In short
Quishing is phishing that hides the real destination inside a QR code instead of a link you can read. There is nothing to hover over, nothing to compare against the words around it, and nothing a filter reading visible text can recognise. Email Scam Checker decodes QR codes wherever a message carries them - in the body, in an image loaded from somewhere else, or inside an attachment - and puts the address they contain through the same checks as any visible link.
- QR codes are decoded from emails, from remotely hosted images, and from PDF, image, and Office attachments.
- The decoded address is checked like any other link, including the registry lookup that flags a domain registered in the last 30 days.
- Attachments are opened and read in your browser and the file itself is never uploaded; a link found inside one is looked up the same way any other link is.
Why a QR code is a good hiding place
A link in an email is at least inspectable. You can read it, hover over it, or let software compare where it claims to go with where it actually goes. A QR code offers none of that. It is a picture of squares, and the address inside it exists only once something decodes it.
Three things follow from that, and all three work in the attacker's favour.
- There is no address to inspect. Whatever your phone's camera does when it recognises a code, the check happens on a small screen, in a hurry, once you have already decided to point the camera at it. You cannot look at the image in your inbox and tell where it leads.
- Filters have nothing to read. A scanner that reads the visible text of an email - the sender, the wording, the addresses in the markup - finds no destination at all when the destination is a picture. The link is not obfuscated; it simply is not text.
- The click moves off the protected machine. A QR code exists to be scanned by a phone, so the message asks you to finish the job on a device your email defenses never see. That phone is usually signed in to the same accounts, and it never saw the warning.
A code also looks modern and official, survives being screenshotted, forwarded, and pasted into a document, and is trivially replaceable - a sticker laid over a printed menu code is the same attack in the offline world.
What gets decoded
Decoding is not limited to the message body. The extension looks for QR codes anywhere a message can carry one, opens the containers it can read, and treats what it finds like any other link.
| Where the code sits | What is extracted |
|---|---|
| Message body | QR codes in the message, plus every visible link and its real address |
| Remotely hosted image | A QR code served from another server is fetched and decoded |
| Link to an image file | A plain link pointing at an image is followed and the file decoded |
| PDF attachment | QR codes in the images the document contains |
| Image attachment | PNG, JPG and JPEG, GIF, WEBP and BMP files, decoded for QR codes |
| Office attachment | .docx, .xlsx and .pptx files - QR codes, plus hyperlinks tucked into the document |
Two of those rows explain why a code cannot simply be moved out of reach. Plenty of messages never embed the QR image at all: the body merely points at an image hosted on some other server, often a content network's, which is why a code hosted elsewhere is still decoded rather than written off as a picture nobody can read. The same reasoning covers a bare link to an image file: the link is unremarkable, and what matters is what the file contains.
Fetching such an image is one of the few moments the extension reaches the network. The request goes to the host the image points at and asks for that file; the message body is not sent anywhere with it. A file inside an attachment is different again: it is opened and decoded in the browser you already have open, and the file itself is never uploaded. A link the attachment turns out to contain is then looked up the way any other link is.
The evasion it closes
Quishing lives in the gap between what a message says and what it contains, and that gap has two shapes.
The first is an email whose body holds no link at all. The text is one polite sentence, the attachment is a picture or a document, and the only destination in the whole message sits inside the code. A scanner that reads markup finds an image on a content network and nothing else, so it reports nothing - there is genuinely nothing textual to report. Host the code on a third-party image domain and the picture looks even less remarkable, since the only domain written down belongs to somebody's image host.
The second shape is a code buried in a document. An invoice arrives as a PDF, complete with a plausible reference number and an amount, and at the foot of the page sits a payment code. The email says "invoice attached" and nothing more, so a body-only scanner sees a message with no links and one attachment, and stops there. That is the pattern this feature is built for: the PDF is opened, the code is read, and the address inside it goes through the same checks as a link pasted into the message.
Both shapes rest on one assumption - that whoever is checking reads only what is written down. Decoding removes it, because a destination hidden in pixels is then checked as thoroughly as one spelled out in plain text.
What the decoded link faces
Once a code is decoded, the address inside it is not treated as special. It goes through the same link checks as any other address in the message: lookalike and typosquatted domains, a brand name hidden in a subdomain, high-risk endings such as .xyz and .top, raw IP addresses where a domain should be, and shorteners - which are flagged, then resolved so the real destination is checked too. Character tricks count as well, since a domain can be assembled from letters that merely look like the ones they replace.
Then comes the lookup. A bare domain name is sent to the public registry to ask when it was registered, and a domain registered within the last 30 days comes back as a supporting risk signal. A recent registration is not proof of anything, but it is one of the strongest single signs of phishing, and it stacks with whatever else the link checks found. It is the same fresh-domain lookup that runs on the links in the message body: a destination delivered as a QR code gets no less scrutiny than one delivered as text.
One thing the code itself adds is a low-severity caution. A link handed over as a picture deserves a second look even when its destination looks clean - legitimate codes are everywhere, but the ones arriving in unexpected email rarely need to be scanned. The destination decides the verdict; the code is the reason to look.
Scoring works as everywhere else: each finding adds points, positive signals subtract them, and the total decides whether the email reads Safe, Suspicious, or Scam. For the full list of what a decoded link is measured against, see heuristic scanning.
When nothing can be decoded
Not every attachment can be opened, and the extension says so rather than staying silent. Three kinds of file land in that bucket.
- Formats with no reader. Vector images (SVG), legacy Office files (.doc, .xls, .ppt), and OpenDocument documents are not parsed for a QR code or a link, because nothing here reads them reliably.
- Encrypted attachments. Where a provider encrypts attachments end to end - Proton Mail is the main one - the file cannot be opened and read directly. An image you choose to open in a preview is the exception: the previewed image is decoded and the verdict recalculated from what it finds. Every other encrypted file stays unread.
- Files that opened and gave nothing up. A document the reader could not make sense of, a code too damaged to decode, or a remotely hosted image the request did not retrieve.
In every one of those cases the email is carrying an attachment and showing no link in the body, which is precisely the shape of a message hiding its destination. So it picks up a low-severity caution: the attachment may hide a link or a QR code. Read that for what it is - a heads-up, not a verdict. It is worth 5 points, the lightest weight there is, and on its own it decides nothing. What it does do is keep a clean email from reading Safe: while a file sits unread, the email is marked "Check the attachment" - a fourth state of its own, distinct from Safe, Suspicious and Scam, and the one that means the extension is telling you it could not look rather than implying that it did. It means "open this one yourself and look", nothing more.
Final verdict
Quishing is not a new kind of scam. It is the same link dressed as a picture, so that nobody - reader or filter - can see where it leads before it is too late. This feature takes that advantage away: the code is decoded, from the message, from an image hosted elsewhere, or from inside an attachment, and the address behind it faces the same tests as any other link. What is left to you is the ordinary judgment - an unexpected code in an unexpected message is a reason to stop, not to scan.
If you want the background on the attack itself, read what quishing is and how QR scams work.