home / blog / qr codes

How QR Codes Work (and What They Can't Do)

A QR code isn't a link. It's a container. What it holds, how it survives a torn corner, and why scanning one blindly is riskier than clicking a link.

A QR (Quick Response) code is a two-dimensional barcode. It packs far more data than the familiar single-line barcode on a product, up to a few thousand characters depending on the version and error correction level used. It was invented in 1994 by Denso Wave for tracking automotive parts, and its patent was released royalty-free. That's a large part of why it became the universal standard instead of one of several competing formats.

Under the hood, a QR code isn't a photo of your data. It's a grid of black and white squares called modules, arranged according to a published spec (ISO/IEC 18004) so that any compliant scanner, from any manufacturer, decodes it the same way. That standardization is the whole point: a code generated in a browser today will still scan correctly on hardware nobody has built yet, as long as it follows the spec.

Anatomy of a QR code: why those three corner squares matter

Look closely at any QR code and you'll notice three identical nested squares in the top-left, top-right, and bottom-left corners. These are finder patterns, and they're the first thing a scanner locates. Their fixed 1:1:3:1:1 ratio of black-to-white stripes is unusual enough that a scanning algorithm can pick them out of a busy background instantly, even at an angle. Three corners, not four, is deliberate: three points are enough to fix the code's orientation and correct for rotation, and leaving the fourth corner free makes room for payload data. Smaller alignment patterns (the little squares scattered through the interior of larger codes) let the scanner correct for the barrel or pincushion distortion you get from scanning a code on a curved surface or at a steep angle. That's why a QR code plastered on a bottle or a crumpled flyer still resolves correctly.

QR codes also come in 40 discrete sizes, called versions, from Version 1 (a 21×21 module grid) up to Version 40 (177×177 modules). Each step up adds more modules and therefore more data capacity, but also makes each module physically smaller for a given print size. That's exactly why cramming a long URL into a QR code and then printing it business-card-size is a common way to make it unscannable. As a concrete reference point, a Version 2 code (25×25 modules) at low error correction holds about 77 numeric digits or 47 alphanumeric characters. Jumping to Version 10 (57×57 modules) at the same error level holds over 900 alphanumeric characters. Capacity roughly scales with the square of the grid size, not linearly.

It's not just for URLs

A QR code just encodes text. What a scanner does with that text depends entirely on its format. A plain URL opens a browser. Text prefixed tel: opens the phone dialer. mailto: opens an email composer. A specially formatted string starting with WIFI: can auto-join a Wi-Fi network, and a block starting with BEGIN:VCARD hands a phone a contact card to save. The QR code itself has no special awareness of any of this. It's the scanning app that interprets the payload and decides what action to take.

Underneath the format string, the encoder also picks one of four data modes depending on what characters you're feeding it: numeric (digits only, the most compact), alphanumeric (digits, uppercase letters, and a handful of symbols like space, $, %, and colon), byte mode (any raw text or UTF-8, including lowercase letters and emoji, at roughly half the density of alphanumeric mode), or kanji mode for Japanese text. That's why an all-caps, digits-only payload like a phone number packs tighter than a mixed-case URL of the same character length: the encoder silently downgrades to the most efficient mode it can use for each stretch of the input.

Why QR codes survive a torn corner

QR codes use Reed-Solomon error correction, the same family of algorithm used in CDs and DVDs, which encodes redundant data alongside the actual payload. There are four error correction levels to choose from, and the difference between them is entirely a tradeoff of robustness against data density:

  • L (Low) — recovers from about 7% damage. Maximizes data capacity; fine for a code you control end to end, like one linking to your own site from a clean digital screen.
  • M (Medium) — recovers from about 15% damage. The default most generators use, a reasonable balance for general printed use.
  • Q (Quartile) — recovers from about 25% damage. Worth using for codes exposed to wear, like outdoor signage or packaging that gets handled.
  • H (High) — recovers from about 30% damage. The level to reach for if you want to place a logo over the center of the code, since the logo effectively "damages" that area on purpose and the correction data has to make up for it.

Higher error correction means a more robust code, but also a denser, more complex pattern for the same amount of data. There's a real tradeoff between damage resistance and how much text fits at a given physical size. A rule of thumb worth knowing: a centered logo should never cover more than about 15-20% of the code's total area even at H level. The finder patterns in the three corners and the timing patterns running between them can never be obscured, since covering one of those makes the code unreadable no matter how much error correction budget is left.

