QR code security: what quishing is and how to guard against it
A QR code carries a link, and a link can lead anywhere. How quishing works, how to check a code before trusting it, and what we scan for on our end.
Quishing headlines make QR codes sound like malware in printed form. The mechanics are smaller than the headlines. A code stores data, in most uses a link, and the danger sits at the destination, the same threat email taught you to handle. Treat an unknown code like an unknown link and you already have most of the defense.
What is quishing?
Quishing is phishing delivered through a QR code: a fake parking fine with a code that opens a counterfeit payment page, or a sticker pasted over the real code on a menu or a charging station. The pattern itself executes nothing on your phone. It hands your browser a URL, and the counterfeit page does the stealing, the same way a phishing email's link does.
Attackers like codes for one reason: a person can read a suspicious URL in an email and can read nothing in a grid of squares. The code hides the link until the moment of scanning, so the check has to happen at that moment.
How do you check a QR code before trusting it?
- Read the preview. iPhone and Android cameras show the destination domain in a banner before opening anything. Our guide on how to scan a QR code walks through the flow on each platform.
- Judge the domain, and treat https as table stakes. The padlock proves encryption; a counterfeit page can carry one too. The domain name is what tells you who you are talking to.
- Look at the physical code. A sticker sitting on top of another code, on a parking meter, a table card or a poster, is the classic move. Peel-test anything that asks for money.
- Type sensitive details only on domains you already know. A payment page reached from a poster in a car park has earned a minute of suspicion.
What do we check on our end?
Each destination behind a QR Tool code passes a malware and phishing check when you create the code, and again on any edit. The recheck matters because the obvious workaround is a clean link edited into a hostile one after approval, and checking once at creation would wave it through.
Anyone can flag a live code through our report page. We built one kill switch, and it exists for phishing and malware alone: a lapsed subscription does not trigger it, and neither does anything else. Disabling codes is a measure we aim at attackers. For your own codes, printed and in the wild, the promise runs the other way: they never expire.
What should a business printing QR codes do?
Your scanners run the same checks on you, so make the preview banner work in your favor. A short branded domain on your codes shows a wary scanner your name before the page opens, which settles the domain question at a glance. Custom domains come with the Pro plan, and white-label on the Business plan removes our name from hosted pages, so the whole path reads as yours; both sit on the pricing page.
Beyond the domain, keep destinations on sites you control rather than third-party link pages, walk past your own printed codes now and then to check for pasted-over stickers, and print a human-readable URL near the code so a scanner can cross-check what the preview shows.
The code is a link with better packaging. Apply link hygiene when scanning, apply domain trust when printing, and quishing loses most of its surface.
Print a code you can still edit next year
3 dynamic QR codes free, with scan analytics. They never expire, even if you never upgrade. No card needed.
Create a free QR code