QR safety

How to check a QR code before opening it

A QR code hides its destination from your eyes. Decode first, inspect the result, and open only when the destination makes sense.

Open the scanner

Read the real destination domain

Look at the hostname rather than familiar words elsewhere in the URL. Attackers can place a trusted brand in the path or subdomain while the registered domain belongs to someone else.

Treat shortened links carefully

A shortener conceals the final destination and may redirect more than once. Do not enter a password or payment information unless the final domain is the service you expected.

Warnings are signals, not guarantees

Automated checks can point out unusual protocols, raw IP addresses, punycode, embedded credentials, and common shorteners. A clean-looking result can still be harmful, and a warning does not always mean a link is malicious.

Privacy note

QR image decoding happens inside your browser. QR Scan Online does not need a copy of the image or the decoded content.

Frequently asked questions

Can a QR code itself install malware?

Scanning normally reveals data or a link. The danger usually begins when a person opens an unsafe destination, downloads a file, grants permissions, or enters sensitive information.

What is punycode?

Punycode represents international characters in a domain using an xn-- prefix. It is legitimate in many cases, but visually similar characters can also be used to imitate familiar domains.