Are QR Codes Safe? How to Spot a Malicious One

The code itself cannot infect your phone — but it can send you somewhere that will. The risk lives in the destination, not the squares.

Open the QR decoder

Why QR scams work

A URL in an email is visible; a URL in a QR code is not. Attackers exploit that blind trust by placing their own code over a legitimate one — on parking meters, restaurant tables, delivery notices, charity posters, and invoices — sending you to a convincing fake payment or login page. Security teams call it quishing, and it bypasses many email link filters because the link is an image.

Warning signs on a printed code

  • A sticker placed on top of another code, or a code with peeling edges
  • A code that does not match the surrounding print quality or branding
  • Unsolicited codes in letters, packages, or on windshields
  • A code demanding urgent payment, a fine, or account verification
  • No visible URL printed alongside the code

Warning signs after decoding

  • A lookalike domain: paypa1.com, my-bank-secure.co, amazon-support.xyz
  • A link shortener hiding the final destination
  • A raw IP address instead of a domain name
  • An http:// login page with no TLS
  • A file download (.apk, .exe, .zip) instead of a web page
  • A Wi-Fi payload in a place where free Wi-Fi makes no sense

The one habit that protects you

Read the code before you open it. Photograph or screenshot the code, decode the image, and inspect the URL as text — then decide. Because QRDecoder decodes locally in your browser, checking a suspicious code never sends the payload to a third party.

Also: never enter payment or login details on a page you reached only through a QR code. Navigate to the company yourself, or type the domain manually.

Related guides

Decode your QR image now

Free, private, and instant — your image never leaves your device.

Upload a QR image