HomeBlogHow to Identify a Fake QR Code

How to Identify a Fake QR Code

How to identify a fake qr code before you scan and before you pay — the physical tampering signs, the URL red flags, the payment-screen checks, and what to do if you have already scanned one.

By Aakash Verma, Founder

Three Checks, in Order

Learning to identify a fake qr code is not complicated, and it does not require any app or technical knowledge. It requires three checks in sequence, and each one catches a different category of fraud:

  1. Before you scan — look at the physical code. Catches sticker swaps and tampering.
  2. After you scan, before you tap — read the URL preview. Catches phishing and lookalike domains.
  3. Before you pay or enter anything — read the screen carefully. Catches fraudulent payment requests and credential harvesting.

Most people do none of these, which is precisely why the attacks work. Doing all three takes about five seconds and defeats the overwhelming majority of real QR fraud.

Check One: The Physical Code

The most common QR fraud in India does not involve any clever technology at all. Someone prints a sticker and pastes it over a legitimate code — at a shop counter, a petrol pump, a parking meter, a restaurant table. The signs are visible if you look:

  • A sticker over a printed surface. If the code is on a sticker but everything around it is printed directly onto the board or menu, that is a mismatch worth questioning.
  • Peeling, bubbling or lifted edges. A code applied later rarely sits as flat as the original print.
  • A different paper, finish or colour temperature from the surrounding material. A matte sticker on a glossy standee, or a slightly different white, is a tell.
  • Misalignment. A code that is not square with the frame, logo or text around it was probably not placed by the person who designed the board.
  • A visible edge of a code underneath. Look at the corners. A sticker slightly smaller than the original leaves a rim of the code beneath it.
  • No branding, or branding that does not match. A payment code at a named shop should carry that shop's name. A bare, unbranded code on a branded board is worth a question.
  • A code that looks newer than everything around it. On an outdoor sign that has weathered for a year, a crisp white code stands out.

If anything looks off, ask the shopkeeper or staff member. In a genuine business, they will know their own code. In a defrauded business, you may be the person who tells them.

Check Two: The URL Preview

Every modern phone camera shows the destination before opening it. This preview is the single most effective anti-fraud tool you have, and it is free and already on your phone.

What to look for:

  • Read the domain, not the whole string. The domain is the part immediately before the first single slash. Everything after it is controlled by whoever owns that domain and proves nothing.
  • Watch for lookalikes. sbi-verify.co, hdfc-secure.in, irctc-refund.net — attackers put the real brand name into a domain they control, betting you will read the brand and stop. The brand name appearing inside a domain is not the same as it being the domain.
  • Be wary of subdomain tricks. hdfcbank.com.verify-login.in is not an HDFC domain — the real domain is verify-login.in. Read from the right.
  • Treat unfamiliar shorteners with caution. A generic shortener hides the destination entirely. A branded short domain belonging to the business you are dealing with is a much better sign.
  • Check the spelling character by character on anything financial. paytrn, phonepay, amazom — one substituted letter is the entire attack.
  • Look for https, but do not treat it as proof of anything. Phishing sites have valid certificates too. It is a minimum, not a signal of legitimacy.

Check Three: The Screen Before You Act

If the code passes the first two checks and you have opened the page or the payment app, one more read catches what the others miss:

  • On a UPI screen, read the payee name. Not the amount — the name. If you are paying "Sharma General Store" and the screen says something unrelated, stop. This is the single check that catches a swapped payment sticker after the fact.
  • Never scan to receive. UPI codes initiate payments from you. A code offered as a way to get a refund, claim a prize, or receive money owed is fraudulent by construction, with no exceptions.
  • Question any request for an OTP, PIN or password. No legitimate business needs your UPI PIN or an OTP to give you something. An OTP request on a page you reached by scanning is close to definitive evidence of fraud.
  • Be suspicious of urgency. "Your account will be blocked in 2 hours," "KYC expires today," "claim within 10 minutes" — manufactured time pressure exists to stop you performing exactly these checks.
  • Check the amount is what you expect. Pre-filled amounts in a payment request can differ from what you were told verbally.
  • Do not install anything. A page asking you to download an APK or install a profile to "complete" a transaction is an attack, without exception.

