Your input stays in this browser.
Pause before opening
Unexpected payment, login, parcel or parking codes deserve extra scrutiny. Check whether a sticker was placed over an original sign. Decode first; this site never opens a link automatically.
Treat the physical context as evidence
A QR code on a known organisation's own letter, counter, or app may fit an expected task; a new sticker over a parking meter, poster, or delivery notice deserves more doubt. Quishing often relies on urgency: a fine, a missed parcel, an account warning, or a payment deadline. The code itself cannot prove who placed it. When the context is surprising, use a known address or official app instead of following the scan.
Read the address carefully
Look for misspellings, punycode, mixed alphabets, embedded usernames or passwords, unusual schemes and shortening services. These are reasons for caution, not proof of fraud. A normal-looking address is not proof of safety.
Decoding is inspection, not a safety verdict
Seeing the text inside a QR code removes one layer of concealment, but it does not establish that a website is genuine or that a request is authorised. A legitimate-looking domain can host a compromised page, and an unfamiliar address can be harmless. Use the decoded result to decide what independent check is appropriate: compare a domain with a statement, find a merchant through its official app, or ask the organisation through a known contact route.
Stop before a credential or payment request
A decoded link can lead to a convincing copy of a login or payment page. Do not enter a password, recovery phrase, card data, or one-time code because a QR image asked for it. Find the service through a saved bookmark, a statement, or the installed official app, then check whether the same request appears there. If a workplace code is suspicious, report the physical location rather than merely removing the sticker.
Protect credentials and payments
Open important services from a saved bookmark or official app instead. Do not enter a password, recovery phrase or card details merely because a QR code led to a convincing page. When in doubt, close the scanned page and begin again from a verified route.
Start with the expected action
A QR code is not inherently malicious, but it hides its contents until a camera or decoder reads it. Ask what you expected to do before scanning: pay a known parking operator, sign in to a service already open on your computer, collect a parcel, or read a menu. An unsolicited email asking for a Microsoft sign-in or an unexpected sticker over a meter changes the risk. NIST describes phishing as a request designed to make someone open a harmful link or submit credentials; the QR image is simply another way to conceal that link.
Inspect the physical object for replacement
At a payment terminal, notice whether the code is printed as part of the sign or is a separate label placed on top. Look for mismatched font, edges, bubbles, different paper or an address that does not match the named operator. Do not peel a suspicious label off and assume the incident is over: someone else may scan it later. Photograph the location without exposing other people's information and report it to the owner or staff through a known contact route.
Read the address without granting it trust
A decoded URL should be inspected before opening. Check the registrable domain, not merely a familiar word in a long subdomain; for example, bank.example.invalid and example.invalid/bank are controlled by different owners. A shortened URL, odd spelling, mixed characters, embedded credentials or an unfamiliar scheme deserves an independent check. A normal-looking address is also not proof. Decode is a visibility step, not a reputation service or a guarantee that the destination's login form is genuine.
A payment case
A diner sees a QR code labelled 'pay table 12' on a sticker. Before scanning, compare the restaurant name and payment method with the bill or ask staff whether the table payment route exists. If the decoded address is not the restaurant's known domain, close it and pay through the displayed terminal or a staff member. Never enter card data, a bank password, recovery phrase or one-time code because a scanned page claims it is needed. The cost of a short verification is lower than correcting an unauthorised payment.
A workplace sign-in case
A code shown inside a service after you have already authenticated can be part of a legitimate device-enrolment flow; NIST notes that QR representations from a trusted authenticated session can carry binding information. That does not make a QR image in an unsolicited email equivalent. For an email or poster asking you to re-authenticate, open the service from a saved bookmark or installed app, then look for the same request there. Report the message through your organisation's normal security channel instead of forwarding the QR image to colleagues.
What to do after a scan
If you merely decoded a suspicious code and did not open it, record the location and tell the responsible organisation. If you opened it but entered no information, close it, avoid downloads, and report it if it impersonates a service. If you entered a password, card detail, recovery phrase or one-time code, use a known route to change credentials or contact the provider immediately; do not return through the QR link. The response depends on what was disclosed, not on whether the graphic looked convincing.
Keep QR safety in proportion
QR codes are also used for legitimate menus, pairing flows, tickets and public information. Treating every code as fraudulent makes normal tasks harder and does not teach a useful check. The sensible boundary is independent verification when the code creates urgency, requests a credential or payment, appears in an unexpected context, or replaces a known official route. UK government phishing guidance similarly advises against giving private information or following links when their authenticity is uncertain. That principle applies after a QR scan as much as after an email link.
A useful record for an incident
Report the original message or the physical location, the time, the organisation being imitated and the decoded address if your security team asks for it. Do not distribute a screenshot as a curiosity, because that can give the fraudulent image more exposure. Keep the report factual: what was expected, what was seen, and whether any credential or payment information was entered. That evidence lets the responsible organisation remove a replacement sticker or block a phishing site without asking users to reconstruct the event from memory. If the venue has cameras or a maintenance log, give staff the exact sign or terminal position so they can preserve evidence and examine other nearby stickers.