← All guides

How to check a QR code link before opening it

By Paragamix GmbH · Published · Developed with AI assistance

Decode first. Decide separately. A QR code can contain a web address, text, contact details or a Wi-Fi configuration. Reading its contents is different from visiting a website, joining a network or approving a sign-in.

Start with the context, not the logo

Were you expecting this code? An unexpected delivery message, an urgent account warning or a sticker placed over another code deserves a pause. For a payment or account action, use the organization’s known app, a saved bookmark or contact information you already trust.

The FTC’s QR-code scam advisory describes replacement parking-meter codes and messages designed to rush people into opening spoofed sites. A familiar brand image does not establish who controls the destination.

Read the destination without following it

  1. If you already have a QR image or screenshot, open the browser-local QR Code Scanner and select it. It supports PNG, JPEG and WebP without camera access or image uploads.
  2. Read both the decoded text and the separately displayed host. Do not paste the result into the address bar just to see what happens.
  3. Check spelling and punctuation against a known address. Treat unexpected internationalized names, an IP address, credentials before an @ sign or a non-web action as reasons to investigate independently.
  4. If you cannot establish the intended destination, stop and use a trusted route. A warning-free result is not proof that a site is safe.

A brand name can appear outside the real host

These are inert examples using reserved example domains, not links to visit:

Do not reduce this to “trust the last two words”: public suffixes vary, and legitimate-looking hosts can be compromised. HTTPS protects a connection to the named site; it does not certify the site’s honesty.

Short links and redirects leave an information gap

A QR code may point to a shortening or tracking service that redirects somewhere else. The scanner displays the encoded destination; it deliberately does not contact that service, expand short links or fetch a preview. This avoids sending the link to a remote checker, but it also means the final destination is unknown.

For a sensitive action, that gap is a reason to choose the official app or a known address, not to click through until you find out. Never approve an unexpected sign-in merely because its QR code came from a familiar-looking page.

If you already interacted with it

Stop entering information. If you supplied credentials, use the real service through a trusted route to secure the account and contact its support. For a work account or device, report what happened through your organization’s established security channel. The scanner cannot tell whether a device or account has been compromised.

See the FTC’s phishing guidance for further steps. Do not send passwords, QR sign-in tokens or confidential screenshots to our correction mailbox.

Inspect a QR image locally →

Decoded content is information, not a reputation check or a guarantee. Keep your browser and device updated.

Methodology and review limitations · Report a non-sensitive correction