How to Scan a QR Code Safely
A QR code can contain a website address, contact details, Wi-Fi settings, or plain text. Scanning reveals the encoded content; it does not confirm that the content is safe or that the code came from the organization named beside it.
Inspect the code and its context
Look at the physical surface before scanning. If a sticker appears to cover another code, the print is damaged, or the code is placed somewhere unexpected, do not use it until you can verify it with the organization responsible. A QR code in an unsolicited email or text deserves the same caution as an unexpected link.
The FBI warns that QR scams can lead to fake payment portals or pages that ask for credentials, and that malicious stickers may be placed over legitimate codes. If a code claims to offer a refund, prize, gift card, delivery update, or urgent account fix, confirm the offer through a separate channel you already trust.
Decode first, then decide whether to open
- Scan the image or use a camera: TheCodePlaza QR Scanner displays the decoded result and offers a separate Open URL action for URL results.
- Read the complete domain: Check the actual hostname character by character. Look for misspellings, extra words, unexpected subdomains, or a domain that does not belong to the organization you expect.
- Verify out-of-band when needed: For payments, account access, or personal information, open the organization’s known app or type its known address yourself instead of following an unexpected code.
- Stop if the request is surprising: Do not enter a password, payment card, recovery code, or personal details just because a QR destination asks for them.
What the address can and cannot tell you
A familiar-looking logo or page title is not proof that the destination is genuine. Check the domain, not only the words shown on the page. HTTPS protects the connection between your browser and a site, but it does not prove that the site itself is the right business or government service.
This scanner decodes a QR payload in the browser and shows its contents before you choose whether to open a URL. That is a useful inspection step, not a security reputation service: it does not certify a link, inspect every page behind it, or guarantee that the destination will remain unchanged.
Warning signs worth checking
- The code is pasted over another one, altered, or displayed in an unexpected place.
- The destination uses a look-alike domain or a shortened address you cannot verify.
- A familiar brand is used to request a password, payment, banking details, or recovery code.
- The message creates urgency or offers a reward that you were not expecting.
Common questions
Does scanning a QR code infect a phone by itself?
A QR code is encoded data, often a link. The risk depends on what it contains and what happens next; do not open or act on a destination just because it was presented as a QR code.
Is an HTTPS link automatically trustworthy?
No. HTTPS indicates an encrypted connection to that domain. You still need to check that the domain is the organization you intended to reach.
Sources and further reading
- FBI: Building a Digital Defense Against QR Code Scams — Advice about suspicious QR codes, altered stickers, and unexpected credential requests.
- DENSO WAVE: What is a QR Code? — Technical explanation of QR codes as carriers of encoded information.