Skip to content
ToolsdaUPI fraud safety · 100% private on-device
UPI Tools
Runs on your deviceNothing you type here is sent anywhere — the whole tool is JavaScript in this tab.

UPI QR Code Decoder & Scam Checker

Decode any UPI QR or link to see the real UPI ID, bank/PSP handle and payee name, and check it against 95 known bank handle patterns and 8 common scam signals — including the "scan to receive" pay trap, where a scammer asks you to scan a QR to "receive" money when UPI never needs your PIN to receive anything. Everything is decoded and scored on your device; nothing is ever uploaded. Methodology last reviewed 2026-08-26. Need a QR to accept payments instead? Create one for your shop.

Check a UPI ID or QR

Safety verdict

What this check can and cannot verify

Checks
  • UPI ID format and recognized handle patterns
  • What a QR or upi:// link actually encodes (payee name, amount, note)
  • Whether a QR is a payment request or an ordinary web link
  • Common social-engineering wording (lottery, KYC, "receive" traps, etc.)
Cannot check
  • Whether the account actually exists
  • Whether the displayed name is who really owns the account
  • Whether the recipient is honest, or a payment was received
  • Live fraud reports, or bank/NPCI records

Paste a UPI ID on the left, or scan a QR. The 8-point warning signal check and score land on this sheet.

How UPI QR Scams Work

The "Scan to Receive" Trap

A stranger says "I'm sending you ₹5,000, just scan this QR to accept it." The QR is actually a upi://pay collect request. Scanning it and entering your PIN sends money OUT of your account — UPI never needs your PIN to receive money.

Fake Refund / Customer Care QR

"Your order was cancelled, scan this QR to get your refund" or "Your electricity bill is overdue, scan to pay and avoid disconnection." Both use urgency to rush you into scanning and paying without checking the payee name.

Fake Marketplace / Army Deal

A too-good-to-be-true OLX listing, often claiming to be an army/defence seller, asks for an "advance payment" QR before shipping. The item never arrives, and the seller's UPI ID has no real connection to any defence institution.

Golden Rules of UPI Safety

  1. Your UPI PIN is only ever needed to SEND money — never to receive it. If entering a PIN is required to "get" a refund, cashback, or prize, it is a scam.
  2. Always check the payee name shown inside your UPI app (GPay/PhonePe/Paytm) before entering your PIN — this checker helps you decide, but your app shows the final, real-time name.
  3. If a deal, prize, or refund sounds too good to be true — free money, a stranger paying you first, a way-below-market price — it almost always is.

Why check a UPI ID or QR code before paying?

A common UPI QR scam sends a message like "I'm sending you ₹5,000, just scan this QR and enter your PIN to accept it" — but the QR actually encodes a upi://pay link, which makes you pay them. UPI never needs your PIN to receive money; a QR that combines "receive" wording with a payment link is, by construction, asking you to pay. This tool parses the UPI ID, link, or QR entirely in your browser and runs an 8-point warning-signal check — including that pay-vs-receive mismatch, brand impersonation, and known scam wording — before you tap "Pay" or scan anything. It cannot confirm the account is genuine; see "What this check can and cannot verify" next to your result.

How this UPI check works

  1. Your browser decodes the UPI ID, payment link, or QR code locally — nothing is uploaded.
  2. It reads the handle, payee name, amount, and note when present in the input.
  3. Those fields are checked against a fixed set of deterministic warning rules.
  4. Every warning shows its reason — the 8-point check list below the verdict lists exactly what was found.
  5. Nothing is sent to a server, and the tool does not query any bank, PSP, or NPCI system — it has no way to.

Methodology last reviewed 2026-08-26.

What the 8 checks look for

  • UPI ID format — does it match the standard name@bankhandle pattern?
  • Bank/PSP handle — does the part after @ match a recognized bank/PSP handle pattern in Toolsda's local list?
  • Pay vs Receive trap — does a "receive money" message hide an actual payment request?
  • Brand impersonation — does the payee name claim to be Amazon, PhonePe, the Army, etc. without matching that brand's known handle pattern?
  • Scam keyword scan — lottery, KBC, KYC, army, OLX, cashback, and other common scam-bait words
  • Amount check — malformed, zero/negative, unusually small (₹1/₹2/₹5), or unusually large amounts
  • Linked website — if the QR encodes a web link instead of a direct UPI request, it's checked for phishing too
  • Merchant identity — does the name/ID pattern read as a business, or a personal account? Neither is verified — it's a pattern read only.

Official UPI help and reporting

Toolsda is an independent tool and is not affiliated with NPCI, RBI, any bank, or any payment app. For anything this checker cannot do — confirming an account, reporting fraud, or resolving a failed payment — use the official channels below.

