Table of Contents
- When a Perfect QR Code Still Lands in Spam
- Choose the generation path deliberately
- Host the asset and destination as brand properties
- Embedding the QR Code Without Triggering Filters
- Use a transparent embed sequence
- Tracking Scans With Static, Dynamic, and Unique Codes
- QR tracking method trade-offs
- Building Trust So Scans Convert Instead of Complain
- Make legitimacy visible
- Common QR Mistakes That Quietly Damage Reputation
- The recurring post-mortem findings
- A/B Testing and Pre-Send Checks for Bulk Senders
- Deliverability checklist
- Putting It Together and Answering the Real Questions
- How often should QR creatives be refreshed?
- Does a plain-text email count as an email with QR code?
- What should happen when scan rates suddenly drop?
- How can a sender recover after a QR campaign lands in spam?

Do not index
Do not index
An email with a QR code can support strong scan-to-action journeys, but it only works reliably when the image, destination, fallback link, and sender infrastructure are all trustworthy. In 2025, marketers placed QR codes in email more often than in any other channel, at 47%, compared with 46% for product packaging and 43% for events, according to Wave Connect's summary of Bitly-cited QR research.
The campaign looked finished. The creative team had approved the QR image, the landing page loaded, and the fallback button worked in testing. On launch day, however, Gmail placement weakened, Outlook engagement dropped, and scans barely moved. The QR itself wasn't broken. The problems sat around it: an image hosted on an unfamiliar domain, a redirect that passed through a disposable shortener, and a list that had accumulated inactive recipients and complaints.
That failure is common because an email with QR code has three separate reputation surfaces:
- The QR image, which affects rendering, accessibility, image analysis, and visual trust.
- The QR destination, which determines where a mobile scan leads and whether the domain looks legitimate.
- The fallback link, which mailbox providers and recipients can evaluate as a conventional URL.
A QR campaign is therefore a deliverability decision before it's a design decision. Gmail, Outlook, and Yahoo evaluate sender authentication, domain behavior, engagement, complaints, links, and message structure together. A polished QR graphic can't compensate for weak email authentication, a suspicious redirect host, or poor list hygiene.
Table of Contents
When a Perfect QR Code Still Lands in SpamChoose the generation path deliberatelyHost the asset and destination as brand propertiesEmbedding the QR Code Without Triggering FiltersUse a transparent embed sequenceTracking Scans With Static, Dynamic, and Unique CodesQR tracking method trade-offsBuilding Trust So Scans Convert Instead of ComplainMake legitimacy visibleCommon QR Mistakes That Quietly Damage ReputationThe recurring post-mortem findingsA/B Testing and Pre-Send Checks for Bulk SendersDeliverability checklistPutting It Together and Answering the Real QuestionsHow often should QR creatives be refreshed?Does a plain-text email count as an email with QR code?What should happen when scan rates suddenly drop?How can a sender recover after a QR campaign lands in spam?
When a Perfect QR Code Still Lands in Spam
A marketing team launches a member offer with a large black-and-white QR code in the center of the message. The code scans correctly on an iPhone, the destination uses HTTPS, and the landing page is responsive. Yet inbox placement collapses because the image is fetched from a generic file host, the mobile destination uses a low-trust redirect domain, and the HTML fallback points to a different hostname.
The mailbox provider doesn't evaluate the QR as an isolated design object. It evaluates the complete message and the sender behind it. Heavy image dependence can reduce useful text signals, image blocking can make the message appear empty, and a redirect can introduce a destination that doesn't match the visible brand. Recipients who can't understand the offer without scanning may delete or report the email, weakening engagement signals further.
QR use is already mainstream. The same Wave Connect report says more than 90% of marketers used QR codes in campaigns in 2025, and 94% increased usage compared with the prior year. The format also has broad consumer familiarity. A 2025 global adoption report estimated that 44.6% of global internet users aged 16 to 64 scan at least one QR code monthly, while the United States accounted for 43.9% of global QR scans. Adoption doesn't remove the need for trust. It raises the standard for legitimate implementation.
Choose the generation path deliberately
Teams usually choose one of three approaches:
- ESP-generated code: Convenient for a basic campaign, but analytics and destination control may be limited.
- Static third-party code: Simple and stable, with no redirect dependency, but scan data is limited.
