Free tool

Is This QR Code Safe? Free Checker

Check a QR code before you open it. Decode the link and see whether it uses the tricks behind QR phishing — lookalike domains, hidden credentials, IP hosts and disguised downloads.

  • Free, no sign-up
  • Runs in your browser

What this tool does

You cannot read a QR code with your eyes, so the first time you see the address is after your phone has already offered to open it. That gap is the entire mechanism behind the stickers appearing on parking meters, restaurant tables and delivery notices. This closes it: decode first, judge second, open last.

At a glance

Checks for Lookalike domains, punycode, hidden redirectors, credentials in the URL, bare IP hosts and risky file types
What it does not do It reads the address as written. It never follows a redirect or opens the page
Where it runs In your browser, on the decoded text alone
Cost Free, no limits on how many you make
Sign-up None. No account, no email address
A phone held up to a printed QR code on a wall poster, the code filling the camera view.
Every code on this page is a working code. Scan the preview with your own phone before you send it to print.

How it works

1

Decode it without opening it

Upload a photo of the code, or paste a link you were sent. Nothing is opened, requested or followed.

2

See the structural warnings

The address is taken apart: its real host, its registrable domain, and every disguise technique present in it, each explained in plain terms.

3

Read the verdict as evidence, not permission

A clean result means none of these specific tricks are present. It is not a statement that the site is safe, and the page never presents it as one.

Good to know

  • This checks the ADDRESS, not the destination. It has no blocklist, no reputation feed and no ability to fetch the page — everything it reports is derived from the URL itself.
  • It cannot follow a shortened link, because that would require a request from a server. When it sees a shortener it says so, which is the honest answer: the destination is hidden.
  • A result with no warnings does not mean a site is trustworthy. It means the URL is not disguised. A hostile page on a perfectly ordinary domain is invisible to this and to every tool like it.
  • It flags Qrindo’s own dynamic links the same way it flags Bitly’s. A redirect we serve hides its destination exactly as much as anyone else’s.

Need an editable, trackable QR?

A dynamic Qrindo code keeps the same printed image but lets you re-point it any time and tracks every scan, geo, device, and live.

Frequently asked questions

What is quishing?

Phishing delivered by QR code. A sticker goes over the real code on a parking meter, a menu or a notice, and the scan lands on a payment or login page that looks right. It works because the address is unreadable until it is already open.

Can you tell me if a website is dangerous?

No, and we will not pretend to. Judging a site needs a reputation database and a live fetch of the page, neither of which happens here. What this can prove is that an address is dressed up to look like a different one.

How do I spot a tampered QR code in the wild?

Feel the edges: a sticker over a printed code has a lip you can catch with a fingernail. Then check that the code sits inside the original artwork rather than on top of it, and be suspicious of any code that asks for payment or a login on a public surface.

How do I know if a QR code is a scam?

Decode it before you open it and read the domain right to left from the last dot: the real site is the part just before the top-level domain. paypal.com.secure-login.ru is on secure-login.ru, not on PayPal. This page performs that reading for you and flags several other tricks.

What is quishing?

Phishing delivered by QR code. A sticker over a real code on a parking meter or a restaurant table sends people to a payment page that is not the business it appears to be. The printed code hides the address, which is exactly why it works.

Still not sure about something? Read the full FAQ →