Skip to content
QRnook

7 min read

QR code safety: how to spot a malicious code

A QR code can hide a link until you scan it. Treat it like any other link: check the destination before opening it and be cautious when a sticker or message seems out of place.

Check the destination

Use the camera preview or a decoder to read the address first. Look at the complete domain name, spelling, subdomain and unusual characters. A familiar logo beside the code does not prove who placed it.

Be cautious with unexpected payment requests, password resets, app installs, prize claims and urgent warnings. Navigate to a service through its official app or a saved address when unsure.

Inspect without opening

A QR decoder can show the encoded text and flag some risky patterns. It cannot determine whether a page is currently compromised, and a clean-looking link can still be harmful.

QRnook never opens a scanned destination automatically. The decision stays with you after you review the decoded content.

If you already opened it

Close the page if something feels wrong. Do not enter credentials or payment details from an unexpected prompt. If you entered a password, change it from the service’s official app or website and check account activity.

In short: A QR safety check can reveal clues, but no local scanner can certify that a website is safe.