- Dynamic platform code: Useful for destination changes and analytics, but every scan depends on the redirect domain remaining reputable and fast.
A dynamic code is not automatically better. It adds an infrastructure dependency, so the redirect host should use the brand's authenticated domain or a clearly related subdomain. Free URL shorteners create an unnecessary trust gap, especially when a recipient sees an unfamiliar domain after scanning.
Host the asset and destination as brand properties
Use HTTPS for the destination and keep the image on a controlled CDN or the sender's established asset infrastructure. PNG is usually the safest email format because it renders broadly. SVG can create inconsistent behavior in some clients, while inline base64 images can complicate message size and filtering.
The QR needs strong contrast, generous quiet space, and enough physical size for the intended scan context. The exact minimum depends on the content density, rendering scale, and distance from the phone, so the creative team should validate the exported asset rather than rely on a nominal pixel rule.
Before sending, test the complete message in:
- iPhone Mail, with images enabled and disabled.
- Gmail on Android, including the scan-to-browser handoff.
- Outlook desktop, where image blocking and fallback visibility matter.
- Apple Mail desktop, including retina rendering and link presentation.
Embedding the QR Code Without Triggering Filters
The safest embed workflow gives the recipient several understandable paths without making the email look like an image wrapper around an unknown redirect.
Start with the image source. A hosted image keeps the message lighter and makes asset updates easier, but the image host becomes part of the trust chain. An inline attachment can improve availability when remote images are blocked, while a CID-based image may behave differently across clients and ESPs. The correct choice depends on the sending platform, but the destination and fallback should remain consistent across every version.
Use a transparent embed sequence
- Generate the code for the final HTTPS destination, or for a controlled redirect if analytics are essential.
- Host the image on a reputable, brand-associated asset domain.
- Add descriptive alt text, such as “QR code for the member offer landing page.”
- Place a short explanation above or beside the image.
- Put a visible fallback link directly below the QR.
- Include the destination in the plain-text part of the multipart message.
- Render-test the result through the production ESP, not only in a design preview.
Alt text supports screen-reader users and recipients with blocked images. It shouldn't become a string of repeated marketing keywords. The CTA should explain the action, while the QR reinforces it. A desktop recipient may be unable to scan the code from the same screen, so a clickable fallback isn't optional.

Teams planning broader campaigns can review Client growth via QR codes for additional use-case context, but the deliverability review still needs to happen inside the email program. Run the final HTML through an HTML Email Checker to catch rendering and markup issues before the seed-list test.
On mobile, verify that the fallback link isn't pushed below a long image, that the QR doesn't become blurry after responsive scaling, and that the scan prompt doesn't compete with the primary button. Those details influence both usability and the engagement signals that mailbox providers observe.
Tracking Scans With Static, Dynamic, and Unique Codes
Static, dynamic, and unique QR codes solve different measurement problems. A static code is best when the destination is stable and scan attribution isn't central. A dynamic code supports destination changes and richer analytics through a redirect. A unique-per-recipient code can connect an individual scan to a CRM record, but it introduces more operational complexity and a larger privacy burden.
The useful fields go beyond total scans. A measurement workflow should separate unique scanners, timestamp, device type, geography, repeat activity, landing-page sessions, and downstream outcomes. Raw scan counts can include repeated scans or automated prefetch-like behavior, so a scan should become meaningful only when it produces a session, form completion, purchase, redemption, or another defined business event.
A practical implementation looks like this:
- Assign a distinct destination or parameter to each audience segment.
- Record scan time, device, and geography.
- Deduplicate repeat activity at the session level.
- Join scan sessions to ESP and CRM engagement records.
- Compare scans with the final conversion, not with opens alone.
- Review the redirect host's latency and error logs.
The redirect is also a deliverability and trust surface. A dynamic code that resolves slowly, changes unexpectedly, or uses a domain unrelated to the sender can reduce completion and increase suspicion. Unique codes may create the strongest attribution, but they require careful data governance and reliable rendering at send time.

QR tracking method trade-offs
Tracking method | Data captured | Cost per send | Reputation risk |
Static | Destination activity with limited attribution | Low operational overhead | Lower, because no redirect is required |
Dynamic | Scans, timing, device, and geography when configured | Platform and redirect overhead | Moderate, because the redirect domain must remain trusted |
Unique | Per-recipient scan and conversion association | Highest implementation overhead | Higher operational risk if personalization or redirects fail |
For workflows involving events, loyalty, tickets, or segmented journeys, the email automation guide can help connect scan events to follow-up logic. The automation should suppress irrelevant reminders and avoid sending repeated QR prompts to recipients who already completed the action.
