Skip to main content

QR Code Safety Scanner

Decode any QR code before your phone trusts it -- image never uploaded.

EVT·T250
Decode Before You Trust

About the QR Code Safety Scanner

A QR code is a link your eyes cannot read — which is the entire reason “quishing” works: stickers over parking-meter codes, fake payment signs, codes in emails that sail past link filters. This tool inverts the trust order. The code is decoded in your browser (bundled open-source decoder; the image never leaves your device), the payload is shown to you in plain language, and only then — if it is a URL — does the destination go through the same phishing engine behind our Link Analyzer: RDAP domain age, TLS handshake, the full redirect chain, brand-impersonation checks.

Wi-Fi join codes, contact cards, dialer and SMS payloads get decoded and explained too, each with what it would have done to your phone.

DecodingIn-browser (jsQR, Apache-2.0)
Your imageNever uploaded
URL analysisShared engine with T223
Last reviewed2026-09-07 by Dennis Traina
Drop a QR code image here, click to choose, or paste from the clipboard
Decoded on your device — the image is never uploaded.
Payload Type
Exactly What the Code Contains

      
Scan History

Your last 20 scans, kept in this browser only.

Scan history requires subscription
Sign up free to save your history
Honey-Do Tracker — home maintenance for landlords and property managers

How to Use the QR Code Safety Scanner

Photograph or screenshot the code and drop the image on this page — upload, drag, or paste straight from the clipboard. Decoding happens in your browser with a bundled open-source decoder, so the image never touches a server. You see the payload exactly as encoded; if it is a URL, the destination is then analysed by the same server-side engine as our Phishing Link Analyzer — only the URL string is sent, never your photo.

Why QR Codes Became a Scam Channel

Three properties make the QR code a gift to fraudsters: it is unreadable to humans, so substitution is invisible; it is physical, so a $0.02 sticker converts someone else’s parking meter, menu or charity poster into your landing page; and it bypasses email filters that scan links but not images. The FTC and FBI have both warned about exactly these patterns. None of this makes QR codes dangerous by nature — it makes unexamined scanning dangerous, which is a habit this page exists to replace.

Reading the Verdict Like an Analyst

The single strongest signal is domain age: real organisations have old domains, and a payment page on a domain registered last Tuesday is close to a verdict by itself. Next comes the redirect chain — shorteners and trackers are resolved hop by hop server-side, so you see where the code actually lands without ever visiting it. Brand names parked in subdomains (yourbank.com.secure-login.xyz), punycode homographs, and typosquats of major brands round out the checks. A “clean” verdict is not a guarantee; a “dangerous” one is a strong reason to walk away and, for stickers in public places, to tell the venue.

Related tools: the Phishing Link Analyzer for pasted links, the QR Code Generator for making codes rather than fearing them, and the Breach Directory if you already tapped something you regret. Browse every Security & Privacy tool for more.

The decoder reads standard QR codes (not Data Matrix, Aztec or PDF417). The link verdict is an automated heuristic, not a guarantee in either direction — new-but-legitimate domains exist, and determined attackers age domains. Decoding is client-side; only decoded URL strings are sent for analysis. jsQR is used under the Apache-2.0 license.

Frequently Asked Questions

What is quishing?

Phishing by QR code. The attack works because a QR code is a link your eyes cannot read: a sticker over the real code on a parking meter, a fake "scan to pay" sign, a code in an email that routes around link-scanning filters. The FTC and FBI have both issued consumer warnings about it. The defence is exactly what this tool does — decode first, read the payload, check the destination — instead of letting the phone camera leap straight to the browser.

Does my photo get uploaded?

No. The QR decoding runs entirely in your browser using a bundled open-source decoder (jsQR, Apache-2.0 licensed); the image never leaves your device and is discarded when you leave the page. Only if the decoded payload is a URL, that URL string — never the image — is sent to our server for the phishing analysis, the same check the Phishing Link Analyzer runs on pasted links.

What does the link analysis actually check?

The checks a security analyst would run without clicking: the domain's registration age via RDAP (a "bank" registered nine days ago is the strongest phishing signal there is), a real TLS handshake from our server, the full redirect chain resolved hop by hop (so shorteners can't hide the destination), homograph and punycode tricks, brand names parked in subdomains, and typosquatting distance from the brands phishers actually impersonate.

What about QR codes that aren't links?

They get decoded and explained in plain language. A WIFI: payload would join your phone to a network — the tool shows the network name, the security type, and the password in the code, and notes that joining an attacker's network lets them observe your traffic. A vCard or MECARD adds a contact; tel: and sms: payloads dial or text a number (premium-rate scams live here); a plain-text payload is just text. In every case the point is the same: see it before your phone acts on it.

The code will not decode. Why?

The usual causes, in order: the photo is blurry or at a steep angle (re-shoot straight on), the code is too small in the frame (crop closer), glare is washing out part of it, or it is not actually a QR code (some parking and transit systems use other 2-D formats like Data Matrix or PDF417, which this decoder does not read). Screenshots of screens decode almost perfectly; photos of curved surfaces are the hardest.

137 Foundry — custom app building studio
137 Foundry — custom app building studio
137 Foundry — custom app building studio
Link copied to clipboard!