The Specific Scams to Recognise

A few patterns are common enough in India to be worth recognising by name:

  • The sticker swap. A fake QR pasted over a shop's real payment code. Your money goes to the fraudster; the shopkeeper never receives it and often does not find out until they reconcile.
  • The "scan to receive money" trap. Presented as a refund, a prize, a marketplace buyer paying you, or a returned deposit. UPI has no scan-to-receive mechanism. This is always fraud.
  • The parking or challan code. A fake code on a windscreen notice or a parking board, leading to a convincing payment page.
  • The delivery-tracking page. A code on a package or a slip leading to a fake courier site that asks for a "redelivery fee" and card details.
  • The KYC-expiry code. A code in an SMS or a printed notice claiming your bank or wallet KYC needs re-verification, leading to a credential-harvesting page.
  • The marketplace buyer. On classifieds platforms, a "buyer" sends a QR code claiming it will transfer payment to you. It will not; it will take payment from you.

Our QR code fraud in India guide covers the landscape and what to do after the fact in more depth.

If You Have Already Scanned or Paid

Speed matters more than anything else here.

  • If you have only scanned and not acted, you are almost certainly fine — scanning alone does not transfer money or install anything. Close the page.
  • If you entered credentials, change that password immediately, on the real site or app reached independently, and enable two-factor authentication if it is not already on.
  • If you made a payment, contact your bank or payment provider immediately through their official app or published number — not any number shown on the suspicious page. Ask them to raise a fraud dispute.
  • Report it. In India, financial cyber fraud can be reported on the National Cyber Crime Reporting Portal (cybercrime.gov.in) and via the national cyber-fraud helpline 1930. Reporting quickly meaningfully improves the chance of funds being held or recovered.
  • If you installed something, disconnect from the internet, uninstall it, and change passwords for anything accessed from that device.
  • Tell the business. If the fake code was on a shop's counter, the shopkeeper needs to know — they are also a victim, and they can remove it before the next customer.

If You Are the Business Displaying the Code

A swapped sticker on your counter damages your customer and your reputation, and you are usually the last to know. Practical defences:

  • Inspect your codes on a schedule. Daily for payment codes at a counter, weekly for outdoor and high-traffic placements. Photograph the correct state so staff can compare.
  • Laminate or frame payment codes, or mount them under acrylic so a sticker cannot be applied cleanly.
  • Brand the code and its surround. A code inside your own branded frame, with your business name on it, makes a swap visibly obvious.
  • Use a branded short domain (Premium plan, ₹14,999/month) so the URL preview itself is a verifiable signal.
  • Train staff to check. The person at the counter is your best detection system, if they know to look.
  • Watch your analytics. A sudden drop in scans on a placement that should be busy can mean your code has been covered by someone else's.
  • Use dynamic codes. If one of your codes is ever compromised or misused, you can repoint it instantly rather than recalling printed material.

Create your QR code on SMLLR — dynamic destinations mean a compromised link is a dashboard fix, not a reprint.

Frequently Asked Questions

How can I tell if a QR code is fake before scanning it?

Look at the physical code. A sticker over a printed surface, peeling or lifted edges, a different paper finish from its surroundings, misalignment with the frame around it, a visible rim of another code underneath, or missing branding are all signs of a swapped sticker. If anything looks off, ask the shop staff — in a genuine business they will know their own code.

What should I look for in the URL preview?

Read the domain — the part immediately before the first single slash — not the whole string. Watch for lookalikes like sbi-verify.co and subdomain tricks like hdfcbank.com.verify-login.in, where the real domain is the last one before the slash. Check spelling character by character on anything financial.

Is a QR code with https safe?

No. HTTPS only means the connection is encrypted, not that the site is legitimate — phishing sites obtain valid certificates routinely. Treat it as a minimum requirement rather than any kind of signal that the destination can be trusted.

How do I spot a fake UPI QR code at a shop?

Check the payee name on your payment screen before confirming, not just the amount. If you are paying a named shop and the screen shows something unrelated, stop. This is the one check that catches a swapped payment sticker after you have already scanned it.

Can someone steal money just by me scanning their QR code?

No. Scanning alone does not transfer anything — a UPI code can only initiate a payment that you then have to approve with your PIN. The danger is approving that payment without reading the payee name, or entering your PIN on a fake page that looks like your payment app.

What should I do if I already paid a fake QR code?

Act immediately. Contact your bank or payment provider through their official app or published number — never a number shown on the suspicious page — and ask them to raise a fraud dispute. Report it on the National Cyber Crime Reporting Portal (cybercrime.gov.in) and the national cyber-fraud helpline 1930. Speed meaningfully improves the chance of funds being held.

How do I protect my business's QR codes from being swapped?

Inspect them on a schedule — daily for counter payment codes, weekly for outdoor placements — and photograph the correct state so staff can compare. Mount payment codes under acrylic or in a branded frame so a sticker cannot be applied cleanly, and use a branded short domain (Premium plan, ₹14,999/month) so the URL preview itself verifies you.

Related Resources