Building Trust So Scans Convert Instead of Complain
A recipient receives an email with a QR code for an event ticket. The sender is familiar, the purpose is clear, and the visible fallback link uses the same brand domain. That context can determine whether the scan feels useful or suspicious.
Caution is justified. Microsoft reported that QR-code phishing detections reached 18.7 million in March 2026, up from 7.6 million in January 2026, a 146% increase over the quarter. QR codes embedded directly in email bodies also surged 336% in March, according to Microsoft's Q1 2026 email threat analysis. Legitimate senders need to treat the QR image, its hosted URL, and its fallback link as separate reputation surfaces.
Build trust into all three. State who sent the message, explain the action, show the destination brand, and provide a conventional route. “Scan to view your event ticket” gives useful context. “Scan immediately to avoid losing access” creates pressure associated with phishing. Keep the sender identity, QR destination, and fallback hostname aligned.
Make legitimacy visible
- Place the brand and scan purpose beside the code.
- Show a human-readable destination or branded fallback URL.
- Use the primary domain or a clearly related subdomain for redirects.
- Keep the sender name, From domain, landing page, and fallback hostname consistent.
- Use available identity signals, such as BIMI, when the infrastructure supports them.
- Do not request passwords, payment details, or MFA codes after an unexpected scan.
The fallback link serves more than accessibility. It lets recipients inspect the domain before acting, gives filters a conventional URL to evaluate, and preserves the call to action when images are blocked or the reader cannot scan the screen.

Measure completed actions, not scans alone. A direct-mail engagement benchmark reports QR-driven engagement between 0.43% and 3.55%, with a median of 1.63%. The top 10% of campaigns reach 5.29% or higher. Use those figures for planning, not to justify aggressive copy or unfamiliar redirects. A smaller volume of legitimate scans is more valuable than scans followed by complaints.
Common QR Mistakes That Quietly Damage Reputation
QR campaigns tend to fail through small implementation decisions rather than one dramatic defect. The image may be oversized, the fallback may be absent, or the redirect may sit on infrastructure that has no relationship to the sender. Each choice affects rendering, user confidence, or reputation.

The recurring post-mortem findings
- Oversized QR images: A dominant graphic can push meaningful copy below the preview area and make the email appear promotional or empty when images are blocked. Keep the QR proportionate to the message and confirm the total payload remains reasonable.
- Missing or stuffed alt text: Empty alt text hides the action from assistive technology. Keyword-heavy alt text looks unnatural and doesn't explain the destination. Use one concise description.
- No fallback link: Desktop readers, screen-reader users, and strict image-blocking clients lose the primary action. Add a visible branded link directly beside or below the code.
- Untrusted redirect infrastructure: A free shortener or unrelated hostname asks the recipient to trust a second brand. Use a controlled domain, HTTPS, and a stable destination.
- Unverified landing pages: A QR that leads to a temporary page, broken redirect, or mismatched brand creates complaints even when the email itself is authenticated.
- Low contrast and poor export quality: A code that scans only after repeated attempts frustrates users and produces weak engagement. The best QR code design and placement should be validated in the actual email clients and at the intended scan distance.
- Unsegmented repetition: Sending the same scan request to recipients who already completed the action creates fatigue. Feed scan and conversion events back into suppression and follow-up logic.
The operational benchmark should be conservative. A Federal Committee on Statistical Methodology presentation found modest changes in web participation and yield in independent QR contact-material research, including web participation moving from 92.1% to 93.8% while yield moved from 22.4% to 21.9%. The lesson is simple: a QR code doesn't repair a difficult workflow. It needs a clear purpose, a mobile-first page, and a short path to completion.
A/B Testing and Pre-Send Checks for Bulk Senders
The common assumption is that adding a QR code automatically creates another conversion path. It can also create another reason to distrust the message, another redirect to monitor, and another asset for filters to inspect. Testing should isolate whether the QR improves completion for the actual audience rather than assuming that scan volume equals value.
