Email Scam Checker Email Scam Checker

Check if a QR code is safe before you scan it

Upload the code - a screenshot, a photo, or a PDF with one embedded - and we read it here on your device, then report where it leads. It is the check to run on a code you did not expect: a scam QR code, a quishing link, or a sticker pasted over the real one. No account, and nothing to install.

Drop a QR code image or PDF here

PNG, JPEG, WebP, GIF, BMP or PDF. You can also paste a screenshot with Ctrl / ⌘ + V.

The file is read on your device. Nothing is uploaded.

Questions

It reads the QR code and looks at the destination it points to. Eight signals about that destination are reported: a bare IP address instead of a domain, a high-risk domain suffix, a known brand name hidden inside an unrelated domain, look-alike characters, an internationalized domain, a near-miss spelling of a well-known brand, a link that hides where it goes, and - on request - how recently the domain was registered. Each one is explained in plain language under the verdict.

On their own, yes: a QR code is only a way of storing text, usually a link, and reading it does nothing by itself. The risk is not being able to see where it leads before you commit to opening it - a link in an email can be hovered over first, but a QR code shows nothing until your phone has already gone to the page. A scam can print a code that leads to a look-alike login page in seconds. Scams that use QR codes are common enough to have their own name: quishing.

Quishing is phishing that arrives as a QR code. The code is only the delivery method: it encodes a link, and the link leads somewhere the reader cannot see before opening it. Because a code shows no address, the habit of reading a link before clicking it does not apply, and a code can be printed and stuck anywhere a written link would look out of place. The word is a blend of QR and phishing.

No. The image or PDF is read on your own device, in the browser, and the QR code is decoded there. Nothing about the file leaves your machine. The one exception is the domain age check, which you have to ask for: it asks the domain registry how old the domain is, and only the domain name is sent.

Because it is the one part of the check that needs the network. The registry for a domain publishes when it was registered, and that answer cannot be worked out offline. It is offered as a separate step so the automatic check never contacts anything on your behalf, and the button says what it is about to do before it does it.

Our lookup does not cover .ru, .рф, .su, .by and .kz, so a recently registered domain on one of those suffixes will not be flagged. The page tells you when that is the case instead of letting a clean result suggest otherwise.

It is the same idea applied to a different input. This page looks at one QR code and eight signals about where it leads, because a code on its own carries nothing else: no sender, no subject, no message. The extension reads a whole email and checks 28 things about it, including the sender and the words used. Neither one is a substitute for the other, and this page does not claim the extension's coverage.

Scanning on its own does not install anything, and a QR code has no way to carry a program inside itself. What it carries is an address, and the risk is what waits at that address: a page that asks for a password, a payment that goes to the wrong account, or a file the page invites you to download and open. The scan is the safe part. Where it takes you is the part worth checking first.

Usually a page opens, and what that page does decides the damage. It may ask you to sign in and keep the password, show a payment page for a bill that does not exist, or offer a download that installs something. None of it happens until you act on the page. Reading the code here tells you what it points at without your phone opening the destination at all.

The code is placed where someone already expects to scan one, or where scanning is the only way forward: a parking meter, a restaurant table, a package slip, an email claiming a delivery needs rescheduling. It leads to a page built to look like the real thing, and that page asks for a payment, a password, or a code sent by text message. The loss is whatever the page manages to collect.

A QR code can carry the same phishing link an email or text would, just as an image instead of clickable text. Most phishing filters scan text for a suspicious address; a code hides that address inside a picture, so it is not what those filters are built to read. Once scanned, the code works like any other phishing link: it opens a look-alike login page, a fake invoice, or a payment form built to collect whatever you type into it.

The specific term is quishing: phishing delivered through a QR code instead of a typed or clicked link. It sits in the same family as smishing, which arrives by text, and vishing, which arrives by phone call - the delivery method is what separates them, not the goal. All three lead to the same kind of page: one built to collect a password, a payment, or a one-time code.

Treat a code the way you would treat an unexpected link: find out where it goes before acting on what the page asks for. Check whether the domain matches the organisation the code claims to be from, and be wary of a code stuck over another one on a poster or a parking meter - a sticker is easy to place and easy to miss. For anything that matters, a bill, a login, a payment, typing the address yourself rather than scanning a code that offers to save the trouble avoids the risk outright.

Yes. A code can sit in the email body or inside an attached image or PDF, and either way its link is a picture rather than text, so it does not appear as an address a link scanner can check or a reader can hover over. A fake delivery notice, an unpaid invoice, or a benefits update are the usual excuses used to get it scanned. This page reads exactly that kind of file - an image or a PDF - and reports where the code inside it leads before you open it on your phone.

No. A QR code is a way of writing down text, and the text is almost always a web address. It stores no program and cannot run one. Malware reaches you through the page the code points at, not through the code. That is why this page reports the destination rather than inspecting the code for anything dangerous in itself.

Not from the code itself. Two codes can look identical and point at different places, and a sticker laid over the real code on a poster or a parking meter cannot be told from the original by eye. What can be checked is the destination: whether the domain matches the organisation it claims to be, whether it is a near-miss spelling of a well-known brand, and how recently it was registered. That is the part this page reports.

Yes, and that is the usual way. A screenshot of a code, a photo taken of a poster or a package, or a PDF with a code embedded in it can all be dropped onto this page, and the image is decoded here in the browser. If the picture is blurred, cropped or shot at an angle the page says it could not read the code rather than guessing at what it might say.

It is free and there is no account. No sign-up, no email address to hand over, and nothing to install on your phone. The page reads the code and reports the signals it can see. The one step that uses the network is the domain age check, which you have to trigger yourself, and the button states what it is about to send before it sends it.

Looking for the browser extension instead? It reads a whole email and checks far more than a single code allows - see what it checks.