Read the guide

🛡️ Trust & Safety

Disclaimer: what this checks

Safety: What This Check Can and Cannot Detect

This runs 8 heuristic checks in your browser — it is not a fraud database.

Can verify
  • Run 8 in-browser checks: amount-field tampering, UPI ID/VPA format, suspicious or lookalike merchant names, and other common QR phishing patterns
  • Flag QR codes and payment requests that look off before you scan or pay
Cannot verify
  • Check NPCI's live fraud or blacklist database — no public API for this exists
  • Confirm the shop owner or merchant is genuine
  • Detect screen-overlay or app-spoofing scams happening on your phone
  • Replace verifying the merchant directly — this is a second opinion, not a guarantee

If the amount looks wrong or you don't recognize the merchant, don't pay — call and verify first.

Non-affiliation

Toolsda is an independent product and is not affiliated with, endorsed by, or connected to NPCI, RBI, UPI, Google Pay, PhonePe, Paytm, or any bank. UPI® is a registered trademark of NPCI.

Report error

Found wrong handle mapping, or a wrong scam flag?

If something looks like fraud:NPCI cybercrime.gov.in Helpline 1930

Last verified: 27 Aug 2026Source: Heuristics source: Toolsda, built from documented UPI QR-scam patternsRuns 100% on your device

Frequently Asked Questions

Can this tool verify whether a UPI ID is real?

No. It checks the UPI ID's format and its handle against a local reference list, and scans the payee name, amount, and note for common scam wording — entirely on your device. It has no connection to NPCI, any bank, or any payment app, so it cannot confirm an account exists or that a payment will reach anyone.

Does a recognized handle mean the payee is safe?

No. A recognized handle (like @okicici or @ybl) only means the suffix matches a known bank/PSP naming pattern — it identifies the payment provider, not who holds the account or whether they are trustworthy. Scammers can and do use real, recognized handles.

Does Toolsda upload my QR code or UPI ID?

No. The QR image is decoded and the UPI ID or link is analysed entirely inside your browser. Nothing is uploaded, logged, or sent to a server — ever.

Can I scan a QR code to receive money?

Scanning is safe — the risk starts only when you enter your UPI PIN. UPI never requires your PIN to receive money. If a QR asks you to enter your PIN to "receive" a refund, cashback, or prize, it is actually a payment request and you would be sending money out, not in.

What should I verify inside my UPI app before paying?

The payee name and amount your app itself shows on the confirmation screen — that is real-time information this tool cannot see. If the name differs from who you expect to pay, or the amount is wrong, stop before entering your PIN.

What should I do if I already sent money to a scammer?

Immediately contact your bank and UPI app to report it, then call the national cyber-fraud helpline at 1930 or file a report at cybercrime.gov.in. Acting quickly improves the chance of a transaction freeze, but recovery is never guaranteed.

Can this tool verify a UPI payment screenshot or transaction status?

No. This tool only analyses a UPI ID, payment link, or QR code before you pay — it does not read screenshots and has no way to confirm whether a past payment was sent, received, or credited. Check your UPI app or bank statement for that.

What does the warning signal score mean?

It's a heuristic score (0–100) reflecting how many locally detected warning patterns were found — not a probability of fraud and not a live bank or NPCI lookup. A low score does not guarantee safety; a high score means the input matched one or more known risky patterns, and deserves extra caution before you pay.

What does pa= mean inside a UPI QR code?

pa is the payee address — the UPI ID (VPA) money would be sent to, e.g. rahul@okaxis. A QR also commonly carries pn (payee name), am (amount), and tn (transaction note). This tool decodes all of these locally and shows them in the Payment Details card.

Which bank or app is @okaxis, @ybl, or @paytm?

@okaxis and @oksbi are Google Pay handles routed through Axis Bank / SBI respectively, @ybl is PhonePe, and @paytm is Paytm — the handle after @ identifies the payment provider's naming pattern, not the specific account holder. Search the full list in the UPI Handle Directory.

Why does my QR show a different name than expected?

The payee name in a QR or link is a self-declared field (pn=) — anyone generating a QR can put any text there, including a well-known brand name that does not match the actual account. That mismatch is exactly what the brand-impersonation check on this page looks for. Always confirm the name your own UPI app shows at the final confirmation screen before entering your PIN.

More UPI Tools

See the full cluster on the UPI Tools hub — generate a UPI Payment Link or a UPI QR Code of your own, look up an unfamiliar handle in the UPI Handle Directory, or run a UPI ID through the dedicated UPI ID Checker for a closer look at its format and blacklist status.