QR peek

A phone camera opens a QR code almost as soon as it sees one. This reader stops one step short. It decodes the code, shows what’s written in it and what a phone would do with it, and leaves the decision to you.

Phones start the back camera when you choose “Scan with the camera”. From a computer, a screenshot or a photo of the code works: drop the file, or paste it with Ctrl+V (⌘+V on a Mac).

🔒 Decoding takes place on your device. Camera frames and pictures stay in your browser, and what the code says is not passed to anyone.

A QR code is a short piece of text

Those black and white squares spell out characters, a few thousand at most, with error correction so the code still reads when part of it is dirty or covered by a logo. That’s all there is in it. No program, no hidden destination. The trouble comes from what the scanning device does next. If the text begins with https://, the phone offers to open it. Other prefixes trigger other actions, and nobody can tell which by looking at the squares.

That’s why fraud has moved to QR codes. A link in an email goes through spam filters, and you can hover over it to inspect it. Print the same link as a code on a parking meter, a restaurant table or a fake delivery notice, and it skips the filters and gets opened on a phone, where the address bar shows very little.

The kinds of content the reader recognizes

Starts withWhat a phone would doWhat to check
http://, https://, www.Open a web pageThe domain in bold
WIFI:Join a wireless networkWho runs the network; open networks and WEP are flagged
BEGIN:VCARD, MECARD:Add a contactThe email and website fields
mailto:, SMSTO:, sms:, tel:Prepare a message or a callThe recipient; short codes and premium-rate numbers are flagged
otpauth://Add an account to an authenticator appThat you’re the one setting it up
bitcoin:, ethereum: and similarPrepare a cryptocurrency transferEverything, because it can’t be reversed
000201…, BCD, upi://Prepare a card, bank (SEPA) or UPI paymentPayee name and amount
geo:, BEGIN:VEVENTOpen a map, add a calendar eventNothing in particular

Anything else is shown as plain text. If there’s a web address buried in that text, it gets the same examination as a link. A code holding a javascript:, data: or file: address is marked red.

What reading the code can’t tell you

The reader sees the address, not the page. A domain with nothing wrong in its spelling can still host a copy of a bank login form. To test the destination itself, paste the address into the unsafe-site lookup or follow it hop by hop with the redirect trace. Both run from our server, not from your phone.

It can’t see the physical world either. Run a finger over a code on a public machine, because a sticker has an edge. For any payment, the safest route is the operator’s app or a web address you type yourself.

Be especially careful with otpauth:// codes. They contain the secret your login codes are generated from. Only scan one on the security page of a service where you’re turning on two-step verification yourself. Nobody legitimate will send you one to “verify your account”.

Decoding uses the barcode detector built into your browser when there is one. Otherwise a small open-source decoder is loaded from this site. Either way the picture stays on your device, and the camera, which needs your permission, is switched off as soon as a code is read.

Questions people ask

Can scanning a QR code hack my phone?

Reading a code is harmless, since all it gives is text. The risk starts with what happens next, such as opening a phishing page, joining an unknown Wi-Fi network or approving a payment. If you look at the content first, as this page does, nothing happens that you didn’t choose.

How do I scan a QR code that is on my own screen?

Take a screenshot, then drop the image on this page, choose it with the file button or paste it with Ctrl+V (⌘V on a Mac). The picture is decoded locally.

What is quishing?

Phishing delivered through a QR code. One typical form is a sticker on a parking meter or charging station that leads to a fake payment page. Another is an email asking you to scan a code to “keep your account active”, which moves you from a protected work computer to a personal phone.

Why does the reader say no QR code was found?

The code is probably too small in the frame, blurred or cut off. Crop the picture around the code, keep a white margin on all four sides, and try again. Codes other than QR, such as ordinary product barcodes or Data Matrix, aren’t read.

Is a QR code that uses a link shortener dangerous?

Not necessarily. Many QR generators route every code through their own short domain so the destination can be changed later. It does mean the code tells you nothing about where you’ll land, and the destination can change after the code was printed. Use the shortener’s preview feature, or the redirect trace.

Does the camera picture leave my device?

No. Frames are analyzed in the browser and thrown away. The decoded content isn’t transmitted either.