QCan I check a QR code from a photo I already took?
Yes, upload the saved image to a QR URL scanner, which decodes the embedded data and analyzes the link separately from opening it.
Extract and safely audit web links encoded in QR codes. Detect quishing scams, malicious downloads, and hidden redirect chains.
Upload, browse, or drag & drop any QR code image (PNG, JPG, SVG) into the dropzone.
The scanner automatically decodes the embedded hyperlink or web address.
Click 'RUN AUDIT' to execute real-time threat, SSL, and redirect analysis.
Inspect the verified destination URL safely before opening.
Link and URL inspection uses multi-layered heuristic analysis to trace redirect hops, calculate domain entropy, and isolate phishing evasion techniques before client browser execution.
Traverses HTTP 301/302/307/308 responses, client-side meta refresh tags, and JavaScript location replacements to expose final landing pages obscured by intermediary tracker cloaks.
Evaluates character frequency distribution across hostnames and URL path tokens. Flags randomized strings (≥ 3.8 bits/char) characteristic of Domain Generation Algorithms and disposable payloads.
Detects Cyrillic, Greek, and Latin cross-script visual lookalike substitutions in Internationalized Domain Names (IDNs), uncovering spoofed bank, portal, and authentication login domains.
Inspection executes in an isolated sandbox isolate. Neither the scanned URL, client IP address, nor response headers are written to persistent disk or forwarded to advertising telemetry.
Direct, peer-reviewed engineering answers to core deployment, troubleshooting, and compliance questions.
Yes, upload the saved image to a QR URL scanner, which decodes the embedded data and analyzes the link separately from opening it.
Yes, fraudulent QR stickers placed over legitimate ones at parking meters, EV chargers, and events are a growing scam vector — always check the decoded URL first.
No, QR codes can also encode Wi-Fi credentials, contact cards, or plain text; a QR scanner should identify the data type before assuming it's a URL.
The QR code itself can't install malware, but the link it opens can trigger downloads or exploit browser vulnerabilities — checking the destination first prevents this.
Look for stickers that appear layered over another code, slightly misaligned, or placed somewhere unusual — then verify the decoded link with a QR URL scanner before trusting it.
Treat them the same as suspicious links — decode and check the destination URL with a scanner before opening, especially if the message creates urgency.
Quishing is QR-code phishing, where a malicious code hides a scam link. A QR URL scanner decodes the code and checks the destination before you ever open it in a browser.
The QR code itself is just data, but it can link to a site that downloads malware or steals credentials — scanning the destination URL first prevents this.
Upload the QR code image to a QR URL scanner, which decodes it and analyzes the embedded link separately from your device.
Not always — scammers place fraudulent stickers over legitimate QR codes in parking lots, restaurants, and events, so checking the decoded link first is a smart habit.
Watch for mismatched domains, misspelled brand names, unusual TLDs, and shortened URLs — a QR URL scanner flags many of these automatically.
Quishing is a phishing technique where attackers embed malicious URLs in QR codes. When scanned, the victim is directed to a phishing site or malware download, bypassing traditional link scanners.
IncogSay uses a client-side QR decoder (jsQR) to extract the URL from your uploaded image, then runs the full URL safety analysis locally — your image is never uploaded to any server.
PNG, JPG/JPEG, WEBP, and GIF formats are supported. The QR code should be clear and well-lit for accurate decoding.
Yes. If you receive a suspicious QR code in an email or document, take a screenshot and upload it to IncogSay for analysis.
No. QR code decoding is executed entirely inside your browser session using web APIs. The image bytes never leave your device.
Yes. Once the embedded URL is extracted from the QR image, IncogSay expands any redirect hops to inspect the true final landing page.
Yes, upload the QR code image file directly to a QR URL scanner on desktop, which decodes it the same way a camera would, without needing a phone at all.
These typically encode ticket data, not URLs, but if a ticket link directs you to a website to 'verify' or 'claim' something, it's worth checking that URL before entering any information.
Yes, some tools support scanning multiple QR code images at once, useful for businesses verifying a batch of printed codes still point to the correct, untampered URLs.
Don't proceed to the site — report the QR code if it's in a public or business location, since it may have been physically tampered with by a scammer's sticker overlay.
Generally low risk from the restaurant itself, but a scanner check is worth it if the QR code sticker looks altered, peeling, or placed oddly compared to the venue's other signage.
Basic QR decoding (reading the raw text/URL) can happen offline, but checking that URL's safety against threat databases requires an internet connection to a scanning service.
A normal QR app usually opens the link immediately, while a QR URL scanner decodes the link first and checks its safety before you're ever taken to the destination site.
Retailers using QR codes for promotions, loyalty programs, or payment are targets for sticker-swap scams where fraudsters overlay a fake QR code on legitimate in-store displays.
Yes, attendees scanning codes for schedules, Wi-Fi, or networking apps should verify the destination, since public event settings are common targets for QR code tampering.
Yes, scammers sometimes place fraudulent QR codes on yard signs directing to fake listing or payment pages — checking the decoded link before visiting protects against this specific scam.
Yes, delivery-related QR code scams have increased, often mimicking shipping carriers to steal personal or payment information — always verify the decoded URL first.
Yes, periodically re-scanning your own public-facing QR codes with a scanner confirms they still link correctly and haven't been physically swapped by someone else.
A QR URL scanner extracts the encoded website address from a QR code image without automatically opening it in your browser. This protects you from 'quishing' (QR code phishing attacks) by allowing you to inspect the URL, redirect chains, and security score first.
Quishing is a social engineering attack where scammers place malicious QR codes in physical locations (parking meters, restaurant tables, mailers) or PDF invoices. Scanning with your phone camera normally opens the website immediately, exposing you to credential theft.
Take a photo or screenshot of the QR code. Upload or drag-and-drop the image file into IncogSay's QR URL scanner. The tool decodes the target URL and executes a safe edge audit before you decide whether to visit.
Yes. Once the encoded URL is extracted, our scanner traces all 301/302 HTTP redirects and inspects the final landing page for phishing and malware threats.
Yes. IncogSay provides a 100% free online QR code link scanner, QR URL extractor, and quishing defense tool with zero data logging.