Why does my QR code say "Link Disabled for Safety"?
Updated September 14, 2026 · 2 min read
The destination behind the code was flagged as unsafe — phishing or malware — by the URL safety screening every QRCodeStack destination goes through, so we stopped the code redirecting. It is a deliberate block, not a fault with the printed pattern. If you believe the flag is wrong, email support@qrcodestack.com with the code's link and we will review it; blocks are lifted by a person, not automatically.
What gets screened, and when
Every destination is checked against Google Web Risk at three moments: when a code or short link is created, whenever its destination is changed, and again on a rolling daily basis for as long as it stays live. The daily recheck exists because the classic abuse pattern is a destination that is clean on day one and malicious on day thirty.
Alongside that, a handful of checks always run and always block, with no lookup involved:
- Destinations that are not
httporhttps. - Private, internal or reserved network addresses.
- URLs with a username and password embedded in them.
When a destination is flagged, every QR code and short link pointing at it is blocked, and scanners see the safety page rather than the destination. The same screening protects the short-link side of the product.
Why a legitimate site gets flagged
Flags are not always about the site you meant to link to. Common reasons a genuine destination gets caught:
- The site was compromised. An injected page or a hacked plugin on an otherwise normal site is enough.
- Shared hosting. A flagged neighbour on the same host or subdomain can drag a clean address in with it.
- A redirect chain. If your destination bounces through another shortener or an ad-tracking hop, that hop is part of what gets assessed.
- A file download. Links that serve executables or archives are treated far more suspiciously than pages.
- A recycled domain. A domain with a bad history keeps that history for a while after you buy it.
How to get the code working again
- Check the destination yourself on a device you do not mind risking, or ask whoever runs it. If the site really is compromised, cleaning it is the first job.
- Email support@qrcodestack.com with the code's link and the destination. A block is cleared by review, so changing the destination on a blocked code does not lift it by itself.
- If the campaign is live and cannot wait, create a new code pointing at a destination you control and use that for anything you can still change — anything already printed stays blocked until the review is done.
If you were stopped at creation instead, with "This destination URL is flagged as unsafe (phishing or malware) and cannot be used", the same applies: the destination is what needs sorting, not the code.
Reporting a code that should be blocked
If you scanned a QRCodeStack code that took you somewhere malicious, send the link to support@qrcodestack.com and we will investigate. Screening is not perfect — a destination that is brand new, or that only turns hostile for some visitors, can pass a lookup — so reports matter.
Nothing about the safety page identifies the code's owner or your organisation. It says only that the destination was flagged and the code has been disabled.
Frequently asked questions
Can I unblock the code myself?
No. Blocks are cleared by review, so email support@qrcodestack.com with the code's link and the destination.
Will changing the destination unblock it?
Not on its own. Change it if the old destination was the problem, then ask support to review the code.
Do I have to reprint?
No. The printed pattern is unaffected — once the block is lifted the same code redirects normally again.
Why was my brand new site flagged?
New domains and recycled domains carry little or bad reputation, and redirect chains and file downloads raise the risk score. Email support and we will look at it.
Are short links screened too?
Yes. The same checks run on short-link destinations at creation, on every change, and daily afterwards.
Related articles
Why does my QR code show Unavailable, Expired or Not Yet Active?
The page title tells you which setting stopped the scan: archived, paused, scan limit reached, a date schedule, a lapsed plan, a password, or a safety block.
How do I edit a QR code's destination after printing?
Open the code, click Edit, change the destination on the Content step and click Update. The printed pattern keeps working. Static codes cannot be edited.
What happens when someone scans my QR code?
The camera opens qrcodestack.com/qr/…, we run a short list of checks, record the scan, then send the visitor on — or render a hosted page for display types.
Still stuck?
Email support@qrcodestack.com with the email on your account and, if it is about one code, its name or short link. A person replies within one business day, usually sooner.