Are QR Codes Safe? How to Spot a Malicious One
The code itself cannot infect your phone — but it can send you somewhere that will. The risk lives in the destination, not the squares.
Open the QR decoderWhy QR scams work
A URL in an email is visible; a URL in a QR code is not. Attackers exploit that blind trust by placing their own code over a legitimate one — on parking meters, restaurant tables, delivery notices, charity posters, and invoices — sending you to a convincing fake payment or login page. Security teams call it quishing, and it bypasses many email link filters because the link is an image.
Warning signs on a printed code
- A sticker placed on top of another code, or a code with peeling edges
- A code that does not match the surrounding print quality or branding
- Unsolicited codes in letters, packages, or on windshields
- A code demanding urgent payment, a fine, or account verification
- No visible URL printed alongside the code
Warning signs after decoding
- A lookalike domain: paypa1.com, my-bank-secure.co, amazon-support.xyz
- A link shortener hiding the final destination
- A raw IP address instead of a domain name
- An http:// login page with no TLS
- A file download (.apk, .exe, .zip) instead of a web page
- A Wi-Fi payload in a place where free Wi-Fi makes no sense
The one habit that protects you
Read the code before you open it. Photograph or screenshot the code, decode the image, and inspect the URL as text — then decide. Because QRDecoder decodes locally in your browser, checking a suspicious code never sends the payload to a third party.
Also: never enter payment or login details on a page you reached only through a QR code. Navigate to the company yourself, or type the domain manually.
Related guides
Decode your QR image now
Free, private, and instant — your image never leaves your device.
Upload a QR image