QR peek
A phone camera opens a QR code almost as soon as it sees one. This reader stops one step short. It decodes the code, shows what’s written in it and what a phone would do with it, and leaves the decision to you.
Phones start the back camera when you choose “Scan with the camera”. From a computer, a screenshot or a photo of the code works: drop the file, or paste it with Ctrl+V (⌘+V on a Mac).
🔒 Decoding takes place on your device. Camera frames and pictures stay in your browser, and what the code says is not passed to anyone.
A QR code is a short piece of text
Those black and white squares spell out characters, a few thousand at most, with error correction so the code still reads when part of it is dirty or covered by a logo. That’s all there is in it. No program, no hidden destination. The trouble comes from what the scanning device does next. If the text begins with https://, the phone offers to open it. Other prefixes trigger other actions, and nobody can tell which by looking at the squares.
That’s why fraud has moved to QR codes. A link in an email goes through spam filters, and you can hover over it to inspect it. Print the same link as a code on a parking meter, a restaurant table or a fake delivery notice, and it skips the filters and gets opened on a phone, where the address bar shows very little.
The kinds of content the reader recognizes
| Starts with | What a phone would do | What to check |
|---|---|---|
http://, https://, www. | Open a web page | The domain in bold |
WIFI: | Join a wireless network | Who runs the network; open networks and WEP are flagged |
BEGIN:VCARD, MECARD: | Add a contact | The email and website fields |
mailto:, SMSTO:, sms:, tel: | Prepare a message or a call | The recipient; short codes and premium-rate numbers are flagged |
otpauth:// | Add an account to an authenticator app | That you’re the one setting it up |
bitcoin:, ethereum: and similar | Prepare a cryptocurrency transfer | Everything, because it can’t be reversed |
000201…, BCD, upi:// | Prepare a card, bank (SEPA) or UPI payment | Payee name and amount |
geo:, BEGIN:VEVENT | Open a map, add a calendar event | Nothing in particular |
Anything else is shown as plain text. If there’s a web address buried in that text, it gets the same examination as a link. A code holding a javascript:, data: or file: address is marked red.
How a link is examined
Most codes hold a web address, and the reader takes it apart without requesting it.
- Domain. The registrable domain is shown in bold and tested for mixed alphabets, invisible characters and resemblance to well-known brands, with the same engine as the lookalike character detector. Anything before an
@gets called out, becausehttps://city-parking.example@payments.example.net/takes you to payments.example.net. - Encryption. A plain
http://address is yellow. - Shorteners. About fifty services such as bit.ly, tinyurl.com and qrco.de are recognized. The real destination is stored on the shortener’s server and can’t be read from the code. For bit.ly, adding
+to the end of the address shows a preview page. TinyURL haspreview.tinyurl.com. - Tracking parameters.
utm_source,fbclid,gclidand their relatives are listed, and you get a second copy of the address without them. - Payment words. If the address mentions paying, parking, a fine, a toll or an invoice, a note reminds you to check for a sticker placed over the original code.
The decoded text is never turned into a clickable link, with one exception. Ordinary web addresses get an “Open anyway” link at the bottom, which opens a new tab without sending a referrer.
What reading the code can’t tell you
The reader sees the address, not the page. A domain with nothing wrong in its spelling can still host a copy of a bank login form. To test the destination itself, paste the address into the unsafe-site lookup or follow it hop by hop with the redirect trace. Both run from our server, not from your phone.
It can’t see the physical world either. Run a finger over a code on a public machine, because a sticker has an edge. For any payment, the safest route is the operator’s app or a web address you type yourself.
Be especially careful with otpauth:// codes. They contain the secret your login codes are generated from. Only scan one on the security page of a service where you’re turning on two-step verification yourself. Nobody legitimate will send you one to “verify your account”.
Decoding uses the barcode detector built into your browser when there is one. Otherwise a small open-source decoder is loaded from this site. Either way the picture stays on your device, and the camera, which needs your permission, is switched off as soon as a code is read.
Questions people ask
Can scanning a QR code hack my phone?
Reading a code is harmless, since all it gives is text. The risk starts with what happens next, such as opening a phishing page, joining an unknown Wi-Fi network or approving a payment. If you look at the content first, as this page does, nothing happens that you didn’t choose.
How do I scan a QR code that is on my own screen?
Take a screenshot, then drop the image on this page, choose it with the file button or paste it with Ctrl+V (⌘V on a Mac). The picture is decoded locally.
What is quishing?
Phishing delivered through a QR code. One typical form is a sticker on a parking meter or charging station that leads to a fake payment page. Another is an email asking you to scan a code to “keep your account active”, which moves you from a protected work computer to a personal phone.
Why does the reader say no QR code was found?
The code is probably too small in the frame, blurred or cut off. Crop the picture around the code, keep a white margin on all four sides, and try again. Codes other than QR, such as ordinary product barcodes or Data Matrix, aren’t read.
Is a QR code that uses a link shortener dangerous?
Not necessarily. Many QR generators route every code through their own short domain so the destination can be changed later. It does mean the code tells you nothing about where you’ll land, and the destination can change after the code was printed. Use the shortener’s preview feature, or the redirect trace.
Does the camera picture leave my device?
No. Frames are analyzed in the browser and thrown away. The decoded content isn’t transmitted either.