QR Code Checker: Scan Safely Before Opening

Fake QR codes on a parking meter, an invoice or a parcel: scan the code here first. The scanner shows the link’s real domain and flags common traps, never opening it without your consent.

  • Free
  • No sign-up
  • Never expires
  • No scan tracking

Static QR codes: the content is written into the code itself, with no redirection through our servers. It will always work, unlike “dynamic” QR codes that stop working at the end of a free trial. Static vs. dynamic: the difference

QR code source

Before opening a link, the reader shows its real domain and flags common traps: shortened link, IP address, misleading characters, fake domain placed before an “@”, unencrypted link, program download. No link is opened without your consent.

Scan a QR code with your camera

The camera only turns on if you click below. No image is saved or sent.

100% local processing, nothing is uploaded

How does it work?

Scan the code with the camera or import a photo of it: its content is shown without being opened. For a link, the scanner highlights the real destination domain (for example example.com in https://www.shop.example.com/…) and flags:

  • shortened or redirected links (bit.ly, qrco.de…), whose destination is hidden;
  • misleading characters: a Cyrillic “а” imitating a Latin “a”, shown in its real form;
  • addresses containing an “@”, where everything before it is ignored;
  • IP addresses, unusual ports, unencrypted links (http) and program downloads (.apk, .exe…);
  • dangerous protocols (javascript:, data:, file:), which are never opened.

Nothing is uploaded: the analysis looks at the address itself, without consulting any blocklist. It therefore does not guarantee that a site is safe; it helps you spot an address that does not match what you expect. For a bank transfer, also check the beneficiary’s name and the IBAN shown.

Examples

A fake parking notice

A code stuck on a parking meter leads to parking-payment-city.com rather than the city’s website or the official app: the domain shown in large type is enough to spot the scam before you type the 16 digits of a bank card.

A shortened link in a letter

The code on an “urgent” letter contains https://bit.ly/3xYz12: the scanner flags a shortened link whose destination is hidden. Rather than opening it, go straight to the official website by typing its address yourself.

Frequently asked questions

What is “quishing”?
It is phishing by QR code: a fake code, stuck over the real one or printed on a letter, leads to a site imitating a bank, a public service or a parking operator in order to steal your credentials or bank details. Always check the domain before entering anything.
Is a link with no alerts necessarily safe?
No. The analysis spots the traps visible in the address, but a fraudulent site can have an ordinary domain name. The decisive question remains: is this domain really that of the organization you expect? If in doubt, type the official address yourself.
What should I do if I fell for a fake QR code?
Do not enter any information. If you have already given your bank details, contact your bank immediately to block your card. Report the site to your national fraud reporting service (for example reportfraud.ftc.gov in the United States or Action Fraud in the United Kingdom).
Are my images and camera feed sent anywhere?
No. The camera only turns on when you click “Turn on the camera” and stops as soon as a code is read or you leave the page. Images are analyzed in your browser; none are saved or sent. Only the decoding program may be downloaded from this site, if your browser lacks one.