Level 1: Use your phone's built-in preview

Both iPhones and Android phones show you the destination link before opening it — this is your fastest, always-available first check.

Limitation

A preview only shows you the raw URL — it doesn't tell you whether that destination is actually safe. URL shorteners hide the real address entirely, and lookalike domains (like "paypa1.com") can pass a quick glance without registering as wrong.

Level 2: Read the domain carefully

If the preview shows a full domain (not a shortened link), take a moment to actually read it rather than skimming it. Ask:

Level 3: Run an actual safety check

For anything that isn't obviously trustworthy — an unfamiliar code in public, an unexpected one in an email, or a shortened link — the most reliable step is checking the destination against real threat data before visiting it.

How CheckThisQR helps

Upload a photo or scan with your camera — the QR code is decoded right in your browser, and if it contains a link, that destination is checked against threat-intelligence data before you ever visit it. Free, no account needed.

Check a QR code now

A quick decision guide

  1. Unexpected QR code by email or text? Treat it as suspicious by default — legitimate services send clickable links, not scannable images.
  2. QR code in public (parking, menu, poster)? Glance for physical tampering first (see our guide to spotting a fake sticker), then preview the link before tapping.
  3. About to enter a password or payment details after scanning? Always run a full check first — this is exactly the moment attackers are counting on you skipping.