Is QR Device Linking Safe?
See the security boundary of short-lived QR requests, explicit approval and recognized devices.
Safety in context
QR linking is safer when the code is short-lived, the scan only requests access, and the current inbox session must explicitly approve the device.
Safety comes from the full flow, not the square code
The QR is only one part of the design. A safe flow also depends on recognizing the device, refusing unexpected requests and not leaving the linked inbox open on a borrowed phone.
Device linking keeps the task inside one active MailOnce inbox. The QR code is only a short request mechanism; access still depends on approval from the browser that already controls the inbox.
Judge the flow, not the QR image
Safety depends on several parts working together: a short-lived request, an explicit approval step, and the user checking that the device is expected. The right habit is to refuse anything you did not initiate and to avoid leaving the inbox open on a borrowed or shared device.
The practical takeaway
Treat the QR as a request token, not a password. Approve only the device you intended to link.
Try MailOnce
Move one active inbox between your own devices
Create a temporary inbox, then link another device only when your task genuinely moves from one screen to another.
Create temporary emailRelated device linking guides
Continue with the device-linking topics closest to what you just read.
How to Open the Same Temporary Inbox on Another Device
Continue with the inbox already receiving your messages instead of creating a second address.
Read guideHow QR Device Linking Works in MailOnce
Follow the request from rotating QR code to browser approval and access on the second device.
Read guideWhy Does MailOnce Require Approval After Scanning the QR Code?
Understand why a scan starts a request but the existing session still controls permission.
Read guide