# QR code scams on packages and mail

> Scam letters and unexpected parcels carry QR codes claiming a missed delivery, an unpaid fee or a prize, leading to phishing or card-harvesting pages. Postal services and police have warned about these campaigns. Never scan a code from unsolicited mail — open your carrier's own app or website instead.

Source: https://useqr.app/docs/security/qr-code-scams-on-packages-and-mail · Last reviewed 2026-08-21 · UseQR is free forever, MIT licensed, no signup.

---

## Why scammers put QR codes in your letterbox

Physical mail arrives pre-trusted. There is no spam folder, no
[email filter](/docs/security/why-qr-phishing-bypasses-email-filters), and a printed card
with a courier's colours looks official in a way an email never quite does. A QR code
completes the trick: it hides the destination — a URL printed in text on a card can be
read and doubted; a code cannot — and it moves you straight onto your phone, where the
address bar is small and the pressure to resolve "your parcel" is high. Postal services
and police forces in several countries have published warnings about these campaigns.

## The common variants

| Variant | The lure | The goal |
|---|---|---|
| Missed-parcel card | "We could not deliver. Scan to rebook or pay a small fee" | Card details, harvested via a fake courier page |
| Customs or postage due | "£1.99 outstanding — scan to release your parcel" | Card details; the tiny amount lowers your guard |
| Brushing package | An unsolicited free item with a "scan to register" or "who sent me this?" insert | Phishing, account credentials, or reviews under your name |
| Prize or gift card | "You have won — scan to claim" | Personal data and card details |
| Fake survey insert | "Scan for a refund/voucher for your recent order" | Account login credentials |

The **brushing** variant deserves a note: the parcel itself is real and free. Sellers send
unordered goods to real addresses to fabricate "verified purchase" reviews. The QR insert
inside is the dangerous part — the United States Postal Inspection Service has warned
specifically about scanning codes found in unsolicited packages.

## The anatomy of the missed-parcel lure

1. A card or letter arrives referencing a delivery you vaguely might be expecting —
   online shopping volume makes this guess land often.
2. A small fee (typically £1–3) frames the page as routine rather than as a theft. The
   real target is the card number, not the fee.
3. Urgency ("parcel returned after 48 hours") pushes you to scan now, on your phone,
   without checking.

## The safe-handling rules

- **Never scan a code from unsolicited mail.** This rule has no exceptions worth making —
  a genuine courier's card contains a tracking number you can use independently.
- **Go direct instead.** Open the carrier's own app or type its website yourself, and
  enter the tracking number printed on the card. If the card is genuine, the delivery
  exists there; if not, you have your answer. Legitimate carriers do not take payment
  through a QR code on a doorstep card.
- **Check with the retailer.** Expecting a parcel? Your order confirmation has the real
  tracking link.
- **Curious what a code contains?** Decode it without opening it: our [scanner](/scan)
  reads a photo of the code entirely in your browser and shows the raw text — the
  [domain check](/docs/security/how-to-check-a-qr-code-before-opening) then takes seconds.
- **Received an unordered package?** Keep it or bin it — you are not obliged to pay or
  return it — but do not scan the insert, and consider changing the password on the
  shopping account it names, since brushing often follows a data leak.

## What makes this different from email quishing

The playbook matches [QR phishing email](/docs/security/qr-codes-in-phishing-emails)
tactics — same lures, same fake pages — but the physical channel removes even the weak
protections email has: no gateway scanning, no sender address to inspect, no report-spam
button. Your habits are the entire defence, which is why the "never scan unsolicited
mail" rule is worth making absolute.

## FAQ

### Is it safe to scan a QR code that came in the post?
Only if you were expecting the item and can verify the sender — and even then, going directly to the company's app or website is safer. For anything unsolicited, do not scan; verify through the carrier's official channel instead.

### What is a brushing scam and what does the QR code do?
Brushing is sending unordered parcels to real addresses so the seller can post fake verified reviews. The parcel is harmless; the QR insert inside typically leads to a phishing page. Postal inspectors have warned against scanning codes in unsolicited packages.

### How do couriers really charge customs or redelivery fees?
Through their own apps and websites, referenced by your tracking number — not through a QR code on a doorstep card demanding immediate payment. When a fee is genuine, you will find it by entering the tracking number on the carrier's official site.

### Can scanning the code on a scam letter hurt my phone?
The scan itself does nothing — a code is inert text and cannot install anything. The danger begins on the page it opens, if you enter card details or credentials there. If you scanned but typed nothing, simply close the page.

## Try it

- https://useqr.app/scan
- https://useqr.app/validate
