How to check a QR code link before opening it
Decode first. Decide separately. A QR code can contain a web address, text, contact details or a Wi-Fi configuration. Reading its contents is different from visiting a website, joining a network or approving a sign-in.
Start with the context, not the logo
Were you expecting this code? An unexpected delivery message, an urgent account warning or a sticker placed over another code deserves a pause. For a payment or account action, use the organization’s known app, a saved bookmark or contact information you already trust.
The FTC’s QR-code scam advisory describes replacement parking-meter codes and messages designed to rush people into opening spoofed sites. A familiar brand image does not establish who controls the destination.
Read the destination without following it
- If you already have a QR image or screenshot, open the browser-local QR Code Scanner and select it. It supports PNG, JPEG and WebP without camera access or image uploads.
- Read both the decoded text and the separately displayed host. Do not paste the result into the address bar just to see what happens.
- Check spelling and punctuation against a known address. Treat unexpected internationalized names, an IP address, credentials before an @ sign or a non-web action as reasons to investigate independently.
- If you cannot establish the intended destination, stop and use a trusted route. A warning-free result is not proof that a site is safe.
A brand name can appear outside the real host
These are inert examples using reserved example domains, not links to visit:
https://accounts.example.com/loginhas the hostaccounts.example.com.https://accounts.example.com.attacker.example/loginhas the hostaccounts.example.com.attacker.example, notaccounts.example.com.https://accounts.example.com@attacker.example/loginhas the hostattacker.example. The text before @ is not the destination.
Do not reduce this to “trust the last two words”: public suffixes vary, and legitimate-looking hosts can be compromised. HTTPS protects a connection to the named site; it does not certify the site’s honesty.
Short links and redirects leave an information gap
A QR code may point to a shortening or tracking service that redirects somewhere else. The scanner displays the encoded destination; it deliberately does not contact that service, expand short links or fetch a preview. This avoids sending the link to a remote checker, but it also means the final destination is unknown.
For a sensitive action, that gap is a reason to choose the official app or a known address, not to click through until you find out. Never approve an unexpected sign-in merely because its QR code came from a familiar-looking page.
If you already interacted with it
Stop entering information. If you supplied credentials, use the real service through a trusted route to secure the account and contact its support. For a work account or device, report what happened through your organization’s established security channel. The scanner cannot tell whether a device or account has been compromised.
See the FTC’s phishing guidance for further steps. Do not send passwords, QR sign-in tokens or confidential screenshots to our correction mailbox.
Decoded content is information, not a reputation check or a guarantee. Keep your browser and device updated.