Security 2026-02-12 7 min By Cornelious Fazal

How to Check QR Code Safety: Pre-Scan Verification Guide

Try the QR Generator Free · No signup · Permanent

Quick Answer

Check a QR code by inspecting the physical label, previewing the decoded address, and confirming the expected domain before opening it. These checks reduce risk but cannot prove a destination is safe; stop if the page redirects unexpectedly or requests information the stated task does not need.

security/how-to-check-qr-code-safety.html
// FAQ

Frequently Asked Questions

Run your fingernail along the edges of the code. A raised ridge, misaligned border, or peeling paper indicates a malicious sticker has been pasted over the original printed signage. Avoid scanning any layered codes. Check the final destination, mobile layout, and printed placement before distributing the code to users.

Inspect the root domain name before tapping. Look for typosquatting (e.g., paypa1.com), mismatched brand names in subdomains, or unprompted URI schemes such as tel:, SMSTO:, or WIFI:. Provide a visible alternative when the workflow depends on a particular camera feature, app, account, or network connection.

No. Scanning a computer screen with a mobile phone is a primary vector for corporate quishing attacks designed to bypass endpoint monitoring. Legitimate IT systems rarely require scanning desktop screens for routine tasks. Document the expected domain near the code so users can recognize a substituted sticker or misleading redirect.

Red flags include unprompted file download prompts (APK or mobile profiles), immediate login forms for Microsoft 365 or Google on unrelated sites, missing HTTPS locks, and artificial countdown timers demanding payment. Use a stable public destination, test it while signed out, and keep ownership details with the printed campaign record.

Photograph the code without tapping the preview link, then upload the image to an offline client-side QR payload decoder. Check the extracted plaintext URL against VirusTotal or Google Safe Browsing. For an unfamiliar code, inspect the destination first and confirm the organization through a separate trusted channel.