Are QR Codes in Emails Safe? What to Know Before You Scan
The email looks totally normal. It's from your bank — or maybe PayPal, Amazon, UPS. The logo is right, the formatting looks professional, and there's no suspicious link anywhere in the message. Just a QR code and a simple instruction: “Scan to verify your account.” Feels legit. That's exactly the point.
QR codes in email have become one of the fastest-growing phishing techniques out there, and it's almost never talked about. Most people know to be suspicious of a sketchy link — but a QR code in an email? That feels different. It feels like something a real company would do. Attackers know this, and they're counting on it.
Here's what's actually happening, how to spot it, and what to do when you get one of these emails.
Why Attackers Use QR Codes in Emails
This one has a really clean explanation. Traditional spam filters and email security tools work by scanning the text of your emails — they look for suspicious URLs, known phishing domains, malicious links, and other red flags embedded in the message itself. If a filter sees a link to paypa1-verify.net, it flags the email. Done.
But a QR code is just an image. The email security filter sees a PNG or JPEG file — not a URL. It can't read what's encoded inside. So the attacker hides the phishing link inside the QR code image, the filter sees nothing suspicious, and the email lands in your inbox looking completely clean.
It's a deliberately simple workaround for one of the most common email defenses. And it works because QR codes are now normal enough that seeing one in a legitimate-looking email doesn't immediately raise a red flag the way a weird link would.
What Makes a QR Code Email Suspicious
No single sign is definitive, but here are five things that should make you slow down — and if you see more than one, treat the email as a threat.
You weren't expecting the email.
Your bank does not send unsolicited QR codes. Neither does PayPal, Amazon, or UPS. Legitimate companies that need you to verify something will direct you to log in to your account on their website — through a typed URL or a browser bookmark — not through a code in an email. If you didn't initiate the action, be suspicious of the email.
The language is urgent.
“Your account will be locked in 24 hours.” “Verify immediately to avoid suspension.” “Action required — confirm your identity now.” Urgency is the oldest move in phishing because it short-circuits careful thinking. Real account security issues don't come with countdown clocks.
The sender address doesn't match.
Look at the actual email address, not just the display name. An email can say “PayPal Security Team” in the From field while the actual address is security@paypal-alerts.co. Legitimate emails from major companies come from their official domain — paypal.com, amazon.com, ups.com. Not variations of it.
The reason for scanning is vague.
“Verify your identity.” “Confirm your shipping address.” “Complete your security check.” These are deliberately generic. A real company email asking you to take a specific action would explain what action, why, and what specific thing needs to be resolved — not a vague request to “verify” something.
The QR code is in a PDF attachment.
This is the double-obfuscation version. The email looks like a routine document — an invoice, a receipt, a shipping notice — and the QR code is buried inside the attached PDF. Two layers of packaging to get past filters and feel legitimate. This pattern is increasingly common in attacks targeting corporate employees.
What Actually Happens When You Scan One
When you scan a QR code from an email, your phone's browser opens the URL encoded inside. From there, the attack usually takes one of three forms:
- •Credential harvesting. The page looks exactly like your bank's login page, or PayPal's, or Amazon's. You enter your username and password. They're now captured.
- •Tracking and fingerprinting. Even if you don't type anything, loading the page can set cookies or tracking pixels that identify your device, confirm your email is active, and build a profile for future targeting.
- •Drive-by downloads. On vulnerable devices — especially older Android phones or unpatched browsers — some pages attempt to trigger automatic file downloads. This is less common but more damaging.
Here's what makes this especially effective: the attack moves from your email inbox to your personal phone. Your employer's IT department might monitor your work laptop. They're not monitoring your phone browser. Corporate email security tools stop at the email — they have no visibility into what your phone does when you scan the code.
The Safe Approach: Read the URL Before You Tap
This is genuinely the best defense, and it's simpler than it sounds. Before you open any URL from a QR code — especially one from an email — read the decoded URL first.
Ask yourself a few quick questions: Does the domain match the organization the email claims to be from? Is it actually HTTPS? Does it look like a typosquat — something like paypa1.com or amazon-verify.net? Is the root domain familiar, or is it a random string before a legitimate-looking suffix?
Focus on the root domain — the part right before the first single slash. That's where fakes hide. A URL can look long and official while pointing somewhere completely unrelated. The only part that matters for trust is the root domain.
If anything looks off — if you're not 100% sure — don't tap. You can always go to the company's website directly by typing the address yourself or using a bookmark. If your account actually has an issue, it'll show up there too.
SnapScan always shows you the decoded URL before anything opens.
One-time $14.97. No subscription. No auto-open.
Get SnapScan — $14.97 One-TimeHow SnapScan Helps
Most phone cameras and built-in scanners auto-open QR code URLs immediately — sometimes with barely a glance at where they're going. The URL banner flashes for a second and then you're already on the page.
SnapScan works differently. It shows you the full decoded URL — or text, or contact info, or whatever is actually inside the code — before anything happens. Nothing opens automatically. You read the URL, decide whether it looks right, and then tap to open if you want to. That half-second pause is exactly where you catch a typosquatted domain or a URL that doesn't match the claimed sender.
It also doesn't auto-open anything in the background, send your scan history anywhere, or ask for permissions it doesn't need. If you want to understand more about the privacy trade-offs in QR scanner apps, that post has the full breakdown of what the free options are actually doing with your data.
And if you haven't thought about what permissions your scanner is asking for, it's worth a look — most people are surprised. A QR scanner only needs your camera. If it's asking for more, that's a different kind of risk. The post on QR scanner permissions covers exactly what each permission does and why it's asking.
This post is part of a growing series on QR code safety — if you want the broader picture on physical fake QR codes placed in public spaces, that one covers parking meters, restaurant tables, and delivery notices in detail.
FAQ
Can a QR code in an email give me a virus?
The QR code itself can't — it's just encoded data. What it can do is open a URL that attempts to download something malicious, or land you on a phishing page that harvests your credentials. The risk isn't in scanning the code; it's in what you do after it opens. On most modern, updated phones the drive-by download risk is low — but credential harvesting is very real, which is why reading the URL before you tap matters.
How do I tell if a QR code email is legitimate?
Check the sender address (not just the display name) against the company's known domain. Look for urgency language — it's almost always a sign of phishing. And when you scan the code, read the decoded URL before opening it: does the domain match the company it claims to be from? A legitimate email from your bank will point to your bank's actual domain, not a lookalike. When in doubt, go to the company's website directly instead of using the code.
Do major companies — banks, Amazon, UPS — send QR codes in emails?
Rarely, and almost never for account verification or security actions. When they do use QR codes in email, it's typically for things like mobile app download links or loyalty program check-ins — not for asking you to log in or confirm your identity. If you receive an unsolicited email from a financial institution or major retailer asking you to scan a QR code to verify your account, treat it as phishing until proven otherwise. Log in to the account directly from your browser to check if there's actually an issue.
What should I do if I scanned a suspicious QR code?
Close the browser immediately and don't enter any information on the page. If you already entered a password, change it right away on the real site. If you entered payment information, contact your bank or card issuer. Most of the damage from QR code email phishing happens at the credential entry step — catching it before you type anything limits your exposure significantly. If the browser prompted you to download or install something, check your downloads folder and delete anything unfamiliar, and run a security scan if you have one available.
QR codes in emails are a growing attack vector precisely because they look harmless. The safest habit is simple: read the URL before you tap. SnapScan makes that easy — $14.97 once, no subscription.
See every QR code's URL before anything opens. One-time $14.97, no subscription.
Get SnapScan — $14.97 One-Time