
read receipts
Why Scammers Started Mailing You Pictures of Links
A QR code in an email isn't there to save you a step. It's there because your spam filter can't read it.
A link scanner is a simple, relentless thing. It reads the text URLs in your email, checks them against lists of known-bad domains, follows redirects, and flags the ones that lead somewhere nasty. It's good at its job. So scammers did the obvious thing: they stopped sending links.
They started sending pictures of links.
That's the whole trick behind "quishing" — QR-code phishing. A QR code is just a URL encoded as a black-and-white image. To the software guarding your inbox, it's a picture of a dog or a picture of a malicious login page; both are the same soup of pixels. The scanner that would instantly catch secure-paypa1-login.ru in text sails right past the same address when it's baked into a square of dots. The medium is the evasion. That's not a side effect. It's the entire reason for the switch.
And then there's the handoff. The email lands on your laptop, where your company's filters, your corporate firewall, and your browser's safe-browsing warnings all live. But you don't scan the code on your laptop. You pick up your phone — a personal device, often outside any of that protection — and point its camera at the screen. The attack literally walks itself off the monitored machine and onto the one nobody's watching. By the time the fake Microsoft 365 page loads on your phone, every tripwire has been stepped over.
The volume tells you how well this works. Microsoft reported that at one point during its 2023–2024 tracking, QR codes made up roughly 25% of all email phishing it was seeing — a quarter of the junk, delivered as imagery specifically to dodge the readers that catch text. CISA has put out its own guidance warning that QR codes in unsolicited messages are a favored route to credential-harvesting and malware, precisely because people have been trained to trust the little square.
The themes are boringly predictable, which is a tell in itself. A code to "re-enable" your expiring multi-factor authentication. A parking-fine QR sticker that's been slapped over the real one at the meter. A DocuSign you weren't expecting. A shipping notice with a code to "confirm delivery." The design goal is always to create a small, plausible reason to lift your phone before your brain catches up.
Here's the part that makes defending yourself easy: there is almost no legitimate situation where a stranger needs you to scan a QR code out of an email to log in or confirm something urgent. Your bank doesn't do it. Your IT department doesn't do it. If a message wants you to authenticate, you open a new tab and type the address yourself — the one you already know, not the one offered to you. A QR code removes your ability to read the destination before you commit, which is exactly why it's being used against you.
So the rule is almost rude in its simplicity. Don't point your phone at a QR code that arrived in your inbox. Not to check it. Not because it looks official. Not even to see where it goes. If the sender is real, there's a boring text link or a phone number or a login page you already have bookmarked.
The scanners can't see the code. You can. That's the only advantage left in the exchange, and it only works if you refuse the scan.
Sources
- CISA — Guidance on malicious QR codes and phishing
- Microsoft Security — Microsoft Defender reporting on quishing volume, 2023–2024