Inbox
Back to Device Linking

Is QR Device Linking Safe?

See the security boundary of short-lived QR requests, explicit approval and recognized devices.

7 min read

Safety in context

QR linking is safer when the code is short-lived, the scan only requests access, and the current inbox session must explicitly approve the device.

Safety comes from the full flow, not the square code

The QR is only one part of the design. A safe flow also depends on recognizing the device, refusing unexpected requests and not leaving the linked inbox open on a borrowed phone.

Device linking keeps the task inside one active MailOnce inbox. The QR code is only a short request mechanism; access still depends on approval from the browser that already controls the inbox.

Judge the flow, not the QR image

Safety depends on several parts working together: a short-lived request, an explicit approval step, and the user checking that the device is expected. The right habit is to refuse anything you did not initiate and to avoid leaving the inbox open on a borrowed or shared device.

Advertisement

The practical takeaway

Treat the QR as a request token, not a password. Approve only the device you intended to link.

Try MailOnce

Move one active inbox between your own devices

Create a temporary inbox, then link another device only when your task genuinely moves from one screen to another.

Create temporary email

Related device linking guides

Continue with the device-linking topics closest to what you just read.