IsMyUrlSafe

QR Safety Checker

Scan a code with your camera or upload a photo of it. The link inside is pulled out on your device and checked before you ever open it.

or

A QR code is unreadable to you until your camera opens it — by which point you are already on the page. Checking the code first closes that gap.

Quishing: phishing that hides in a grid of dots

Because nobody can eyeball a QR code, it is an ideal disguise for a malicious link. Fraudsters print their own codes on fake parking notices and letters, email them inside bogus invoices, and — most simply — stick a small label bearing their code directly over a real one in a public place. The scan feels routine; the destination is a look-alike payment or sign-in page.

What happens when you check one here

  1. You scan the code with your camera or upload a photo or screenshot of it.
  2. Your browser decodes the code on your device and reads the address inside it.
  3. That address is cross-referenced against continuously updated records of sites reported for phishing, malware and fraud.
  4. You get a plain safe, suspicious or unsafe verdict — the same one the URL check would give.

Where tampered codes turn up

The high-risk places are the ones where scanning is expected and paying is normal: a code taped over the real one on a parking meter or a restaurant table card, a delivery label on a parcel you were not expecting, a QR code embedded in an emailed bill, or a poster in a station or car park. Anywhere a code asks you to pay, sign in or "confirm" something is worth a check first.

Your image stays on your device

Whether you scan or upload, the photo is processed entirely in your browser. It is never sent anywhere — only the link found inside the code is checked, and only when you ask for the result.

FAQ

QR Safety Checker — common questions

How do I check a QR code that is printed in front of me?

Use "Scan with your camera" and point your phone at the code, or take a normal photo of it and upload that photo. Either way the code is read on your device.

Is my photo or camera image uploaded anywhere?

No. The image is decoded in your browser, on your device. Only the web address found inside the code is sent to be checked — the picture itself never leaves your phone or computer.

The "Scan with your camera" button does not open the camera.

Live camera access needs a secure connection and your permission, and some browsers or devices block it. If it will not start, take a photo of the code and use the upload option instead — the result is the same.

Which camera does the scanner use on a phone?

It requests the rear-facing camera, which is the one you want for pointing at a code on a poster, a sign or a package.

The code is not a link — it holds Wi-Fi details or a contact card.

Those cannot be checked as a website. The tool tells you what type of content the code holds so you can decide whether you trust it, but there is no link for it to assess.

What is "quishing"?

Quishing is phishing carried out with QR codes. A common version is a printed sticker with a fraudulent code placed on top of a legitimate one, so scanning it sends you to a convincing copy of the real site.

Can a QR code itself contain a virus?

The code is just encoded text, almost always a link. The danger is not the square of dots — it is the page that link opens, which is exactly what this checker looks at.

An email contains a QR code and asks me to scan it with my phone to continue. Is that normal?

Be cautious. Pushing you from a managed work computer onto a personal phone is a known way to sidestep security controls. Extract the link and check it before you scan.