See where a QR code goes before you scan it
A QR code is a link you cannot read. That is exactly why scammers love them: they hide a malicious address inside a harmless-looking square and stick it on a parking meter, a menu, a package or an email. This free checker decodes the QR code in your browser to reveal the hidden link, then checks that link for danger, so you find out where it goes before you ever point your camera at it.
How it works
- Upload a photo or screenshot of the QR code.
- It decodes the code in your browser and shows you the exact link or content inside.
- If it is a website, it follows the redirects, checks how old the domain is, and scans the address for spoofing tricks, then gives a clear verdict.
What quishing is, and why it works
Quishing is phishing with QR codes. Because the human eye cannot read a QR code, you have no way to tell a genuine one from a fake, and a small sticker placed over a real code is invisible. Scanning takes you straight to a convincing fake login or payment page. QR scams have appeared on parking meters, restaurant tables, delivery notices and posters. Checking the code first, instead of trusting it, removes the whole trick.
Why not just scan it?
Scanning with your phone's camera opens the destination immediately, which is what the attacker wants. Uploading the image here reads the link without visiting it, so you see the real address and its safety check first. It is the QR version of hovering over a link before you click.
Private and honest
The QR code is decoded entirely in your browser; the image never leaves your device. Only the link inside (if it is a website) is sent to our server to check the domain, just like our link checker. A clean result is strong evidence, not a guarantee, so never enter passwords or payment details on a page you reached from an unexpected QR code. This is part of the RealCheck set of tools for the AI era: is this real?