Verdetto

How to check a QR code link before you open it

Updated 2026-09-03. About a four-minute read.

In short. Before you open a link from a QR code: read the domain, not the whole address; treat shortened links as unknown until they are expanded; look for lookalike names; check for https and no unusual port; never install anything a code hands you; and ask why the code is where it is. A scanner can show you all of that. It cannot tell you a page is safe.

A QR code is just a way of typing a link so you do not have to. The trouble is that the link is invisible until something reads it, and most scanner apps open it the instant they do. Fake codes on parking meters, restaurant tables, posters, and even in emails rely on exactly that. The fix is simple: look at the link before you open it. Here is what to look at, in order.

1. Read the domain, not the whole link

The domain is the part after https:// and before the first single slash. In https://accounts.example.com/login?ref=qr the domain is accounts.example.com, and the part that matters most is the last two labels, example.com. Everything after the slash can say anything; it is the domain that decides where you land. A good scanner shows the domain by itself in large type, so you do not have to find it in a long string.

2. Treat shortened links as unknown

Links through bit.ly, t.co, tinyurl, and similar services hide their destination on purpose. A code that shows one of these tells you nothing until it is expanded. Either expand it first, with a scanner that follows the short link and shows you where it ends up, or do not open it.

3. Look for lookalikes

The oldest trick is a domain that reads like a familiar one. Watch for a digit standing in for a letter (paypa1.com), an extra word or hyphen (paypal-secure.com), a familiar name pushed into the wrong place (paypal.com.example.net, where the domain is example.net), and letters from another alphabet that draw the same shape. If a name looks almost right, it is wrong.

4. Check the connection and the port

A link that starts with http:// rather than https:// sends everything you type in the open. A link with a number after the domain, such as example.com:8080, is talking to something other than an ordinary website. Neither proves a scam, but neither belongs on a code that asks you to sign in or pay.

5. Do not install what a code hands you

A link that ends in .apk is an Android program, not a page. Apps come from the store, not from stickers. The same goes for links that ask for permission to install "an update" or "a viewer" before you can see anything.

6. Ask why the code is there

A QR code stuck over another QR code, a code on a parking meter that already has a payment terminal, a code in a text message from a number you do not know, a code that promises a refund or a prize: the placement is the warning. Criminals print stickers because stickers are cheap. When a code appears where a code would not naturally be, skip it and use the official app or website directly.

What a scanner can and cannot tell you

A scanner can show you the link in full, expand a short one, flag the patterns above, and compare the address with lists of known phishing and scam sites. What it cannot do is open the page and judge it for you, and no list is complete. That is why Verdetto reports "No warnings found" rather than "safe": it means none of its checks matched, and the last check is the one you make by reading the address. If a code asks you to sign in, enter card details, or install something, close it and go to the site you already know.

If you already opened one

Close the page. If you typed a password, change it on the real site and anywhere else you used it. If you entered card details, tell your bank. If you installed something, uninstall it and run a scan with the security software already on the phone. Then delete the code from your history so you do not open it again by accident.

Verdetto shows every link before it opens, expands shortened ones, and flags each of the patterns above on your phone, with no ads. See what it does.