Check first, then open.

Is this QR code safe?

QRTrust checks every QR code against Europe's largest quishing database before you open it. Report suspicious codes directly – we take care of the follow-up.

or paste a link

Free · no sign-up · operated in Germany

How it works

How the QR code check works

  1. 1

    Capture the QR code

    Scan the code with your camera, upload a photo or paste the link. The link is not opened.

  2. 2

    Wait for the result

    QRTrust compares the destination with its own quishing database and other phishing lists and follows redirects to the final page. The result appears within a few seconds.

  3. 3

    Decide or report

    Only open the link if the result is green. Report a suspicious code directly, optionally with a photo and location. We take care of everything else.

Traffic light

What does the result mean?

GreenThe link has not been flagged so far.
The destination is neither in the QRTrust quishing database nor on the phishing lists queried, and the check found no typical signs of fraud. There is no absolute certainty: new scam pages are often only a few hours old. Only enter login or payment details if you know the provider.
YellowPlease check the link yourself as well.
The link is not known to be fraudulent but shows features common in quishing, such as a very new domain, several redirects or a name resembling a well-known brand. This does not necessarily mean it is a scam. If in doubt, open the provider's site via its official app or an address you type yourself.
RedThe link has been flagged as phishing or quishing.
The destination is on a block list, has already been reported as quishing or shows clear signs of fraud. Do not open the link and do not enter any data. If you found the code on a parking meter, a charging station or in a letter, please report it.

Our tip: Bookmark qrtrust.de or add it to your phone's home screen. That way the check is at hand when you are standing at a parking meter or charging station.

Follow-up

After your report, we take care of the rest

At QRTrust, a report does not end up in an inbox. We follow up on every confirmed case so that the fake code disappears and others are warned.

  1. 1

    Secure evidence

    We capture the scam page with a screenshot, timestamp and technical data before it goes offline.

  2. 2

    Inform the company

    We inform the company whose name is being misused, such as the bank, the parking operator or the charging provider.

  3. 3

    Work with the authorities

    We work with the relevant authorities and provide the secured evidence for prosecution.

  4. 4

    Warn others

    Confirmed cases are added to the quishing database and the quishing map. Every further scan of the code is then flagged as dangerous.

Background

What is quishing?

Quishing is phishing via QR code. Fraudsters stick fake codes on parking meters and charging stations, print them on fake bank letters or parking tickets and send them by email. The code leads to a cloned page that asks for login or card details.

Unlike a link in an email, a QR code does not reveal where it leads. That is exactly what the perpetrators exploit.

How to recognise a fake QR code

Sticker over the original
A code stuck over the original has a noticeable edge or sits at an angle. Many cities do not use QR codes on parking meters at all.
Unusual address
Shortened links, misspelled brand names or unusual endings such as .live or .top are warning signs.
Immediate login or payment
The page immediately asks for bank access, a TAN or card details, although you only wanted to park or charge.
Time pressure
Supposed account blocks, reminders or deadlines: pressure is meant to stop you from checking calmly.

FAQ

Frequently asked questions

I have already entered my details. What now?
Have your card or online banking blocked immediately through your bank. Change affected passwords, check your account activity and report the incident to the police. Your bank will never call you to have a transfer or TAN confirmed.
How do I report a suspicious QR code?
Check the code here first. If the result is yellow or red, a button to report it appears. You can add a photo and the location. QRTrust secures evidence such as a screenshot and timestamp, informs the affected company and works with the authorities. Confirmed cases appear in the quishing database and on the quishing map.
Is the link opened during the check?
No. Your device does not open the page. The check runs on QRTrust's servers, which follow redirects and analyse the destination.
What happens to the links that are checked?
QRTrust processes the checked addresses on servers in Germany. For the check, the address is also compared with external phishing lists. You do not need an account or have to provide personal data to use the check.
Does the check cost anything?
No. The check is free for private individuals and requires no sign-up. Enterprise offerings are available for municipalities, operators of parking meters and charging stations, and companies.

Made in Germany

Data Protection Made in Germany

Your data stays in Germany - guaranteed GDPR compliant.

Hosted in Germany
Frankfurt am Main
GDPR Compliant
EU Standards
Real-time Analysis
<100ms
TLS 1.3
Encrypted
Multi-Layer
Local threat database, Self Trained AI
EU Only
No third countries