TrustScan
Link safety

Is this QR code safe?

You cannot tell by looking at it — a QR code is a picture of text, and the text is only readable to a machine. Paste the link your scanner showed you and see what our checks find. It runs here, in your browser, and is not sent anywhere.

How QR code scams work

The attack is physical and almost embarrassingly simple. Someone prints a QR code sticker and puts it over the real one — on a parking meter, a restaurant table, an EV charger, a delivery card pushed through your door. You scan it because scanning is what those codes are for. A page opens asking you to pay a fine, confirm a delivery, or log in. It looks right because it was copied from the real thing.

The industry calls this quishing — phishing delivered by QR code. It works better than email phishing for one reason: in an email you can hover over a link and read where it goes. With a QR code there is nothing to read. You are trusting a pattern of squares.

Why your phone's built-in scanner is not enough

Most built-in camera scanners show you a shortened preview of the address in a small banner, and one tap opens it. That preview is often truncated in exactly the place where the deception lives — the end of the domain. A lookalike domain and the real one can be visually identical in a phone-sized font.

The 21 checks

These run on your device the moment a code is read, before anything opens. Every one of them is free in the app, permanently.

Domain deception

  • Lookalike alphabets. Cyrillic “а”, Greek “ο” and fullwidth forms render identically to Latin letters. раypal.com is not paypal.com.
  • Punycode. The xn-- encoding browsers use for international domains, which displays as ordinary letters.
  • Percent-encoded homographs. The same trick written as %D0%B0 escapes, which looks like plain ASCII to a naive checker but is decoded by the browser before it connects.
  • Brand impersonation. A famous name outside its own domain — paypal-billing.com, apple-support.com, netflix.secure-login.xyz.

Hidden destinations

  • Raw IP addresses where a domain name should be.
  • Obfuscated addresses written in hex or octal, such as 0xd8.0x3a.0xd3.0x2e, which browsers still resolve.
  • The “@” trick. Everything before an @ in a URL is ignored, so a link can display a trusted name and go elsewhere.
  • Link shorteners, which hide the destination entirely until you have already arrived.
  • Open redirects — a second address carried inside the first, laundering a scam link through a domain you trust.

Suspicious shape

  • Throwaway domain endings disproportionately used for short-lived scam sites.
  • Login words inside the domain, like verify- or secure-.
  • Deep subdomain chains that push the real domain off the right-hand edge of a phone screen.
  • File downloads — links ending in .apk, .exe or similar, which install something rather than open a page.
  • Credential requests — addresses mentioning passwords, one-time codes, 2FA or recovery phrases.

Spotting a tampered code in the real world

  • Feel the edges. A sticker over a printed code has a lip you can catch with a fingernail.
  • Look for mismatch. Wrong shade of white, a slightly different size, a logo that does not sit where it does elsewhere.
  • Be suspicious of urgency. Parking fines, failed deliveries and account suspensions are the three most common pretexts.
  • Never enter card details on a page you reached by scanning a code in public. Type the company's address yourself instead.

What we do not do

The checks run offline, on your phone. Links are not sent to a server for a reputation lookup, which is how most “safe browsing” features work and how they end up with a record of everything you scan. The trade is honest: we catch structural deception rather than a live blocklist of known-bad sites. For the physical sticker-over-a-poster attack, structure is what gives it away.

Get TrustScan free Create a QR code