Level 1: Use your phone's built-in preview
Both iPhones and Android phones show you the destination link before opening it — this is your fastest, always-available first check.
- iPhone: open the standard Camera app and frame the QR code. A banner appears at the top showing the URL — read it before tapping.
- Android: open the Camera app or Google Lens and frame the code. A preview chip shows the link — tap and hold rather than tapping straight through.
A preview only shows you the raw URL — it doesn't tell you whether that destination is actually safe. URL shorteners hide the real address entirely, and lookalike domains (like "paypa1.com") can pass a quick glance without registering as wrong.
Level 2: Read the domain carefully
If the preview shows a full domain (not a shortened link), take a moment to actually read it rather than skimming it. Ask:
- Does this domain match the business or organization I'd expect? (A real parking app isn't going to be hosted on a random unrelated domain.)
- Are there subtle misspellings, extra words, or unusual endings (.xyz, .top) that a real brand wouldn't use?
- Is it a URL shortener (bit.ly, tinyurl, etc.)? If so, you genuinely can't tell where it leads without unshortening it first.
Level 3: Run an actual safety check
For anything that isn't obviously trustworthy — an unfamiliar code in public, an unexpected one in an email, or a shortened link — the most reliable step is checking the destination against real threat data before visiting it.
Upload a photo or scan with your camera — the QR code is decoded right in your browser, and if it contains a link, that destination is checked against threat-intelligence data before you ever visit it. Free, no account needed.
Check a QR code nowA quick decision guide
- Unexpected QR code by email or text? Treat it as suspicious by default — legitimate services send clickable links, not scannable images.
- QR code in public (parking, menu, poster)? Glance for physical tampering first (see our guide to spotting a fake sticker), then preview the link before tapping.
- About to enter a password or payment details after scanning? Always run a full check first — this is exactly the moment attackers are counting on you skipping.