
QR codes in email marketing: when they help, when they're just friction
Nearly half of marketers put a QR code in an email campaign, but does it actually help? A look at image-blocking mechanics across Outlook, Apple Mail and Gmail, why a scan can beat an inflated open rate, and the quishing risk agencies need to know.
ScanKit · Organization
· 13 min read
Nearly half of marketers now put a QR code somewhere in an email campaign, according to Bitly's 2025 QR Code Trends survey, which puts email ahead of product packaging, events and print ads as the single most common QR placement. That is a striking number for a channel that already has a perfectly good click target built in: the hyperlink. If a reader can already tap a link in the email they are reading, why hand them a second, clumsier way to reach the same destination?
The honest answer is that a QR code in an email is sometimes a genuinely useful shortcut and sometimes pure friction dressed up as innovation. Which one it is depends on mechanics that most marketing advice skips entirely: how email clients actually render images, what an "open" really measures once Apple's privacy tools are in the mix, and a security risk that has gone from theoretical to an active FBI warning in the space of two years. This guide works through all three, then gives you a placement checklist and a way to track what the code actually does once it is out in the wild.
Why marketers reach for a QR code in an email in the first place
The pitch is usually one of three things. First, cross-device handoff: the email is read on a laptop but the destination, a coupon, a wallet pass, a WiFi login, a store locator, only makes sense on the phone that will physically be at the till or the venue. Second, novelty: a QR code stands out in an inbox full of "Shop Now" buttons and gets a second look. Third, measurement: a scan feels like a cleaner signal of intent than a click, because it requires someone to physically pick up their phone and use the camera.
Each of those has a real answer, and it is not the same answer for every send. Cross-device handoff is the strongest case by far, and it is worth building the rest of your thinking around it. Novelty wears off within a few sends to the same list and stops being a reason on its own. The measurement argument is more interesting than most marketers realise, and it is where the recent history of email tracking actually makes QR codes look better, not worse, if you use dynamic codes rather than static ones.
The mechanic nobody mentions: whether the image even loads
Before any of that matters, the QR code has to render. A QR code in an email is an image, and email clients do not all treat images the same way.
Outlook (desktop) blocks external images by default and shows a placeholder until the recipient clicks "Download pictures." That is documented client behaviour, not a rumour, and it means a meaningful slice of a B2B list, where Outlook usage skews higher, will see a grey box instead of your code unless they take an extra action first. Apple Mail, Gmail and most modern webmail clients auto-load images (Gmail moved to server-side image proxying and auto-display around 2013, after years of blocking by default), so the render problem is now concentrated in Outlook and a handful of privacy-focused clients rather than spread evenly across the inbox.
This is not an argument against using a QR code in an email. It is an argument for never making it the only way to reach your destination. Always ship a visible text link alongside the image, and write real alt text for the QR image itself (something like "Scan to view the WiFi login QR code, or tap this link") so that recipients on a client that blocks images, or anyone using a screen reader, are not stuck.
Is a scan a better signal than an "open"? The maths says yes, cautiously
Here is the part of the debate almost no one runs the numbers on. Apple Mail is the largest single email client by measured opens, at roughly 65% of tracked opens according to Litmus's ongoing email client market share data, with Gmail around 24% and Outlook around 6%. Since iOS 15 in 2021, Apple's Mail Privacy Protection has pre-fetched every tracking pixel through Apple's own proxy servers regardless of whether the recipient actually opens the message or even reads it. Several independent analytics write-ups from 2024 put the share of "opens" generated purely by this proxy, rather than a real human opening the email, at somewhere around three-quarters of all pixel fires in some datasets.
That means the "open rate" line on your campaign report has been substantially inflated for years on any list with meaningful Apple Mail share, which is most consumer lists. A QR scan does not have that problem in the same way: it requires a person to pick up a phone, open a camera, and deliberately point it at the code. It is not a perfect metric either (a person can scan out of curiosity and never act on the destination), but it is not artificially triggered by a privacy proxy the way a pixel-based open is.
