How to Check If a QR Code Is Safe Before You Scan It

The safest way to check a QR code is to preview its destination without opening it, inspect the real domain, and then use the organization’s official app or type its known address yourself. A QR code is only a container: it can point to a legitimate menu or payment page, but it can just as easily hide a fake login, payment form, app download, or redirect.
This matters in 2026 because QR-code scams are still appearing in both physical and digital settings. On August 20, 2026, the U.S. Federal Trade Commission warned that unexpected packages may include QR codes leading to phishing pages. The FBI has also documented malicious QR codes in targeted phishing campaigns. The attack is often called quishing—QR-code phishing.
Use this 30-second QR code safety check
- Look at where the code came from. Treat codes in unexpected texts, emails, parcels, flyers, parking meters, and public signs as untrusted until verified.
- Inspect the physical label. Do not scan a sticker that appears to cover another QR code, has lifted edges, mismatched printing, or sits awkwardly over a payment terminal.
- Preview the link—do not tap it yet. Your phone’s camera normally displays the destination before opening it.
- Read the hostname carefully. Confirm the part immediately before the first single slash is the company’s real domain—not a look-alike.
- Open the official app or type the known website instead. This is the safest option for signing in, paying, downloading software, or providing personal information.
If any part of the process creates urgency—“pay now,” “verify immediately,” “your account will close,” or “scan to claim a refund”—pause. The FTC advises inspecting the URL and contacting the organization through a phone number or website you already know is genuine.
How to preview a QR code without opening it
On iPhone
Open the Camera app and point it at the code. Wait for the link notification to appear, but do not tap it. Read the domain shown in the notification. You can also use Code Scanner from Control Center, but the same rule applies: inspect the destination before opening it.
If the code is inside an image or screenshot, open it in Photos and press and hold the QR code or use the detected-link control. The exact wording can vary by iOS version.
On Android
Open the built-in Camera app and point it at the code. Many Android phones display a URL card before opening the browser. Google Lens can also identify a code in a saved image: open the screenshot in Google Photos, choose Lens, and examine the result without visiting it.
Do not install a random “QR scanner” just to inspect a code. Modern iPhones and Android phones already provide scanning tools, and an unnecessary scanner may request access to your camera, contacts, location, or files. Apply the same permission and developer checks you would use when deciding whether a browser extension is safe before installing it.
How to read the real domain in a QR-code link
Scammers rely on people recognizing a trusted word anywhere in a URL. The important part is the registered domain—not the page title, padlock icon, or first familiar-looking word.
Consider this example:
https://accounts.example.com.verify-now.net/login
The controlling domain is verify-now.net, not example.com. Everything to the left of it is a subdomain chosen by whoever owns verify-now.net.
Check for:
- misspellings, extra hyphens, doubled letters, or substituted characters;
- a trusted brand name placed before an unfamiliar domain;
- URL shorteners that hide the final destination;
- an IP address instead of a recognizable domain;
- an unfamiliar country-code or top-level domain;
- long strings designed to push the real hostname off the screen.
HTTPS does not prove that a site is legitimate. It only means the connection between your device and that site is encrypted. A phishing site can also obtain a valid certificate and display a padlock.
Red flags that mean “do not continue”
The code is a sticker on a public payment point
Fraudsters may paste their own QR code over a legitimate one on parking meters, restaurant tables, charging stations, or ticket machines. The FBI specifically advises checking for physical tampering. Use the operator’s official app, type the address printed elsewhere on the machine, or ask an employee to confirm the code.
The page immediately asks you to sign in or pay
A QR code that leads directly to a Microsoft 365, Google, bank, delivery, toll, or parking login should be treated cautiously. Close the page and sign in through the official app or a bookmark you created yourself. Your password manager refusing to fill the credentials can be a valuable domain-mismatch warning—do not override it automatically.
It asks you to install an app, APK, profile, or certificate
Do not install software from a QR-code landing page. Find the app independently in Apple’s App Store or Google Play and confirm the publisher. On Android, never enable “install unknown apps” because a QR page instructs you to. On iPhone, do not approve an unfamiliar configuration profile or device-management enrollment.
