QR Code Scam Checker: Is This QR Code Safe?

Photograph a QR code before you open it and see exactly where it leads, what it does and whether it is a scam.

The photo is decoded on your device and never uploaded. The contents are shown as text and nothing inside the code is opened.

A QR code is a picture of some text, and you cannot read that text until your phone has already acted on it. That is exactly why scammers like them. A sticker over the real code on a parking meter, a code in an email that slips past spam filters, or a card in a parcel you never ordered all look the same as a genuine code, and your camera app gives you only a second to glance at a shortened address before you tap.

This checker lets you look inside a QR code without opening it. Take a photo or upload a screenshot and the code is decoded right here on your device. You see the full contents as plain text, what scanning would actually do, whether that is opening a website, joining a Wi-Fi network, paying in cryptocurrency, filling in a bank transfer or sending a text, and every scam sign we find, adjusted for where you found the code.

How it works

  1. Tell us where you found the code, such as a parking meter, an email or an unexpected parcel. Scams look different in each place, so the checks and advice change to match.
  2. Take a photo with your phone or upload a screenshot. On a computer you can also drag an image in or paste a screenshot.
  3. The image is decoded in your browser, using the phone's built in barcode reader where it has one and the open source jsQR decoder everywhere else. It is tried at several sizes so blurry or large photos still read.
  4. The decoded text is identified as one of twelve payload types, including website links, Wi-Fi logins, cryptocurrency payments, bank and instant payment requests, pre-written text messages, phone numbers, contact cards and app installs.
  5. Website links go through the same analysis as our phishing link checker, which finds the real website and looks for lookalike brand names, cheap throwaway domain endings, shortened links, hidden downloads and other tricks.
  6. Extra checks run for the place you found the code, such as a payment page on a throwaway domain at a parking meter or a phone number inside an unexpected parcel.
  7. Each finding is weighted by how strongly it points to a scam, combined into a risk score from 0 to 100, and turned into a verdict with the steps to take.

Reading your results

  • No warning signs means the contents look normal for where you found the code. It is not proof the code is genuine, so still check the destination matches the business.
  • Check this QR code before you use it means minor signs, such as a payment request or a Wi-Fi login, that are normal in some places and risky in others.
  • This QR code looks suspicious means several warning signs. Do not pay or sign in through it until you have confirmed with the business directly.
  • This looks like a scam QR code means strong signs of deception, such as a lookalike of a known brand, a cryptocurrency payment or an app download. Do not use it.
  • What this code contains names the payload type and describes in plain words what your phone would do if you scanned it.
  • Full contents shows the exact text inside the code. It is never made clickable, so you can read it safely.
  • Real website, payee, network name or phone number pulls out the details that matter for that payload type, so you can compare them with what you expected.
  • What we found lists each warning sign with an explanation of how that trick works and why it matters where you found the code.

How this fits into the real world

Fake QR codes on parking meters are now common enough that the US Federal Trade Commission issued a consumer alert about them in September 2026, describing scammers covering the real codes on meters with their own. The fake code opens a convincing payment page that takes your card details, and often signs you up to recurring charges, while the parking fine you were trying to avoid still arrives. The FBI warned back in January 2022 that criminals were tampering with QR codes to redirect people to sites that steal login and financial information.

In email, the same trick is called quishing. A message claiming your password is about to expire, a document is waiting for your signature or a delivery needs rescheduling includes a QR code instead of a link. Because the link is inside an image, many email security filters cannot read it, and scanning it moves you to your phone, where the full address is hard to see and your work security software may not be running.

QR codes can do more than open websites. A code can join your phone to a Wi-Fi network run by the attacker, open a crypto wallet with a payment ready to send, fill in a bank transfer to the wrong account, or start a text message to a premium rate number. Seeing the payload type before you scan is the only way to know which of these you are agreeing to.

Unexpected parcels are another route. Criminals send items nobody ordered with a QR code that promises to reveal the sender, claim a prize or arrange a return. The code leads to a form that asks for personal and payment details. If a parcel arrives that you did not order, do not scan anything inside it.

Who this is for

  • Drivers paying for parking, tolls or electric vehicle charging by QR code.
  • Anyone who received an email or text asking them to scan a QR code to sign in, sign a document or reschedule a delivery.
  • People who received a parcel they did not order with a QR code inside.
  • Diners and shoppers who want to check a table or counter code before paying through it.
  • Office staff checking invoices and bills that ask to be paid by QR code.

What this tool cannot tell you

  • The checker reads what the code contains, not the page or app it leads to. A new scam site with an ordinary looking address can score low.
  • It cannot tell whether a code has been stuck over a genuine one. Always check a physical code for a sticker edge before scanning.
  • Shortened links and redirects are flagged as hiding their destination rather than followed, because following them would mean visiting the link.
  • Very small, damaged, curved or low contrast codes may not decode. Move closer, avoid glare and keep all four corners in the frame, or type the address your camera showed.
  • Payment QR standards vary by country. Payment codes are identified and explained, but the payee details they contain are not checked against any bank register.

Frequently asked questions

How can I check if a QR code is safe without scanning it?

Take a photo or screenshot of the code instead of opening it, then upload it here. The code is decoded on your device and shown as text, so you can see the real website, payment or Wi-Fi login inside before anything happens. If the website is not the business you expected, do not use the code.

Can you get hacked just by scanning a QR code?

Scanning alone rarely harms an up to date phone. The danger is what the code makes easy next: opening a fake payment or login page, installing an app, joining a rogue Wi-Fi network or sending money. Keep your phone updated and never enter a password, card number or code on a page you reached through an unexpected QR code.

How do I spot a fake QR code on a parking meter?

Look for a sticker placed over the printed code, peeling edges or a code that looks different from the rest of the signage. Check the web address before paying, and prefer the parking operator's official app or the address printed on the sign. If a code looks tampered with, report it to the operator or local council.

What is quishing?

Quishing is QR code phishing. Instead of a clickable link, a scam email or text includes a QR code, which gets past filters that scan links and moves you to your phone where the address is harder to check. Common lures are password expiry notices, shared documents, missed deliveries and multi-factor authentication resets.

I scanned a scam QR code and paid. What should I do?

Call your bank or card issuer on the number on your card straight away and ask them to stop the payment and replace the card. If you entered a password, change it everywhere you used it and turn on two factor authentication. Watch statements for recurring charges, and report the scam to ReportFraud.ftc.gov, Scamwatch, Report Fraud or the Canadian Anti-Fraud Centre.

Is my photo uploaded when I use this checker?

No. The image is decoded by code running in your browser and never leaves your device. Only an anonymous count of the verdict is recorded so we know how often the tool is used.

Why does the checker ask where I found the code?

The same contents can be normal in one place and a red flag in another. A payment request is expected at a cafe counter, while a phone number inside a parcel you did not order is a classic callback scam. Knowing the context lets the checker weigh the risk properly.

Related tools

Guides that go with this tool