A QR code cannot contain a virus, and scanning one cannot install anything. It is a short piece of text written in squares — completely inert. Your phone reads the text and offers to do something with it, and every consequential thing that follows requires you to tap.
That said, the honest answer is not simply “yes, safe”. QR codes have a specific property that makes them useful for fraud: a human being cannot read one. A suspicious link in an email can be inspected before clicking. A suspicious QR code looks exactly like a legitimate one.
How QR phishing actually works
Sometimes called quishing, and the mechanics are dull rather than sophisticated:
- Sticker over the top. A fake code is printed and stuck over the real one — on a parking meter, an EV charger, a restaurant table card, a payment terminal. The victim scans what they believe is the operator’s code and lands on a convincing copy of a payment page.
- Codes in email. A QR code image inside a phishing email survives link scanners that only read text, and moves the victim onto a personal phone, which is usually less protected than a work laptop.
- Fly-posted codes. A code on a flyer or a lamp post offering a prize, a survey or a refund, leading to a credential-harvesting page.
In every case the QR code is only transport. The attack is an ordinary phishing page, and the code is what stops you seeing where you are going.
What to check before you tap
Both iPhone and Android show you the destination before opening it. That preview is the single most useful protection available, and it takes a second to read.
- Does the domain match who you think you are dealing with? Not whether it contains the brand name — whether it is the brand’s domain.
pay-yourbank-secure.comcontains a bank’s name and belongs to somebody else. - Is there a sticker? Physically. Run a thumbnail over the corner of a code on any payment device or public terminal. A code stuck over another code is the clearest warning sign there is.
- Are you being asked to pay, or sign in, off the back of a scan? Legitimate operators do use QR codes for payment, so this is not automatically wrong — but it is exactly the point to stop and reach the site yourself instead.
- Does it want an app from outside a store? Never install from a link that arrived via a code.
- Was it unsolicited? A code on a flyer promising money is the same offer as the email version, with less to inspect.
A note on shortened links
Dynamic QR codes work by encoding a redirect, so the domain the preview shows is the QR provider’s rather than the final destination. That is not a red flag by itself — it is how editable and trackable codes function at all — but it does mean the preview tells you less. Judge those on where you found the code and who is asking, rather than on the URL alone.
If you publish QR codes
The risk runs the other way too: someone covering your code costs your customers money and your reputation the incident.
- Use a domain people recognise. A code resolving through your own domain lets customers verify it in the preview. A generic shortener does not.
- Print the destination beside the code where you can — “scan, or visit example.com/menu”. It gives people a route that does not involve trusting the squares, and makes a substituted sticker obvious.
- Laminate or seal codes in public places, so a sticker cannot be applied cleanly over them.
- Check them physically, on a schedule. Codes on the street get covered, and nobody reports it.
- Use dynamic codes so that if a destination is ever compromised you can repoint every printed copy immediately rather than reprinting.
The short version
Scanning is safe. Tapping without reading is the risk, and the fix costs one second of attention. Treat a QR code exactly as you would treat a link from the same source — because that is all it is.
If you are trying to work out why your own code will not scan rather than whether it is safe, that is a different list.