Loading...

Free QR code generator

URL
Text
WiFi
vCard
Email
    Skip to content
    L2QLink2QR
    GeneratorGuidesBlogAPI
    1. Home
    2. Is this QR code safe?
    Last Updated: September 2026

    Is This QR Code Safe? Free Checker That Shows What a Code Really Contains

    Quick Answer

    Upload a photo of the QR code, or paste the link your camera previewed. This page decodes the code in your browser, shows the exact text inside it, and lists the warning signs it matches. It never opens the link for you. No tool can promise a link is safe, so treat a clean result as the absence of obvious tricks rather than a guarantee.

    Upload a photo or screenshot of the QR code

    The image is read in your browser. It is never uploaded, and the link is never opened automatically.

    If your camera app previewed a link without opening it, paste that link here.

    Why a QR code is harder to judge than a link

    On a web page you can rest a pointer on a link and read where it goes. A QR code gives you nothing to read. The destination is encoded in the pattern itself, so the only way to see it is to decode the code, and most phone cameras decode and offer to open it in the same motion. Scams rely on that gap. The technique has a name now, quishing, and it works because the victim is asked to trust a picture.

    The other reason it works is placement. A QR code on a parking meter, a restaurant table, a package or an invoice arrives with the authority of wherever it is stuck. A sticker costs almost nothing, and placing one over a real printed code takes a second. Consumer protection bodies including the US Federal Trade Commission have warned specifically about codes placed on parking meters and about codes arriving in unexpected packages and messages.

    What this checker looks at

    Every check runs locally on the decoded text. There is no reputation database and no lookup, which is a real limitation and the reason the result is phrased as observations rather than a score.

    • A destination hidden behind an @ sign. In a web address, everything before an @ is ignored by the browser. A link that reads as your bank followed by @ and another domain goes to the other domain.
    • Lookalike and mismatched brand domains. A link naming a company but hosted somewhere that company does not use, or a domain one character away from the real one.
    • Non-Latin characters that imitate ordinary letters. Internationalized domains are decoded so a Cyrillic letter posing as a Latin one becomes visible.
    • Raw IP addresses in place of a domain name, including the decimal and hexadecimal forms used to disguise them.
    • Link shorteners, which hide the real destination until you arrive.
    • Executable downloads and double extensions, such as a file named to look like a PDF that is actually a program.
    • Redirect parameters that carry a second address, a common way to bounce a visitor off a legitimate-looking domain.
    • Payloads that are not links at all. A code can join your device to a wireless network, start a payment, dial a premium number, or add an account to your authenticator app. Each of those is explained rather than scored.

    What it cannot detect

    A scam on a brand new domain with a clean name, served over HTTPS, with no shortener and no lookalike spelling, will pass every check here. So will a legitimate site that happens to use a shortener or an unusual top-level domain. These heuristics describe shape, not intent, and they cannot see the page at the other end. Treat the output as a reason to slow down, never as permission to proceed.

    Habits that protect you better than any checker

    • Feel for a sticker. A code stuck over a printed one is the single most reliable warning sign in public places.
    • Read the domain before you tap, not the page title after it loads.
    • Pay through the operator's own app, or a number printed on the machine, rather than through a scanned code.
    • Never enter a password or card number on a page you reached from an unexpected code.
    • Be suspicious of urgency. A fine that must be paid in the next hour is a pressure tactic.
    • If a code arrives in a package or letter you did not order, treat it as hostile.

    Related tools and reading

    • QR code scanner reads a code with your camera and shows the same safety notes before you open anything.
    • Are QR codes safe? covers the wider question, including what a QR code can and cannot do to your phone.
    • QR repair tool recovers a code that is too blurry or damaged for this page to read.
    • What is a QR code? explains how the pattern stores data in the first place.

    Frequently Asked Questions

    Can you tell me for certain whether a QR code is safe?

    No, and any tool that claims it can is overselling. This checker reads what the code contains and points out the patterns scams commonly use, such as a lookalike domain or a hidden destination. A careful scam can avoid every one of those patterns, and a legitimate business can trip one by accident. Use the result as information, not a verdict.

    Does this open the link to test it?

    No. The link is never fetched or opened automatically, and there is no preview request to the destination. The code is decoded in your browser and analysed as text. Opening it always takes a deliberate click plus a confirmation step.

    Is my image uploaded anywhere?

    No. The image is drawn to a canvas in your browser and decoded locally with the jsQR library. It never leaves your device, and we keep no copy of the image or the decoded content.

    What is quishing?

    Quishing is phishing that uses a QR code instead of a clickable link. Because the destination is hidden inside a pattern of squares, you cannot read it before you scan, which is exactly why the tactic works. Common forms include stickers placed over the real code on a parking meter, fake invoices, and codes in emails that get past filters looking for bad links.

    What should I do about a suspicious sticker on a parking meter?

    Do not scan it. Check whether it is a sticker sitting on top of a printed code, which is the usual giveaway, and pay through the operator's own app or the number printed on the machine instead. Report it to the parking operator and to the local authority that runs the site.

    The checker found no red flags. Can I trust the link?

    Not automatically. No red flags means none of the common tricks matched, which is a weaker statement than the link being safe. Still read the domain shown in the result, and never enter a password or card number on a page you reached by scanning a code you did not expect.

    Sources

    • US Federal Trade Commission, consumer alerts on QR code scams, including codes placed on parking meters and codes sent in unexpected packages.
    • FBI Internet Crime Complaint Center (IC3), public service announcements on malicious QR codes.
    • RFC 3492, Punycode, used here to decode internationalized domain names for the homograph check.
    © 2026 Link2QR
    AboutContactGuidesBlogPrivacyTermsEspañol中文