QR Code Best Practices: Size, Contrast, Error Correction and Testing
How to create QR codes that scan reliably in print and on screens: minimum size, quiet zone, colours, error correction levels, static vs dynamic codes and security.
· 6 min read
QR codes became truly mainstream during the pandemic, when restaurant menus, check-ins and payments moved to phones. Today they appear on packaging, business cards, posters, invoices, TV ads and conference badges. Generating one takes seconds, yet a surprising number of printed codes fail to scan: too small, low contrast, missing margins or pointing to a URL that no longer exists. This guide covers what actually determines whether a QR code works, and how to design and test codes that scan the first time.
How a QR code stores data
A QR code is a grid of dark and light squares called modules. Three large finder patterns in the corners let a camera locate the code and determine its orientation. Smaller alignment patterns correct for perspective distortion, and timing patterns help the decoder determine the grid size. The rest of the area holds your data plus error-correction information.
Codes come in 40 versions, from 21 × 21 modules (version 1) to 177 × 177 (version 40). The generator chooses the smallest version that fits your content at the chosen error-correction level. More data means more modules, and more modules means each one is smaller at a given print size — which is the root of most scanning problems.
Keep the content short
The single most effective improvement is encoding less data:
- A 25-character URL fits in a version 2 code (25 × 25 modules).
- A 120-character URL with tracking parameters needs version 6 or 7 (41 × 41 or 45 × 45 modules).
At the same printed size, the shorter code's modules are nearly twice as large, so it scans from twice the distance and tolerates blur, glare and cheap phone cameras far better. Use a short domain or path, remove unnecessary query parameters, and avoid encoding long text when a link would do.
Size and scanning distance
A practical rule of thumb is that the code's width should be at least one tenth of the scanning distance:
| Scanning distance | Minimum code width |
|---|---|
| 25 cm (table, business card) | 2.5 cm |
| 1 m (poster at arm's length) | 10 cm |
| 3 m (wall poster) | 30 cm |
| 10 m (billboard) | 1 m |
For dense codes, add 20–50% to these figures. Never print a QR code smaller than about 2 × 2 cm.
The quiet zone
The QR specification requires a blank margin of four modules around the code. Scanners use this empty border to find the edges. Designers often crop it to save space or place the code against a busy background, and scanning reliability drops sharply. Keep at least four modules of plain background on every side; in a QR code generator, this is the Margin setting.
Contrast and colour
Scanners convert the image to grayscale and look for luminance differences. That leads to a few rules:
- Dark on light. Black on white is ideal. Dark blue, dark green or dark brand colours on a white or pale background work well.
- Avoid light foregrounds. Yellow, light grey, pastel and neon colours often lack enough contrast.
- Avoid inverted codes (light modules on dark background) unless you have tested them; some scanner apps do not support them.
- No gradients or images behind the code. If the code must sit on a photo, put it on a solid white panel with a quiet zone.
- Watch the medium. Glossy finishes cause glare under shop lights; matte is safer. Transparent stickers take on the colour of whatever they are stuck to.
Error correction levels
QR codes use Reed–Solomon error correction, so a partially damaged or obscured code can still be read:
| Level | Recoverable damage | When to use |
|---|---|---|
| L | about 7% | Screens, clean environments, maximise capacity |
| M | about 15% | Default for most print |
| Q | about 25% | Outdoor, industrial, likely scuffs |
| H | about 30% | Logo in the centre, harsh environments |
Higher levels add redundancy, which increases the number of modules. Do not pick H by default; choose it only when you need the resilience, such as when placing a logo over the centre.
Adding a logo
A logo can make a code recognisable, but it obscures modules. To do it safely:
- Use error-correction level H.
- Keep the logo under about 20% of the code's area and centred.
- Never cover the three finder patterns or the quiet zone.
- Give the logo a solid background so it does not blend into surrounding modules.
- Test with multiple phones, including older and budget models.
Static versus dynamic QR codes
A static code contains the final content directly. It works forever, needs no service and involves no tracking. The trade-off: once printed, the content cannot change.
A dynamic code contains a short redirect URL operated by a QR service, which forwards to your destination and records scans. You can change the destination later and see analytics. The risks: if the service shuts down, changes pricing or your subscription lapses, every printed code breaks — and some free services have inserted ads or interstitial pages.
A good middle ground: generate a static code pointing to a short URL on your own domain, such as example.com/menu, and configure redirects on your server. You keep control, can change the destination and can measure visits with your existing analytics — all without depending on a third party.
Content types beyond URLs
QR codes can encode structured content that phones understand natively:
- Wi-Fi:
WIFI:T:WPA;S:CafeGuest;P:coffee2026;;lets guests join without typing the password. - Contact cards: a vCard (
BEGIN:VCARD ... END:VCARD) saves name, phone and email in one tap. - Email and SMS:
mailto:hello@example.com?subject=HiorSMSTO:+15551234567:Hello. - Calendar events: an iCalendar
VEVENTblock adds an event. - Geo locations:
geo:52.52,13.405opens a map.
Each extra field increases the data size, so keep contact cards concise.
Security and trust
QR codes are opaque to humans, which attackers exploit — so-called "quishing". Fake stickers on parking meters and restaurant tables have redirected people to phishing payment pages. To maintain trust:
- Use a recognisable domain on HTTPS, so the phone's preview shows a URL people trust.
- Print the short URL as text next to the code, so people can verify it or type it manually.
- For public placements, use tamper-evident materials and check them periodically.
- Avoid URL shorteners that hide the destination domain.
Testing checklist
Before sending anything to print:
- Scan with at least two phones and two apps, including the built-in camera on iOS and Android.
- Test at the real size: print a proof, do not just scan from your monitor.
- Test at the expected distance and in the expected lighting.
- Confirm the destination works on mobile, loads quickly and uses HTTPS.
- Check the quiet zone survives the final layout and trimming.
- Export as SVG or high-resolution PNG; avoid JPEG, whose compression blurs module edges. If you need a small file for the web, see how to compress images — but keep QR codes in lossless formats.
QR codes versus barcodes
QR codes hold far more data and scan from any angle, which is why they suit URLs and payments. Linear barcodes remain the standard for retail checkout and logistics because existing scanners and supply chains depend on them. For a tour of linear and 2D symbologies, see barcode types explained.
Summary
Encode as little as possible, print large enough for the scanning distance, keep a four-module quiet zone, use dark-on-light colours with strong contrast, choose error correction deliberately, prefer static codes pointing to your own domain, and test real prints on real phones. Follow these practices and your codes will work for everyone, every time.