where you end up
How recently the domain was registered Asked for separately, this reports whether the domain is under 30 days old Throwaway infrastructure is the norm in QR phishing, which is why a fresh registration is among the strongest single signals there is

Underneath the report sits a verdict: no serious scam indicators found, worth checking before you open it, or likely a scam. The checker scores the findings, and does not display the number. The reason is worth stating. The email extension's score is calibrated across 28 checks on a whole message; this one runs eight against a single address, so showing the same figure would imply a precision that is not there.

Why domain age is the signal the others are not

Domain age is the one signal that comes from outside the address itself, and it is the one that most often settles the answer. Every other check reads the string. Age asks the registry that issued the domain when it was created.

That answer cannot be worked out offline, which is why it is the only step in the check that uses the network, and why it sits behind a button the reader presses rather than running by itself. The registry is asked about the domain name and nothing else - not the file, not the code, not you.

A domain registered in the last 30 days is reported as a strong indicator. The reasoning is not that new domains are bad. It is that scam infrastructure is disposable by design: a domain is bought, used for one campaign, and abandoned, often within days, precisely so that blocklists never catch up with it. A business opening a real site keeps it for years, and the registration date shows that.

The number is a signal, not a verdict. A site registered last week that otherwise looks exactly like what it claims to be is a different proposition from one registered last week whose name is a switched-letter copy of a bank's. Age is strongest when it agrees with something else, and that is how it is reported.

What a QR code checker cannot see

A QR code checker judges the destination address, and QR code safety is not a question an address can settle by itself. Knowing what it cannot tell you is what stops a clean result from meaning more than it does.

  • Whether the code itself is genuine. A sticker laid over a real code is indistinguishable from the original once it is stuck down, and nothing in the decoded text reveals that a second code was ever there. No decoder can help you check QR code authenticity, because authenticity is a property of the surface the code sits on rather than of the text inside it.
  • Where a shortened link ends up. Shortened addresses are reported as a signal and not resolved. Asking the shortener costs you the visit and still does not tell you what is waiting at the end.
  • What the page does. The checks read the address, not the page. A domain can be old, correctly spelled, and cleanly registered, and still host a form built to collect a password.
  • Domains on five suffixes. The age lookup does not cover .ru, .рф, .su, .by or .kz, so a domain registered last week on one of those is not flagged. The page says so when it happens rather than letting a clean result suggest otherwise.

Those gaps are worth more than a longer feature list. A tool that implied it had covered them would be wrong about the one thing a reader is relying on it for. The same discipline runs through the 28 checks the extension runs on a whole email, where the verdicts carry the same kind of stated limit.

What to do if you already scanned a scam QR code

Can you get scammed by scanning a QR code? Not by the scan itself - scanning turns a picture back into text and stops there. What matters is what you did on the page it opened.

  • You only looked. Close the tab. A page collects what you type into it or download from it, and a page you only read was given neither.
  • You typed a password. Change it now, on the real site reached by typing the address yourself, and turn on two-factor authentication. Change it anywhere else you used the same password.
  • You entered card details. Call the number on the back of the card and ask for it to be replaced. Do not wait for the first unfamiliar charge to appear.
  • You downloaded a file and opened it. Treat the phone as compromised until a malware scan says otherwise, and look for apps you do not recognise.

Then report it. The FBI's Internet Crime Complaint Center takes complaints at ic3.gov, and the FTC takes them at ReportFraud.ftc.gov. Phishing and spoofing was the most-reported crime type in the IC3's 2025 Internet Crime Report, at 191,561 of 1,008,597 complaints, which is why the reports matter: they are what the takedowns are built from.

Final verdict - checking a QR code before you scan it

A QR code cannot be judged by looking at it, and it cannot carry anything dangerous by itself. What it carries is an address, and an address is the one part of the whole exchange you can check in advance. Decode the code somewhere other than the phone that would open it, read what the destination looks like - its age, its spelling, the brand it is pretending to be - and the decision stops being a guess.

The QR code checker lets you check a QR code online, for free, in the browser, with no account and nothing to install. What it cannot do is decide for you whether a domain that looks fine is serving a page that is not, so the check narrows the question rather than closing it. That is still considerably more than a sticker on a parking meter gives you.

Frequently asked questions

Decode the code somewhere other than your phone, and read the address it holds before anything opens it. A screenshot, a photo of the code, or a PDF with one embedded can all be dropped onto the free QR code checker, which reads the file in the browser and reports what it finds about the destination. Your phone never visits the page, so nothing is loaded and nothing is asked of you.

Eight, and all eight are about the destination rather than the code. A bare IP address where a domain should be; a high-risk domain suffix; a well-known brand name hidden inside an unrelated domain; look-alike characters; an internationalized domain; a near-miss spelling of a brand; a link that conceals where it goes; and, on request, how recently the domain was registered. Each one is reported in plain language under the verdict.

Because scam infrastructure is built to be thrown away. A domain registered within the last 30 days is one of the strongest single signals an address can carry, and the checker reports it as a high-severity finding. Age is not proof on its own - a real business can launch a new site - but it stacks with whatever else about the domain looks wrong.

No. Decoding a code and visiting its destination are separate steps, and a checker only does the first. The code holds an address written as text, and something has to read that text and report it. The destination page is never loaded, so it cannot fingerprint your device, set a cookie, or show you a login form.

It cannot tell whether the code itself has been tampered with. A sticker placed over a genuine code on a poster or a parking meter looks identical to the original, and no decoder can tell them apart. It also does not follow shortened links, and it does not read the page at the destination - only the address. Domains on .ru, .рф, .su, .by and .kz cannot be age-checked at all.

It depends on what you did on the page. If you only looked, close the tab - what a page collects is what you type into it or download from it. If you entered a password, change it on the real site reached by typing the address yourself, and turn on two-factor authentication. If you entered card details, call your bank and ask for the card to be replaced. Then report it to the FBI's Internet Crime Complaint Center.

The printed code cannot be altered, but it can be covered. Scammers print a sticker carrying their own code and lay it over the real one on a parking meter, a menu or a poster, and the replacement is hard to notice once it is stuck down. The FTC has documented exactly that tactic. So a QR code authenticity check is one you do with your eyes, before you scan: a code sitting proud of the surface, with a ragged edge, or stuck on top of something else is worth a second look on any surface a stranger can reach.

For the destination they are close: a QR code link checker and a link scanner both judge an address rather than a page. The difference is the input. A link scanner reads a link that is already text in an email; a QR code checker decodes a picture or a PDF first, because the address only exists once the image has been read. The checks that follow are the same either way.

Deep-dive guide

This page covers what the feature does and when it fires. For the longer walkthrough, read What Is Quishing? QR Code Phishing Explained .

Other features