A quick process for checking QR destinations before visiting, signing in, or paying.
A QR code is a convenient container, not a trust certificate. A sticker placed over a parking sign or restaurant notice may point somewhere different from the original. Use the same caution you would apply to a link in an unexpected message.
Before scanning
- Look for tampering, an extra sticker, or a mismatched design.
- Ask whether the context makes sense. A payment request deserves more scrutiny than a menu.
- Prefer the official app or typed website when handling a bank, government, or account login.
After decoding
Preview the result before opening it. For a URL, inspect the registered domain, not just familiar words elsewhere in the address. Watch for misspellings, unusual subdomains, punycode, or a shortened link that hides the destination. HTTPS protects the connection but does not prove that the site owner is honest.
Before sharing information
Do not enter a password, card number, one-time code, recovery phrase, or personal document unless you independently confirmed the destination. A legitimate organization should not pressure you to act immediately after an unsolicited scan. For payments, compare the recipient and amount inside the trusted payment app.
If something looks wrong
Close the page, do not download files, and report the physical code to the venue or organization. If you entered credentials, change them through the official service and review account activity. Readability only tells you the symbol was decoded; it says nothing about safety.