The catch is that this only works if the code is dynamic and properly tagged. A static QR code pointing straight at a URL tells you scans happened, full stop. A dynamic code tied to a redirect gives you scan volume, timing, device type and, if you tag the destination URL with UTM parameters, which specific email send drove which conversions, the same way you would want to see in scan metrics for any other channel.
When a QR code in an email genuinely earns its place
The strongest use case by a distance is a destination that only makes sense on a mobile device, viewed somewhere other than a desk. A few concrete examples:
- A WiFi login for an event, where the recipient reads the invite on a laptop days beforehand but needs the network credentials on their phone the moment they walk in.
- A wallet pass (a loyalty card, an event ticket, a boarding pass equivalent) that has to land in Apple Wallet or Google Wallet on the device that will be tapped or scanned at the door.
- An in-store or in-venue coupon meant to be redeemed on a phone screen at the till, where a QR code doubles as the redemption mechanism rather than just a link.
- A short survey or feedback prompt sent after an in-person visit, where scanning feels like a natural continuation of a physical experience rather than a detour from a digital one.
- An account or app download step, where the QR code routes to the correct app store automatically rather than making the recipient search for the app by name.
The common thread is a genuine change of device or context, not just an alternative way to click the same link the recipient is already looking at on the same screen.
When it is just friction, and you should skip it
The case against a QR code weakens fast once you notice how people actually read email. A large share of email opens happen on a phone already, since most inbox checking now happens on mobile. If someone is reading your campaign on the same phone that has the camera, asking them to switch to a camera app, frame the code, wait for the redirect and then land back in a browser is a strictly worse experience than a link they can tap directly with a thumb. You have added steps to remove steps.
Skip the QR code, and just use a normal link, when:
- The destination is a standard web page (a product page, a blog post, a signup form) that works fine as a direct tap.
- Your list skews heavily toward mobile opens already, so there is no meaningful desktop-to-mobile handoff happening.
- The email itself is the primary channel and there is no physical, in-person moment the code is bridging to.
- You only want a slightly different-looking call to action. Novelty is not a strong enough reason on its own, and it stops working the moment the audience has seen a few of these emails already.
If none of the genuinely useful cases from the previous section apply, a QR code in an email is decoration wearing a utility costume. It adds a rendering dependency, an extra tap, and a security surface (more on that shortly) for no real gain over the link that was already sitting in the same message.
A short design and placement checklist
If you have a real handoff use case, a few practical choices make the difference between a code that works and one that quietly fails:
- Never make the QR code the only path to the destination. Pair it with a visible, tappable text link doing exactly the same job.
- Write descriptive alt text on the QR image, both for accessibility and for the recipients whose client blocked the image.
- Keep the surrounding email lightweight. A single QR code plus a clear one-line instruction ("Scan with your phone's camera to add this to Apple Wallet") reads as helpful; a QR code buried among five other visual elements and no instruction reads as clutter, and can also look enough like a generic marketing graphic that spam filters weighing heavy image-to-text ratios treat it less favourably, a widely repeated deliverability rule of thumb rather than a documented threshold from any single mailbox provider.
- Use a dynamic code, not a static one baked directly into the image, so you can fix a broken destination after the send goes out and so you get scan data at all.
- Test the render in Outlook desktop specifically before you send, since it is the one major client where the image will not appear without the recipient taking an extra click.
Tracking what the code actually does
Once the email has gone out, the code needs to earn its keep in the report, not just in the design. Give the redirect its own UTM tagging so scans from this specific send are distinguishable from scans on the same code placed elsewhere, following the naming convention that scales across clients rather than inventing one per campaign. Feed that into whichever analytics stack the client already reports from; if that is Google Analytics 4, make sure the redirect lands with the parameters intact rather than getting stripped by an intermediate page. Report scan volume, device split and time-to-scan alongside the traditional open and click numbers, and be upfront with the client that open rate on an Apple-Mail-heavy list is a soft number these days: scan data is one of the more honest things you can put in front of them.
