Loading theme
Really Free QR Code Generator··8 min read

Decode, Don't Scan: Read a QR Code's Payload First

A QR code is unreadable by eye, yet its payload takes seconds to extract. How to see the destination before you commit — and what the check cannot tell you.


Decode the image instead of scanning it. A scanner decodes the text and immediately acts on it; a decoder decodes the same text and just shows it to you. That difference is the entire safety margin. If the payload is a URL on a domain you recognise, the code goes there directly. If it is a short link on an unfamiliar domain, a third party sits in the path.

Two situations call for this: you are about to scan a code you do not fully trust, and you are about to print a code generated somewhere else. The same technique answers both.

Step 1 — Read the payload instead of opening it

A QR code holds text. A scanner decodes that text and immediately acts on it — opens the URL, joins the Wi-Fi network, starts the call. A decoder decodes the same text and simply shows it to you. That difference is the whole safety margin.

Photograph or screenshot the code and decode the image on our QR reader. It runs entirely in your browser: the image is never uploaded, and nothing is opened. You get the raw payload as text.

Step 2 — Work out what kind of payload it is

QR payloads follow recognisable formats. Reading the prefix tells you what a scanner would have done.

Payload starts withTypeWhat a scanner would do
https:// or http://URLOpen the page. This is the common case
WIFI:T:WPA;S:…;P:…;;Wi-Fi credentialsOffer to join that network — verify the SSID before accepting
BEGIN:VCARDContact cardOffer to save a contact
mailto: / tel: / smsto:Email, call, SMSPre-fill a message or dial a number
Plain text with no prefixTextDisplay it. Harmless
javascript: or an unfamiliar app schemeSuspiciousDo not open it

Our type pages document each format if you want to see how a legitimate one is built: Wi-Fi, vCard, email, phone, plain text.

Step 3 — Judge the domain

For a URL payload, the domain is what matters — read it right-to-left from the first single slash. In https://pay.cityparking.gov/meter/44, the domain is cityparking.gov. In https://cityparking.gov.pay-now.click/meter/44, it is pay-now.click, and the recognisable part is decoration.

What you seeReading
A domain you recognise, matching the organisationDirect. The code goes where it appears to go
A generic QR shortener you do not ownA third party is in the path and can change or disable the destination
A real brand name as a subdomain of something elseClassic spoofing. Check the rightmost labels
A raw IP addressAlmost never legitimate on printed material

One caution about shorteners: recognising the service does not tell you the destination. Unit 42 puts it directly — "Even security-conscious people who check the URL preview before scanning cannot determine the final destination when presented with shortened links" — and the three services they identify as most abused are ordinary QR-generator redirect domains. A familiar shortener is not reassurance.

Step 4 — Follow the redirect chain

If the payload is a short link and you need to know where it actually ends, resolve it without loading the page. From a terminal:

Run curl -sIL "https://short.example/abc" | grep -i "^location:" — this prints each hop's Location header without executing page content. Watch for how many hops appear: a single hop to the expected destination is ordinary, while several hops through unrelated hosts usually means analytics or advertising intermediaries, each of which sees the request. What a QR proxy logs covers what those hops collect.

Two caveats. A redirect can serve you one destination and someone else another, based on IP, user-agent, or time — so a clean result proves what happened for you, right then, not what a customer in another country will get. And a dynamic code's destination can be changed at any moment afterwards, which is precisely the feature it is sold for.

How do you check a code that arrived by email?

Treat this as a separate and more dangerous case. The NCSC notes that QR codes are used in phishing email specifically because not all security tools scan images, so a code can carry a malicious link past filters that would have caught the same link as text — and scanning moves you onto a personal phone with weaker protection than your work machine.

The check is straightforward. Save the image out of the email rather than scanning it from the screen, decode the file, and read the domain. Do this on the computer, not the phone, so you never leave the protected device. If the domain does not exactly match the organisation the email claims to be from, stop — and reach the organisation the way you normally would rather than through anything in the message.

The tell to watch for is urgency paired with a code: a delivery problem, a tax notice, a mailbox at quota, an account needing verification today. Legitimate organisations very rarely need you to scan a printed square to resolve an urgent account issue. Quishing covers the attack patterns in full.

What can a decoder not tell you?

Being clear about the limits keeps the check honest.

  • Whether the destination is safe. A decoder shows you the address, not the content. A recognisable domain can still host a compromised page.
  • What other people get. A redirect can serve different destinations by IP, user-agent, or time of day. Your clean result describes your request, at that moment.
  • What it will do tomorrow. A dynamic code's destination can be changed at any point after you check it. That is the feature it is sold for, and it is why "I verified it once" is not a durable statement about a dynamic code.
  • Whether the printed copy matches the file. Overlay stickers mean the artwork you approved and the object on the wall can differ. Only decoding a physical copy tells you about the physical copy.

The first and last limits are why the business-side advice in this blog keeps returning to the same point: a static code on your own domain is the only arrangement where a one-time check stays true.

Step 5 — Check your own artwork before it goes to print

This takes a minute and prevents an entire class of expensive problem.

  1. Export the final artwork exactly as it will be printed.
  2. Decode that file — not the one in the generator preview.
  3. Confirm the payload is the URL you intended, on a domain you own.
  4. If it is a short link on someone else's domain, do not print it. Regenerate as a static code.
  5. Scan the printed proof once it arrives, and confirm it still lands where it should.

If a code is already printed and this check comes too late, the hostage recovery guide covers the options that remain. If it stopped working and you do not yet know why, start at why your QR code stopped working.

Frequently asked questions

Can I decode a QR code that is damaged, dirty, or partly covered?
Often yes. QR codes carry Reed–Solomon error correction, and at the highest level roughly 30% of the pattern can be lost while the payload still recovers. What cannot be missing is the three large corner squares — those are the position markers a decoder needs to find and orient the grid at all. A code with a torn corner usually fails; one with a scuffed middle usually does not.
Is it safe to scan a QR code just to look at it?
Most phone scanners show a preview before opening, which is reasonably safe. The risk is habitual tapping through. If you have any doubt, decode the image instead — that removes the risk entirely.
How do I know if a QR code is dynamic?
Decode it. If the payload is a short link on a domain that is not yours and not the destination site's, it is dynamic and routes through that third party. A static code contains the destination URL itself.
Can I tell what a QR code does before scanning if I have no internet?
Yes. Decoding is a local computation — a decoder that runs in the browser needs no network once the page is loaded, and the payload is text you can read yourself.
What should I do if a printed code decodes to a domain I do not recognise?
Do not scan it, and if it is on public infrastructure, report it to whoever owns the surface. The FTC and FBI have both warned about stickers placed over legitimate codes; see quishing.

Codes you generate here always decode to exactly what you typed: URL QR code. More context in the truth about QR code scams.


Ready for a static QR code?

Generate one in your browser — no account, no tracking, no subscription. What you create belongs to you.