Common reasons a QR code fails to scan

Most "broken" QR codes aren't actually corrupted. They're just built or printed in a way that fights the scanner. The usual culprits, roughly in order of how often they show up:

  • Low contrast. Scanners rely on a sharp black/white edge to find modules. Light gray on white, or a busy photo behind a semi-transparent code, breaks the edge detection long before a human eye would call it "hard to read."
  • Missing quiet zone. The spec requires a blank margin at least four modules wide around the entire code. Crop a QR code tight against text or a border and scanners lose the finder patterns' context, since the algorithm needs that clean boundary to confirm where the code starts and stops.
  • Too much data crammed in. Encoding a long tracking URL with a dozen query parameters instead of a short link pushes the code into a higher version with smaller, denser modules. Print that at business-card size and the modules fall below what a typical phone camera can resolve at arm's length.
  • Printed too small for the scan distance. A rough working minimum: the code's physical width should be at least 1/10th of the expected scan distance. A code meant to be scanned from 3 feet away needs to be roughly 3-4 inches per side. Shrink that same code to a business card and it just won't resolve from that distance, even though it scans fine held closer.
  • Inverted colors. Most scanners expect dark modules on a light background. Light-on-dark ("negative") QR codes work on some scanners and fail on others, so they're a real gamble unless you've tested the specific apps your audience uses.

How to make a QR code (step by step)

Making a QR code really comes down to two decisions: what data to encode, and how robust it needs to be. Then you generate the image. Here's the practical path:

  • 1. Pick your data type. The most common are: a URL (just paste the full link, including https://), plain text (for anything that doesn't need to trigger an app), a Wi-Fi payload (network name, password, and security type, so scanning joins the network directly), a vCard (name, phone, email, company, saving straight to contacts), an email address (opens a pre-filled composer), or a phone number (opens the dialer).
  • 2. Keep the payload short. Shorter input means a lower QR version, bigger modules, and a code that's easier to scan and easier to shrink onto packaging or a business card. If you're encoding a long URL, run it through a link shortener first.
  • 3. Choose an error correction level. Use M for general use, H if you plan to add a logo or the code will be printed somewhere it might get scuffed or partially covered.
  • 4. Generate and test before you print or publish. Scan the code yourself with two or three different phones/apps, at the size and distance it'll actually be viewed from, before committing it to a poster, product, or print run you can't easily reprint.

GlaeKit's QR Code Generator covers all of the above (URL, text, Wi-Fi, vCard, email, and phone) and turns it into a downloadable QR code entirely in your browser. Nothing is sent to a server, so there's no third party sitting between you and whatever you're encoding.

The security angle: "quishing"

Unlike a text link, you can't preview where a QR code leads before you scan it. The destination stays opaque until your phone's camera decodes it. This has become an actual phishing vector ("quishing"): attackers print malicious QR code stickers over legitimate ones on parking meters, restaurant tables, or posters, banking on the fact that people who'd hesitate to click a suspicious link will scan a QR code without a second thought.

The practical defense is the same instinct you'd apply to a link: check the URL your phone shows before tapping through, especially for QR codes in public physical locations rather than ones you generated or received from a trusted source directly. If a code on a physical sticker looks slightly misaligned, curls at the edge, or sits on top of a printed one rather than being part of the original print, that's a physical tell worth trusting more than the code itself.

Frequently asked questions

How much data can a QR code hold?

Up to about 4,296 alphanumeric characters at the largest standard size and lowest error correction level. In practice, though, most QR codes encode a short URL or a small amount of text, since more data means a denser, harder-to-scan pattern.

Do QR codes expire?

A static QR code (like the ones generated here) never expires. It's just an image encoding fixed text, with no server or account behind it. Some commercial QR services offer "dynamic" QR codes that redirect through their own server, which can expire or be redirected later, but that's a feature of the service, not of QR codes themselves.

Can a QR code contain a virus?

The QR code itself is just text. It can't execute code. The risk is entirely in where that text (usually a URL) leads: a malicious site designed to phish credentials or exploit a browser vulnerability. Treat a scanned QR code link with the same caution as any unfamiliar link.

What data types can I put in a QR code?

Anything that's ultimately text: a URL, plain text, a phone number (tel:), an email address (mailto:), Wi-Fi credentials (WIFI:), or a contact card (vCard format). The QR code doesn't distinguish between these. The scanning app reads the text's prefix or structure and decides what action to offer.

What's the minimum size to print a QR code?

A rough working rule is that the code's physical width should be at least 1/10th of the distance it'll be scanned from, so a code scanned from 3 feet away needs to be roughly 3-4 inches per side. Higher error correction levels and longer encoded data both push the module count up, which raises the minimum printable size further.