It requests unusual permissions
A menu, parking-payment page, or package-tracking site should not need access to your contacts, microphone, accessibility controls, device administration, or screen sharing. Reject the request and leave the page.
It arrived in an unexpected package
The FTC’s August 20, 2026 warning about brushing scams notes that a package you did not order may contain a QR code claiming to identify the sender or process a return. The destination may instead collect card details or account credentials. Check your retailer account directly; do not use the enclosed code.
Can a QR code infect your phone just by scanning it?
Usually, merely letting the camera recognize a QR code does not execute the destination. The larger risk begins when you open the link, download a file, install software, grant permissions, enter credentials, or approve a payment.
That distinction is useful, but it is not a reason to be careless. Keep your phone and browser updated because security flaws do exist, and close any unexpected page immediately. A safe-looking first URL can also redirect to a different destination after you tap it.
Should you check a QR link with VirusTotal?
For a public, non-sensitive URL, a multi-engine reputation service can provide an additional signal. It cannot guarantee that a new or selectively targeted page is safe, and a clean result is not permission to ignore a suspicious domain.
Never submit a private sign-in, password-reset, invitation, medical, billing, or document-sharing link to a public scanning service. Such URLs may contain tokens that grant access or identify you. For sensitive links, navigate to the official service independently.
Special cases: Wi-Fi, payments, and authentication
Wi-Fi QR codes
A Wi-Fi QR code may contain a network name and password rather than a website. Confirm the network name with staff before joining, especially in airports, hotels, cafés, and conferences. A legitimate-looking network name does not prove that the hotspot belongs to the venue. Use this checklist to tell whether public Wi-Fi is safe before handling sensitive accounts.
Payment QR codes
Verify the merchant name and amount inside your bank or wallet app before authorizing. Never approve a payment simply because a caller or message claims it will “reverse” a charge. If the payee is unfamiliar, cancel and confirm with the merchant using a separate channel.
Authenticator setup codes
Two-factor authentication QR codes contain a secret used to generate login codes. Treat them like passwords: do not photograph, upload, share, or scan someone else’s setup code. Keep recovery options current; our guide explains how to transfer Google Authenticator to a new phone without losing codes.
What to do if you already scanned a suspicious QR code
If you only opened the page
- Close the tab and do not accept downloads, notifications, or permission requests.
- Delete any file that downloaded unexpectedly without opening it.
- Update the phone’s operating system and browser.
- Check the browser’s download list and site permissions.
If you entered a password
- Go to the real service using its official app or a manually typed address.
- Change the compromised password immediately, plus any reused version on other accounts.
- Review active sessions, recent sign-ins, forwarding rules, and recovery details.
- Sign out unknown devices and enable multi-factor authentication.
Prefer a phishing-resistant passkey or security key when the service offers one. If you use an authenticator app, never give a one-time code to someone who contacts you unexpectedly.
If you entered card or bank details
Call the issuer using the number printed on the card or shown in the official banking app. Ask it to block or replace the card, review pending transactions, and document the fraud. Do not call a number displayed on the suspicious page.
If you installed an app or device profile
Disconnect from the network, uninstall the app, and remove any unfamiliar device-administration, accessibility, VPN, or configuration-profile access. Run the phone’s built-in security checks. If the device behaves unusually or sensitive accounts were accessed, seek professional help and consider a factory reset after preserving essential files.
Report the QR-code scam
Report the code to the organization being impersonated and to the owner of the physical location so it can be removed. In the United States, file a report at ReportFraud.ftc.gov. For phishing messages, the CISA phishing guidance recommends using a known, legitimate contact route rather than links or phone numbers in the suspicious message.
Bottom line
You cannot prove that every QR code is safe by looking at its pattern. You can, however, avoid most QR phishing by checking the context, previewing the URL, identifying the real domain, and switching to the official app or a manually entered website for any login, payment, or download. When a code combines secrecy, urgency, and a request for sensitive information, do not scan it.

