People & Platforms

QR Code ("Quishing") Scam Checker

A QR code is a link you cannot read before opening — which makes it the perfect wrapper for phishing. Fake codes now appear on parking meters, restaurant tables, packages, and in texts about tolls and deliveries. Describe where you found the code and what happened after scanning, and the AI will tell you whether it matches known quishing patterns — and what to do if it does.

scamanot.com — qr code checker

Works with physical codes and digital ones — parking meters, menus, packages, texts, emails, and flyers.

🔒 Content you paste is never stored, logged, or shared. It is processed server-side and discarded immediately after your result is returned. If a scanned page asked for a login or payment: treat it as hostile, close it, and change any password you entered from a clean browser. This tool informs your decision — it does not guarantee outcomes.

Content never stored
AI runs server-side only
No account required
Cloudflare protected

How quishing actually works.

The QR code isn't the scam — it's the delivery vehicle. These are the patterns the AI checks your encounter against.

The Sticker Overlay

A fraudulent code stuck over the real one on parking meters, EV chargers, menus, and posters. Raised edges or misalignment around a code are worth a look before every scan.

The Unexpected Text

Unpaid tolls, package redelivery, account alerts — arriving with a QR code or link you never asked for. Unsolicited codes carry the same risk as unsolicited links: total.

The Instant Login Page

Scanning leads straight to a "sign in" for your bank, Microsoft, or Amazon. Real codes on legitimate materials rarely demand credentials first — phishing pages always do.

The Payment Redirect

Parking or charging codes leading to unfamiliar payment processors instead of the city's or vendor's official app. Your card details are the entire objective.

The Disguised URL

Shorteners and lookalike domains (rnicrosoft-secure.com) hide the destination. Most phone cameras preview the URL before opening — the habit of reading it is the defense.

The Package You Didn't Order

A mystery delivery with "scan to see who sent you a gift." Brushing-adjacent quishing that trades curiosity for credentials or card numbers.

Three scans, checked.

The same trick in a parking lot, a text thread, and an inbox.

3
Low
The Meter Sticker

A parking meter's QR code leads to "quickpay-parking.net" asking for your plate and card. The city's parking app is mentioned nowhere, and the sticker sits slightly crooked over another code.

Physical overlay quishing — cheap stickers, printed by the hundred, harvesting cards all day in busy lots. Cities take payment through their named apps and official sites; an unfamiliar processor at a meter is a scam by default.

5
Caution
The Toll Text

"FasTrak: Our records show an unpaid toll of $6.49. To avoid a $50 late fee, settle today," with a QR code — and the linked page is a convincing DMV-styled form requesting card and license details.

Unpaid-toll smishing is one of the highest-volume scams in the country, and the QR variant dodges link-scanning filters. Tolling agencies bill by mail and through accounts you log into directly — never by QR-coded text. The $50 late fee is the pressure; the form is the harvest.

8
High Risk
The Office MFA Reset

A work email from "IT Security," correctly branded, says your multi-factor authentication expires today — "scan with your phone to re-enroll." The code opens a flawless Microsoft 365 login that accepts your password and then asks you to approve an MFA prompt.

Enterprise quishing: the QR moves the attack from your protected work laptop to your unfiltered phone, and approving that prompt hands the attacker a live session. Anything time-boxed about MFA arriving by email deserves a call to real IT first. If you approved a prompt — report it to IT immediately; minutes matter.

About QR code scams.

For modern, updated phones — effectively no. Scanning only reads the encoded URL; the danger begins with what you do next: opening the link, entering credentials, downloading a file, or approving a prompt. This is genuinely good news, because it means the defense is entirely in your hands. Scanning a suspicious code and then closing the preview costs you nothing. The scam needs your cooperation on the page it leads to — deny it that, and the code is just ink.
Your phone already shows you. Both iPhone and Android camera apps display the destination URL in a small banner before you tap through — the entire skill is pausing to read it. Look for the actual domain (the part before the first single slash): city services should be on .gov or the city's known domain, companies on their exact real domain. Shortened links (bit.ly and similar), IP addresses, and near-miss spellings are all reasons to close the preview. For payments and logins, skip codes entirely and type the official address yourself.
Fraudsters print QR code stickers pointing at fake payment sites and stick them on parking meters, pay stations, and EV chargers — often directly over the legitimate code. Drivers in a hurry scan, land on a professional-looking payment page, and enter card details that go straight to the scammer, sometimes alongside a fake "parking session" confirmation that leaves them ticketed too. Before scanning at any meter: check whether the code is a sticker sitting on top of another, and prefer the city's official parking app or the phone number printed on the meter itself.
Almost certainly not. Unpaid-toll smishing has become one of the highest-volume text scams in the US, and tolling agencies — E-ZPass, FasTrak, SunPass and the rest — do not send payment demands with QR codes or links by text. Real toll billing arrives by mail or through the account you already hold, accessed by typing the agency's site yourself. Delete the text, and if you're genuinely unsure whether you owe a toll, look up the agency's official site independently and check there. The late-fee countdown in the message is the pressure tactic, not a fact.
No. Per our Security Policy Framework §3.1, nothing you submit is stored in our database. Your description is processed server-side, analyzed, and discarded immediately after your result is returned. We never retain, sell, or train on your submissions.
Respond to what you entered. A password: change it immediately from a different, trusted browser, change it anywhere it was reused, and turn on two-factor authentication. Card details: call the number on the back of the card, report it, and request a replacement — issuers handle this daily and dispute fraudulent charges. Work credentials: report to your IT team right away, especially if you approved an MFA prompt, because minutes determine whether a session gets hijacked. Then report the scam at reportfraud.ftc.gov — and if it was a physical sticker, tell the business or city so it comes down before the next person scans.