Skip to content

Is this QR code safe? Check it before you open it.

Upload a picture of the code, paste a screenshot or point your camera at it. You will see exactly where it goes, with warnings for link shorteners, http links and look-alike addresses. Nothing opens unless you say so, and the picture never leaves your device.

Last updated September 18, 2026

Your picture is read on your device and never uploaded.

What the safety check looks for

A QR code is a link you cannot read with your eyes. The check reads it for you and shows the address in plain text, with the site name first. Then it looks for the patterns that show up again and again in QR code scams.

Warning signWhy it matters
A link shortener or redirect serviceThe real destination stays hidden until you open it.
An address that starts with http, not httpsThe connection is not encrypted, so it is no place for a password or a card number.
A row of numbers where a site name should beReal businesses almost never link this way.
Extra text before an @ signA known trick to make an address look like a different site. The real site is the part after the @.
Odd characters in a familiar nameSpecial characters can be used to imitate a brand you know.
A payment pageCheck the name on the page before you send money.

It is honest about its limits too. It does not visit the link and it cannot promise a site is safe. A clean result means no known warning signs, not a guarantee. The final call is yours, made with the address in front of you.

How QR code scams work

The Federal Trade Commission warned in December 2023 that scammers hide harmful links in QR codes. Some cover the code on a parking meter with their own. Others send a code by text or email and add pressure: a package that could not be delivered, an account with suspicious activity.

The FBI described the same pattern in a January 2022 public service announcement about tampered codes that lead to sites built to steal logins and payment details. In July 2025 it added a warning about unsolicited packages that arrive with a QR code inside.

Every one of these works the same way: the code looks harmless, and the trap is the page behind it. Reading the address first takes that advantage away.

Five habits that keep you safe

  1. Read the site name from right to left. The real site is the part just before the .com or .org. Everything to the left of it can say anything.
  2. Feel for a sticker. On meters, menus and posters, run a finger over the code. A raised edge means someone put a new code over the original.
  3. Distrust urgency. A code that arrives with a deadline, a fine or a prize is a reason to slow down.
  4. Go direct when money is involved. For parking, banking and deliveries, type the official address or use the official app.
  5. Never install an app from a QR code. Use the App Store or Google Play and search for the app by name.

If you already opened a bad link

Opening a page and closing it again is rarely a problem. What matters is what you typed. If you entered a password, change it, and change it on any other site where you used the same one. If you entered card or bank details, call the number on the back of your card. Turn on two-step verification where you can.

In the United States you can report it at ReportFraud.ftc.gov and to the FBI at ic3.gov.

Making codes other people can trust

If you print QR codes for customers, the same rules help you. Point the code at your own domain, use https, and print the address in small text under the code so people can see where it goes. A short line such as "Opens example.com/menu" removes the doubt.

You can make that code with the free generator and add the text as a banner under the code. For everything else the scanner can do, see the online QR code scanner.

Questions about QR code safety

How can I tell if a QR code is safe?+
Read it without opening it. Upload a picture of the code or scan it here, and you will see the full address it points to. Check that the site name is the one you expect, that it starts with https, and that it is not hidden behind a link shortener. If anything looks off, do not open it.
Can a QR code hack my phone just by scanning it?+
Reading a code is not the dangerous part. A QR code is only text, usually a web address. The risk starts when you open the address and type in a password, a card number or install something. That is why seeing the address first matters.
Does this tool visit the link or scan it for viruses?+
No. It does not open the link and it is not antivirus software. It shows you where the code goes and points out known warning signs, so you can decide. Nothing is opened unless you press the button yourself.
What are the warning signs of a fake QR code?+
A sticker placed over another code, a code that arrives by text or email with a deadline, an address that uses a link shortener, an address that starts with http, a row of numbers instead of a site name, and a name that is almost but not quite a brand you know.
I already scanned a suspicious code. What should I do?+
If you only looked at the page, close it. If you typed a password, change it now and anywhere else you use it. If you entered card or bank details, call your bank. In the US you can report it at ReportFraud.ftc.gov and at ic3.gov.
Is my picture uploaded when I check a code?+
No. The code is read inside your browser, on your device. The picture is never sent to us or stored.
Are QR codes on parking meters and restaurant tables safe?+
Usually, but these are the places where scammers put stickers over real codes. Look for a sticker edge, check the address before paying, and when money is involved, type the official site or use the official app instead.

Need a code of your own?

Static QR codes are free and unlimited with no account. A free account adds 10 dynamic QR codes, free for life, with no credit card, no ads on the redirect and no watermarks.

Make a QR code, free