A QR code cannot contain a virus, and scanning one cannot install anything. It is a short piece of text written in squares — completely inert. Your phone reads the text and offers to do something with it, and every consequential thing that follows requires you to tap.

That said, the honest answer is not simply “yes, safe”. QR codes have a specific property that makes them useful for fraud: a human being cannot read one. A suspicious link in an email can be inspected before clicking. A suspicious QR code looks exactly like a legitimate one.

How QR phishing actually works

Sometimes called quishing, and the mechanics are dull rather than sophisticated:

In every case the QR code is only transport. The attack is an ordinary phishing page, and the code is what stops you seeing where you are going.

What to check before you tap

Both iPhone and Android show you the destination before opening it. That preview is the single most useful protection available, and it takes a second to read.

A note on shortened links

Dynamic QR codes work by encoding a redirect, so the domain the preview shows is the QR provider’s rather than the final destination. That is not a red flag by itself — it is how editable and trackable codes function at all — but it does mean the preview tells you less. Judge those on where you found the code and who is asking, rather than on the URL alone.

If you publish QR codes

The risk runs the other way too: someone covering your code costs your customers money and your reputation the incident.

The short version

Scanning is safe. Tapping without reading is the risk, and the fix costs one second of attention. Treat a QR code exactly as you would treat a link from the same source — because that is all it is.

If you are trying to work out why your own code will not scan rather than whether it is safe, that is a different list.