Skip to content
UseQR
ESC

Jump to

MOVEOPEN50 places

Security & privacy

QR code scams on packages and mail

Scam letters and unexpected parcels carry QR codes claiming a missed delivery, an unpaid fee or a prize, leading to phishing or card-harvesting pages. Postal services and police have warned about these campaigns. Never scan a code from unsolicited mail: open your carrier's own app or website instead.

View as MarkdownPaste this page into any AI assistant. It is plain, portable Markdown.

Why scammers put QR codes in your letterbox

Physical mail arrives pre-trusted. There is no spam folder, no email filter, and a printed card with a courier's colours looks official in a way an email never quite does. A QR code completes the trick: it hides the destination (a URL printed in text on a card can be read and doubted; a code cannot), and it moves you straight onto your phone, where the address bar is small and the pressure to resolve "your parcel" is high. Postal services and police forces in several countries have published warnings about these campaigns.

The common variants

Variant The lure The goal
Missed-parcel card "We could not deliver. Scan to rebook or pay a small fee" Card details, harvested via a fake courier page
Customs or postage due "£1.99 outstanding: scan to release your parcel" Card details; the tiny amount lowers your guard
Brushing package An unsolicited free item with a "scan to register" or "who sent me this?" insert Phishing, account credentials, or reviews under your name
Prize or gift card "You have won: scan to claim" Personal data and card details
Fake survey insert "Scan for a refund/voucher for your recent order" Account login credentials

The brushing variant deserves a note: the parcel itself is real and free. Sellers send unordered goods to real addresses to fabricate "verified purchase" reviews. The QR insert inside is the dangerous part, the United States Postal Inspection Service has warned specifically about scanning codes found in unsolicited packages.

The anatomy of the missed-parcel lure

  1. A card or letter arrives referencing a delivery you vaguely might be expecting: online shopping volume makes this guess land often.
  2. A small fee (typically £1–3) frames the page as routine rather than as a theft. The real target is the card number, not the fee.
  3. Urgency ("parcel returned after 48 hours") pushes you to scan now, on your phone, without checking.

The safe-handling rules

  • Never scan a code from unsolicited mail. This rule has no exceptions worth making, a genuine courier's card contains a tracking number you can use independently.
  • Go direct instead. Open the carrier's own app or type its website yourself, and enter the tracking number printed on the card. If the card is genuine, the delivery exists there; if not, you have your answer. Legitimate carriers do not take payment through a QR code on a doorstep card.
  • Check with the retailer. Expecting a parcel? Your order confirmation has the real tracking link.
  • Curious what a code contains? Decode it without opening it: our scanner reads a photo of the code entirely in your browser and shows the raw text, the domain check then takes seconds.
  • Received an unordered package? Keep it or bin it (you are not obliged to pay or return it), but do not scan the insert, and consider changing the password on the shopping account it names, since brushing often follows a data leak.

What makes this different from email quishing

The playbook matches QR phishing email tactics (same lures, same fake pages), but the physical channel removes even the weak protections email has: no gateway scanning, no sender address to inspect, no report-spam button. Your habits are the entire defence, which is why the "never scan unsolicited mail" rule is worth making absolute.

FAQ

Is it safe to scan a QR code that came in the post?

Only if you were expecting the item and can verify the sender, and even then, going directly to the company's app or website is safer. For anything unsolicited, do not scan; verify through the carrier's official channel instead.

What is a brushing scam and what does the QR code do?

Brushing is sending unordered parcels to real addresses so the seller can post fake verified reviews. The parcel is harmless; the QR insert inside typically leads to a phishing page. Postal inspectors have warned against scanning codes in unsolicited packages.

How do couriers really charge customs or redelivery fees?

Through their own apps and websites, referenced by your tracking number, not through a QR code on a doorstep card demanding immediate payment. When a fee is genuine, you will find it by entering the tracking number on the carrier's official site.

Can scanning the code on a scam letter hurt my phone?

The scan itself does nothing: a code is inert text and cannot install anything. The danger begins on the page it opens, if you enter card details or credentials there. If you scanned but typed nothing, simply close the page.

Try it: free, no signup

  • Are QR codes safe?, Scanning a QR code is safe in itself: it decodes text and nothing else. The risk is entirely in what you do next. A code cannot install software, dial,…
  • QR codes in phishing emails, Why phishers put QR codes in email: the image slips past URL filters, and the scan moves you to an unmanaged phone. The lures, the journey, the defences.
  • How to check where a QR code goes before opening it, Use the preview banner both iOS and Android show before opening, and read the domain immediately before the first single slash. To inspect without any…
  • Quishing: QR code phishing explained, Quishing is phishing delivered by QR code. It works for two structural reasons: a human cannot read a URL from a pattern before scanning it, and email…