Stand Against Crime

Free tool · QR code safety

QR Code Scam Checker

Scanned a QR code and unsure? “Quishing” hides scam links behind fake QR stickers, emails, and messages. Learn how these scams work, how to spot a fake — and paste the link a QR code opened into our free checker to scan it for the tricks scammers use.

What Is a QR Scam?

A QR scam — also called “quishing” (QR + phishing) — uses a QR code to send you to a fraudulent website or payment request while looking completely legitimate. A QR code is really just a link in a form your eyes can’t read, which is exactly what makes it useful to scammers: you can’t see where it goes until you’ve already scanned it.

Instead of a suspicious-looking link in a message, the scammer hands you a tidy little square. Scan it and you land on a convincing fake — your bank’s login page, a parking-payment form, a courier’s “pay the fee” page — where anything you type goes straight to them.

How QR Scams Work

1

They make a QR code that points to a trap

The code leads to a fake payment or login page, a malicious app download, or a payment request — anything that captures your money or your credentials.

2

They put it where you’ll trust it

A sticker placed over the real code on a parking meter, EV charger, or restaurant table; a QR in a phishing email or text; a fake “missed delivery” slip; or a poster in a public place.

3

You scan it

Your phone opens a convincing lookalike site or a payment request. Because a QR code hides the web address, nothing looks obviously wrong.

4

You hand over money or details

You enter card, bank, or login details — or approve a payment — and it goes straight to the scammer. Crypto and instant transfers can’t be reversed.

Fake QR Examples

The same trick shows up in a lot of everyday places. A few of the most common:

Parking meters & EV chargers

A fake sticker over the real code sends you to a bogus “pay for parking” page. Police across the US, UK, Australia, and India have all warned about this.

Restaurant “scan to pay”

A swapped table QR routes your bill payment to a scammer instead of the venue.

“Missed delivery” slips & texts

“We couldn’t deliver your parcel — scan to reschedule or pay a small fee.” The QR leads to a fake courier page that harvests card details.

Emails at work (“quishing”)

“Scan this QR to keep your account active or reset your MFA.” Hiding the link inside an image sneaks it past email filters and moves you onto your phone, away from work security.

Fake refund or cashback (UPI)

“Scan this QR to receive your refund.” Scanning a QR or approving a collect request SENDS money — you never scan a code or enter a PIN to receive it.

Charity & donation posters

Fake QR codes stuck on posters, or shared during disasters and appeals, quietly divert donations to a scammer.

How to Check a QR Code

  1. 1

    Look for a sticker. If the QR code is a sticker sitting on top of printed material — on a meter, sign, or menu — treat it with suspicion. Peeling edges or a misaligned code are red flags.

  2. 2

    Preview the link before opening. Most phone cameras show the web address when you point at a code. Read it before you tap anything.

  3. 3

    Check the exact domain. Is it the company’s real address, spelled exactly right? Watch for extra words, hyphens, odd endings (.xyz, .top), or lookalike characters.

  4. 4

    Prefer the app you already have. Pay through the official app you downloaded yourself, or type the address by hand — a fake sticker can’t change an app that’s already on your phone.

  5. 5

    Never enter details from a QR page. Don’t type card, bank, or login details — or approve a payment PIN — on a page you reached by scanning a code.

  6. 6

    Scan the link below. Paste the address the QR code opened into our checker to spot common tricks before you trust it.

Use Our Free QR Checker

Paste the link a QR code opened (or any suspicious link) and we’ll check its structure for the tricks scammers use.

100% private. The link is analyzed entirely in your browser. We never open it, send it anywhere, or store it.

Tip: on most phones you can long-press a QR code (or use the camera preview) to see the link before opening it — then paste it here.

Waiting

Paste a link to check it

This checks a link’s structure, not a live reputation database, so it can’t catch everything. When in doubt, don’t open it.

What to Do If You Already Paid

Move fast — the sooner you act, the better your chance of stopping or reversing it.

  1. 1

    Contact your bank or card issuer immediately and ask them to dispute, freeze, or recall the payment. Paid by card? Request a chargeback. In India, call 1930 and tell your bank and UPI app to block further transactions.

  2. 2

    If you entered a password or login, change it now and turn on two-factor authentication. If you shared card details, have the card blocked and reissued.

  3. 3

    Report it — here’s who to contact wherever you live.

  4. 4

    Ignore anyone who offers to “recover” your money for a fee — that’s a second scam. See how to get your money back after a scam.

Frequently Asked Questions

Are QR codes themselves dangerous?

The QR code itself is just a link — it can’t “hack” your phone on its own. The danger is where it takes you: a page built to steal your money or logins, or a prompt to approve a payment. So the risk is entirely about the destination, which is why checking the link matters.

Is the link I paste sent anywhere?

No. The checks run entirely in your browser using built-in heuristics. The link is never opened, transmitted, stored, or logged.

What is “quishing”?

Quishing is phishing via QR codes. Scammers place fake QR codes — or stick them over real ones — that lead to fraudulent payment or login pages. Because you cannot read a QR code with your eyes, checking the link it resolves to is essential.

Can a link be dangerous even if it looks fine here?

Yes. This tool catches common structural tricks, but no checker is perfect. Treat any link that arrived unexpectedly — by text, email, or QR — with caution, and reach websites by typing the address yourself.

Which tricks does the checker catch most often?

Lookalike domains and typo-squats, brand names hidden in subdomains, the “@” credential trick, punycode characters that imitate real letters, raw IP-address hosts, and URL shorteners that hide the true destination.

Last reviewed: August 2026

Keep Going

Read the full story behind these scams, or protect the rest of your household.

Warn someone — share this