Skip to main content
QRSenBuilt for business
Core Concepts

How to Tell If a QR Code Is Real or Fake

Look for physical signs of tampering, like a sticker placed over what should be an official code, and be cautious of codes in unsolicited mail or emails pushing urgent action. Scanning a QR code itself is safe, the real risk is entirely in where the decoded link leads and what you do once you're there, the same as clicking any link.

A QR code printed on a separate sticker and placed on top of an existing sign, parking meter, or menu is one of the most common tampering patterns, since it's trivial for anyone to print a sticker with a malicious code and place it over a legitimate one in a public location. Look for a sticker with slightly different material, a crooked placement, or edges that look freshly applied, if a code looks like it doesn't quite belong on the surface it's sitting on, treat it with suspicion.

A QR code arriving in unsolicited physical mail, an unexpected email, or a text message you weren't expecting, especially one paired with urgent language like 'verify your account now' or 'unpaid toll, pay immediately,' is a classic pressure tactic used regardless of whether the mechanism is a QR code, a link, or a phone call. Legitimate organizations rarely require you to act within minutes, urgency is a manipulation tactic, not a normal business practice.

Use your phone's built-in link preview to see the actual destination domain before tapping through, rather than trusting the code blindly. Be extra cautious with links that go through a shortener or redirect service where the real destination is hidden, and never enter login credentials or payment information on a page you land on immediately after scanning an unfamiliar code, especially if that page asks for something a normal website wouldn't need right away.

It's worth being clear that scanning a QR code is not itself dangerous, decoding the pattern just reveals text or a link, nothing executes or installs automatically. The entire risk sits downstream, in the website the link points to and what you're asked to do once you arrive, exactly the same risk profile as clicking a link in an email or text message. Treating QR codes with the same healthy skepticism you'd apply to any unexpected link covers almost all of the real-world risk here.

Businesses displaying their own QR codes publicly can help their customers with this by making tampering easier to notice — printing codes directly into the original signage or packaging design rather than as a separate sticker applied afterward, and periodically checking public-facing codes for signs of an added sticker, closes off the single most common real-world tampering method before a customer ever has to spot it themselves.

Frequently asked questions

Generally yes, but it's still worth a quick visual check for signs of an added sticker before scanning, since public signage is a common target for exactly this kind of tampering. If the code is printed as part of the original sign rather than stuck on afterward, it's much less likely to have been tampered with.
If you haven't entered any information, simply close the page and avoid interacting further, no harm is done from the scan itself. If you did enter login credentials or payment details, change that password immediately and monitor the relevant account for unusual activity, the same steps you'd take after any phishing link.
Not from the scan alone, since decoding a QR code only reveals a link or text, it doesn't run code or install anything on its own. The risk requires a further action, tapping through and then entering information or downloading something on the destination page.