The quishing risk agencies cannot ignore
There is a security dimension to this that has moved from a hypothetical to an active threat inside the last two years. QR code phishing, now commonly called quishing, rose sharply between 2023 and 2025, with Abnormal Security's tracking putting it at roughly 8.3% of all phishing attacks in 2025, up from under 1% two years earlier. The FBI issued a flash alert in January 2026 warning that state-linked phishing groups were embedding malicious QR codes in spear-phishing emails specifically to move victims off a monitored corporate laptop and onto a personal phone, where the same URL-scanning and sandboxing that protects a clicked link in a corporate inbox typically does not run.
That mechanism, a QR code moving the click off the device and network that would normally inspect it, is exactly why quishing works as an attack and exactly why a legitimate QR code in a legitimate marketing email needs to look unmistakably legitimate. Practical steps for an agency sending QR codes in client campaigns: always route through a domain the recipient will recognise as the client's own (not a bare shortener with no branding), never ask someone to scan a code to "verify your account" or re-enter a password, and consider a short line in the email itself explaining what the code does and where it goes, since that is exactly the context a phishing email will not bother to include. The broader picture on locking down campaign codes against tampering and impersonation is worth reading in full if you are running QR campaigns for clients at any scale that needs its own security posture.
Frequently asked questions
Do QR codes actually work in email marketing?
They work well for a specific job: moving someone from an email read on one device to an action that only makes sense on their phone, such as a wallet pass, an in-person redemption, or a WiFi login. For a destination that is just a standard web page, a normal tappable link performs at least as well and adds no extra friction.
Why put a QR code in an email instead of just a link?
Only when the destination genuinely needs to be reached on a different device than the one the email was read on, or needs the phone's camera or wallet app specifically. If the recipient is already reading the email on their phone, a QR code adds steps rather than removing them.
Do email clients block QR code images by default?
Outlook (desktop) blocks external images by default and shows a placeholder until the recipient clicks to download them. Apple Mail and Gmail auto-load images for most recipients today. Always include a visible text link alongside the QR image so the message still works when the image does not load.
Is a QR code scan a better metric than an email open?
It can be more trustworthy in one specific way: since iOS 15 launched Apple Mail Privacy Protection in 2021, a large share of recorded "opens" are triggered automatically by Apple's proxy pre-fetching the tracking pixel, not by a person reading the email. A scan requires someone to deliberately use their camera, so it is not subject to that same inflation, though it still is not proof the recipient acted on the destination.
What is quishing, and should marketing emails worry about it?
Quishing is phishing delivered via a QR code rather than a clickable link, and it has grown fast enough that the FBI issued a flash alert about it in January 2026. It matters for legitimate marketing email because a QR code that looks unbranded or unexplained is indistinguishable from an attack to a cautious recipient. Always route through a recognisable domain and explain what the code does in the email copy itself.
Should I put a QR code in my email signature?
Only if it leads somewhere that benefits from the camera specifically, such as a vCard contact save or a wallet-style loyalty card. For a link to a website or a calendar booking page, a normal hyperlink in the signature works just as well and does not require the recipient to reach for their phone while reading email on a laptop.
The short version
A QR code in an email earns its place only when the destination genuinely needs a different device or the phone's camera and wallet, not as a stylistic alternative to a link that was already sitting right there. Check how the image actually renders across Outlook, Apple Mail and Gmail before you rely on it, treat scan counts as a more honest signal than open rate on any list with heavy Apple Mail share, and never send an unexplained code from an unrecognisable domain given how fast quishing has grown. If your next campaign has a real cross-device moment in it, build it on a dynamic code with proper UTM tagging so the scan data actually tells your client something useful.
Keep reading

· 14 min read
QR codes for nonprofit fundraising: what the data says, and the disclosure rule agencies miss
Do QR codes actually raise more money for nonprofits? Real direct mail response data, the mobile-vs-desktop gift gap, and the US charitable solicitation registration rule that a QR code can quietly trigger for agencies running national appeals.
Read more
· 17 min read
The EU Digital Product Passport: what it means for your agency's QR codes
Does your QR platform make a client DPP-compliant? Almost never. Here's what the EU Digital Product Passport actually requires, which deadlines are confirmed (batteries, February 2027) versus still indicative, and where agencies genuinely add value.
Read more