Photograph a QR code before you open it and see exactly where it leads, what it does and whether it is a scam.
The photo is decoded on your device and never uploaded. The contents are shown as text and nothing inside the code is opened.
A QR code is a picture of some text, and you cannot read that text until your phone has already acted on it. That is exactly why scammers like them. A sticker over the real code on a parking meter, a code in an email that slips past spam filters, or a card in a parcel you never ordered all look the same as a genuine code, and your camera app gives you only a second to glance at a shortened address before you tap.
This checker lets you look inside a QR code without opening it. Take a photo or upload a screenshot and the code is decoded right here on your device. You see the full contents as plain text, what scanning would actually do, whether that is opening a website, joining a Wi-Fi network, paying in cryptocurrency, filling in a bank transfer or sending a text, and every scam sign we find, adjusted for where you found the code.
Fake QR codes on parking meters are now common enough that the US Federal Trade Commission issued a consumer alert about them in September 2026, describing scammers covering the real codes on meters with their own. The fake code opens a convincing payment page that takes your card details, and often signs you up to recurring charges, while the parking fine you were trying to avoid still arrives. The FBI warned back in January 2022 that criminals were tampering with QR codes to redirect people to sites that steal login and financial information.
In email, the same trick is called quishing. A message claiming your password is about to expire, a document is waiting for your signature or a delivery needs rescheduling includes a QR code instead of a link. Because the link is inside an image, many email security filters cannot read it, and scanning it moves you to your phone, where the full address is hard to see and your work security software may not be running.
QR codes can do more than open websites. A code can join your phone to a Wi-Fi network run by the attacker, open a crypto wallet with a payment ready to send, fill in a bank transfer to the wrong account, or start a text message to a premium rate number. Seeing the payload type before you scan is the only way to know which of these you are agreeing to.
Unexpected parcels are another route. Criminals send items nobody ordered with a QR code that promises to reveal the sender, claim a prize or arrange a return. The code leads to a form that asks for personal and payment details. If a parcel arrives that you did not order, do not scan anything inside it.
Take a photo or screenshot of the code instead of opening it, then upload it here. The code is decoded on your device and shown as text, so you can see the real website, payment or Wi-Fi login inside before anything happens. If the website is not the business you expected, do not use the code.
Scanning alone rarely harms an up to date phone. The danger is what the code makes easy next: opening a fake payment or login page, installing an app, joining a rogue Wi-Fi network or sending money. Keep your phone updated and never enter a password, card number or code on a page you reached through an unexpected QR code.
Look for a sticker placed over the printed code, peeling edges or a code that looks different from the rest of the signage. Check the web address before paying, and prefer the parking operator's official app or the address printed on the sign. If a code looks tampered with, report it to the operator or local council.
Quishing is QR code phishing. Instead of a clickable link, a scam email or text includes a QR code, which gets past filters that scan links and moves you to your phone where the address is harder to check. Common lures are password expiry notices, shared documents, missed deliveries and multi-factor authentication resets.
Call your bank or card issuer on the number on your card straight away and ask them to stop the payment and replace the card. If you entered a password, change it everywhere you used it and turn on two factor authentication. Watch statements for recurring charges, and report the scam to ReportFraud.ftc.gov, Scamwatch, Report Fraud or the Canadian Anti-Fraud Centre.
No. The image is decoded by code running in your browser and never leaves your device. Only an anonymous count of the verdict is recorded so we know how often the tool is used.
The same contents can be normal in one place and a red flag in another. A payment request is expected at a cafe counter, while a phone number inside a parcel you did not order is a classic callback scam. Knowing the context lets the checker weigh the risk properly.