See where a QR code goes before you scan it
QR codes hide their destination, and scammers exploit that — fake codes on parking meters, restaurant tables, and posters send people to counterfeit payment pages. Photograph the code, drop the image below, and read the link as plain text before deciding to trust it.
How to check the decoded link
Green flags
- The domain matches the organization exactly
- The link uses https
- No misspellings like "paypa1" or extra words in the domain
Red flags
- A URL shortener where a business should use its own domain
- A domain that imitates a brand with typos or hyphens
- A payment request from a code found on a sticker
- Login pages reached from posters or parking meters
Why quishing works — and how this stops it
A QR code is just text, usually a URL, drawn as squares. Your eyes cannot read it, so a malicious sticker over a real code is invisible until after you have scanned and tapped. Decoding the image first turns the trick back into a plain link you can inspect. If the decoded link is shortened, run it through our link expander to reveal the final destination, and check the domain's age with the whois lookup — scam domains are usually days old.
Everything on this page runs locally in your browser. The image is never uploaded, so a code containing sensitive information (like WiFi credentials) stays with you.