How to Check a QR Code Before Opening It

How to Check a QR Code Before Opening It

To check a QR code before opening it, scan it with something that shows you the contents without acting on them, then read the full web address and find the real domain name before you tap anything. If the code wants you to pay, log in or install an app, skip the link and go to the company’s site or official app yourself. That one habit stops most QR code scams, because a scam code has to send you to an address the scammer controls.

The FTC puts it simply: if you see a QR code in an unexpected place, inspect the URL before you open it and look for misspellings or switched letters. Below is how to do that properly, and where the method runs out.

What does checking a QR code actually involve? #

A QR code is just stored text. Most codes you meet hold a web address, but they can also hold a Wi-Fi login, a contact card, a phone number, a pre-written text message or plain words. Scanning the code only reads that text. Nothing happens until you tap the link, join the network or send the message.

So checking a code means reading what it contains and asking two questions:

  • Where will this take me? For a link, that’s the domain name, not the logo on the sticker or the page title.
  • What does it want me to do? Paying, signing in, typing card details or installing something is where the money and data leave.

Step by step: how to check a QR code before you open it #

  1. Look at the code itself. On a parking meter, poster or restaurant table, check whether the code is a sticker placed over something else. The FBI specifically tells people to make sure a physical code hasn’t been tampered with, for example with a sticker on top of the original.
  2. Scan without opening. Use a scanner that previews the contents instead of launching them. Your phone’s camera shows a small link banner first; a dedicated scanner can show more.
  3. Read the full address. Don’t stop at the first few characters. Scam links often start with something familiar and hide the real destination further along.
  4. Find the real domain. Look at the part between https:// and the next /. Read it from right to left: the last two pieces (or three for addresses like .co.uk) are the domain that owns the page. In https://login.yourbank.com/account, the owner is yourbank.com. In https://yourbank.com.account-verify.info/, the owner is account-verify.info, and “yourbank.com” is just decoration.
  5. Check for red flags. Watch for a shortened link (bit.ly, tinyurl.com, qrco.de and similar), plain http:// with no “s”, a string of numbers instead of a name, an @ sign in the address, or odd characters that imitate normal letters.
  6. Judge the request. If the page wants a payment, a password or an app download, don’t do it from the code. Type the company’s address yourself or open its app.
  7. When unsure, walk away. A legitimate business always has another way to reach it. A scammer only has the code.

How can you see where a QR code goes without opening it? #

On iPhone #

Apple’s Camera app reads QR codes on its own. Apple’s instructions are to open Camera, frame the code and tap the link that appears. That link banner is your preview: read it before you tap. It usually shows a short version of the destination, often just the domain, so a long or suspicious address can hide details you’d want to see.

On Android #

Most Android phones read QR codes through the camera app or Google Lens, and show a link chip before opening anything. The same rule applies: read it, don’t just tap it.

With a scanner that shows everything first #

QR Handler is built for this step. It never opens a code by itself. Every scan lands on a result screen showing the full contents: the whole link, the Wi-Fi network and password, or the contact details. For links it adds a safety strip with the real host name, whether the link is encrypted (https) or not, and warnings for shortened links, raw IP addresses, @ tricks and look-alike characters. For a shortened link, a Reveal destination button follows the redirect and shows where it really ends up, but only when you tap it.

What can a QR code checker actually catch? #

Some tricks are easy to spot mechanically. Others can’t be detected by any scanner. This is roughly how it breaks down:

CheckWhat it tells youWhat it misses
Show the full addressExactly where the link pointsWhether that site is honest
Highlight the real domainWho owns the pageA convincing new domain like cityparking-pay.com
Flag http vs httpsWhether the connection is encryptedScam sites use https too; the padlock only means encrypted
Flag link shortenersThat the destination is hiddenWhere it leads, until the redirect is followed
Flag raw IP addressesThe link skips a named siteNothing about who runs the server
Flag @ in the addressText before the @ is fakeNothing further
Flag look-alike charactersNon-Latin letters posing as normal onesPlain-letter swaps like paypa1 or rnicrosoft

The padlock deserves its own warning. HTTPS means nobody can read the traffic between you and the site. It doesn’t mean the site is who it claims to be, and most phishing pages have it.

What no QR scanner can tell you #

Be skeptical of any app that promises to catch every malicious code. No scanner can:

  • Know a normally spelled domain is a scam. A fake payment site registered yesterday with an ordinary name passes every character check.
  • See that a sticker covers a real code. That’s a job for your eyes.
  • Judge what the page will do. A clean-looking link can lead to a page that asks for your card number.
  • Spot a real site that’s been hacked. The domain is genuine; the content isn’t.

That includes QR Handler. Its link checks run entirely on your phone, with no blocklist or reputation lookup. It shows you what’s really there and flags the known tricks, so the decision stays with you. The Reveal destination button is the one exception to working offline: it has to contact the link to follow the redirect, so the server learns that someone checked it.

If you want a second opinion on a specific address, you can paste it into a reputation checker such as Google’s Safe Browsing site status or VirusTotal. A “no issues found” result only means the site hasn’t been reported yet, so treat it as one input, not a verdict.

Extra care for payment and login codes #

Most QR scams aim at money or passwords, so give those codes more scrutiny than a menu or a museum label.

  • Parking and tolls: pay through the city’s or operator’s official app from the App Store or Google Play, the meter itself, or an address printed on an official sign. Our guide to fake parking meter QR codes covers the physical signs of tampering.
  • Emails and texts with codes: treat a code in a message the same way you’d treat a link. If it claims a failed delivery or a problem with your account, contact the company using a number or address you already trust. The FBI advises exactly this for “failed payment” messages.
  • Anything asking you to log in: type the site’s address yourself or use its app. The FBI’s advice is to type a known, trusted address rather than follow the code, especially for payments.

For the wider picture of how these attacks are built, see what quishing is.

Frequently asked questions #

Can I see where a QR code goes without opening it? #

Yes. Scanning only reads the code, and both iPhone and Android show a preview banner before opening anything. For the full address instead of a shortened preview, use a scanner that displays the whole contents first and lets you decide what to do.

Does the iPhone camera check QR codes for safety? #

The Camera app reads the code and shows you the link. Apple’s scanning instructions don’t describe a safety check at that step. Safari’s Fraudulent Website Warning setting can flag some known phishing sites once a page loads, but it only knows about sites already reported.

Is a QR code with https safe? #

Not necessarily. HTTPS only means the connection is encrypted, and scam sites routinely use it. Check the domain name itself and what the page asks you to do.

What should I do if I already opened a suspicious QR code? #

If you only looked at the page, close it. If you entered a card number, password or personal details, act on that right away. Our guide on what to do after scanning a malicious QR code walks through each case.

The risks are the same, but a QR code hides its destination until you scan it, and you usually open it on a phone where the address bar is small. That’s why scanning safely mostly comes down to reading the address before you tap.