Use a controlled comparison:
- Keep the audience, sender identity, offer, and send conditions consistent.
- Test a QR version against a non-QR version with an equivalent fallback CTA.
- Use distinct destinations so scan activity and link activity don't merge.
- Compare completed outcomes, complaints, unsubscribes, bounces, and inbox placement.
- Review results by device context. A QR may help desktop-to-mobile journeys while adding friction on mobile.
- Stop or revise the treatment if complaints rise or the redirect produces errors.
The pre-send gate must cover infrastructure as well as creative. Gmail and Yahoo introduced bulk-sender requirements in 2024 that include SPF and DKIM authentication, DMARC with at least a p=none policy, valid forward and reverse DNS, and complaint controls. A summary of the Gmail and Yahoo requirements states that spam complaints must remain below 0.3%.
Deliverability checklist
- Confirm SPF, DKIM, and DMARC alignment for the From domain.
- Verify valid forward and reverse DNS for the sending IP.
- Confirm the List-Unsubscribe header provides one-click unsubscribing.
- Ensure unsubscribe requests are honored promptly. Yahoo's guidance says within 2 days, as summarized by Signet's sender-requirements guide.
- Monitor complaint rates against Gmail's guidance of below 0.10%, and avoid sustained rates at or above 0.30%, as explained by Oracle Marketing Cloud.
- Run a low-volume seed-list test in Gmail, Outlook, Yahoo, and Apple Mail.
- Scan every QR variant and click every fallback before release.
Also check the infrastructure independently. Yahoo's sender best practices call for valid forward and reverse DNS and compliance with RFC 5321 and RFC 5322. A technically correct email can still struggle when its sending setup is inconsistent.
Putting It Together and Answering the Real Questions
A reliable email with QR code follows an ordered launch sequence. First audit SPF, DKIM, DMARC, DNS, unsubscribe handling, and recent complaint behavior. Then lock the redirect domain, confirm the HTTPS destination, generate the image, embed descriptive alt text, add the branded fallback, render the message, and run the QR versus no-QR comparison.
After launch, monitor scans as session-level activity and connect them to the business outcome. A redemption or completed form matters more than a raw scan. For promotions that depend on coupons or loyalty behavior, a dedicated coupon management feature may simplify the post-scan experience, but the destination still needs consistent branding, secure hosting, and a clear route back to the official site.
How often should QR creatives be refreshed?
Refresh the creative when the offer, destination, audience, or trust context changes. A stable code can remain useful when the destination is stable, but teams should revalidate the image, redirect, fallback, and landing page before each major send. Dynamic codes should never be allowed to change destinations without a documented owner and review process.
Does a plain-text email count as an email with QR code?
A plain-text message can't display a scannable QR image, but it can preserve the same accessible journey by describing the offer and providing the full branded URL. The multipart plain-text version should mirror the HTML fallback so recipients using text-only clients aren't excluded.
What should happen when scan rates suddenly drop?
Check rendering first, then scan the production asset from several devices. Review redirect status, destination availability, domain changes, campaign segmentation, and device mix before altering the creative. If scans fall while complaints rise, pause the campaign and investigate trust, authentication, and list quality rather than only enlarging the QR.
How can a sender recover after a QR campaign lands in spam?
Stop the problematic treatment, preserve the evidence, and identify whether the cause was authentication, redirect reputation, creative structure, complaints, or poor targeting. Send only to engaged, permission-based recipients while correcting the infrastructure and monitoring complaint rates. Recovery requires controlled volume and consistent behavior, not a new QR generator.
Teams that need help separating an image problem from a domain-reputation problem can use the SPF checker, DKIM checker, DMARC checker, and blacklist checker before changing campaign creative. Tools can surface defects, but they won't decide whether a QR is appropriate for the audience, whether a redirect deserves trust, or whether the campaign should be paused.
The practical standard is clear: authenticate the sender, control the image host, use a branded destination, provide a visible fallback, test the actual clients, and measure completed actions alongside complaints. An email with QR code can shorten a desktop-to-mobile journey, but only when every reputation surface earns the scan.
MailAdept provides ongoing deliverability consulting for QR-enabled campaigns, including SPF, DKIM, DMARC, redirect-domain review, inbox placement monitoring, and post-send diagnosis. Teams can visit Mailadept to request a focused audit and build a safer scan-to-conversion workflow.
