Is This QR Code Safe? Check the Link First

Scan the code or paste its link to see the real website and the warning signs of a scam, without opening anything.

Set up to check a link before you open it

Scan the code, or paste the address your phone shows in its preview. You get the website the link really opens and every warning sign in the address. Nothing is opened or looked up.

  1. Scan the code with the camera, or paste the link into the text box below and press Decode text.
  2. Read the website name first: the part just before the ending (.com, .co.uk) is who you'd be dealing with.
  3. Red means signs of a scam: don't enter card numbers, passwords or codes. Amber means check the name carefully.
Made-up example data, decoded on this page.

Opens the rear camera on a phone. The video stays on your device.

Drop an image with a QR code or barcodeChoose a photo or screenshot with a codeor click to choose, or paste a screenshot with Ctrl+V (⌘V on a Mac)Tap to pick from your photos or files · PNG, JPEG, WebP, GIF, AVIF, BMP
Or decode the text of a code

Where fake QR codes turn up

Most QR code fraud happens in open spaces: parking meters, car parks, stations, restaurant tables and posters, where a sticker can cover the real code. The UK’s National Cyber Security Centre said so in February 2024, and Action Fraud (now Report Fraud) counted 784 reports and almost £3.5 million lost between April 2024 and April 2025, with car parks the most common place. In the US, the FTC warned about codes in unexpected emails, texts and letters in December 2023 and about fake codes on parking meters in September 2026, and the FBI’s 2022 warning adds: check that a code hasn’t been stuck on top of another.

What the checks look at

The address is split the way a browser reads it. The example above starts with paypal.com, but the site is parking-fines.example: everything before the real name is decoration, and that trick is flagged red. The checks also flag lookalike spellings (paypa1, accented or foreign letters), a brand’s name on someone else’s domain, an @ in the address, shorteners and dynamic QR services that hide the destination, free hosting where anyone can publish, domain endings most abused for phishing, a second address hidden inside the link and app downloads.

What to do next

If the verdict is red, don’t open the link: pay through the operator’s own app or a website you type yourself. If it’s amber, compare the website name with the organisation you expect. When a code on a meter looks stuck on, tell the operator so they can remove it.

QR Code ScannerSomeone shared their result

Suggested