Docs · Guide

Is this QR code safe to scan

Scanning is safe. Tapping is the decision. A QR code is text drawn as squares, and reading it does nothing to your phone; what matters is what the text asks you to do next, and there are three checks that answer that before you do it, none of which needs an app.

What a QR code can and cannot do

The pattern encodes a string of characters. The camera decodes that string and shows it to you. That is the whole exchange, and it is why "scanning a QR code" cannot on its own install anything, run anything or take anything. The content is one of a few kinds, and each has a different next step:

  • A web address · the phone offers to open it. The risk is the page: a lookalike login, a fake payment form, a download. This is nearly every code you will meet.
  • WiFi credentials · the phone offers to join the network. Joining a network you did not choose means your traffic goes through it. A café's code on the counter is fine; a code on a lamppost is not.
  • A contact card, a phone number, a pre-written message · the phone offers to save, dial or send. The thing to read is the number and the message text, because a pre-filled premium-rate number or a message that "confirms" something is the attack.

In every case the phone stops and shows you the content before acting. That pause is the safety feature. Use it.

Three checks before you tap

  • Read the banner. When the camera recognises a code it shows the address in a small banner. Read the domain before tapping. If it is the company you expect, on a domain you recognise, go ahead. If it is a shortener or a domain you have never seen, the destination is one hop further away and you have not seen it yet.
  • Look at the object. The commonest real-world attack is not a clever code, it is a sticker. A code stuck over the printed one on a parking meter, a menu or a poster is the thing to look for: edges that do not match the artwork, a different paper, a code where the design around it did not leave room for one. If the meter has a card reader, use it, and tell whoever runs the site.
  • Read the address you land on, from the first slash backwards. The part just before the first slash is the owner of the page, and everything before that is decoration. A page that then asks for a password, a card number or a code from your bank is asking for something a poster never needs. Close it, search for the company's real site, and go there instead.

Seeing inside a code without opening it

If the banner shows only a short address, or you want to see exactly what a code contains before your phone acts on it, read it from a photo instead. Our free decoder takes a photo or a screenshot and reports the text out of the pattern · the full address, a WiFi payload with its network name, a contact card field by field · without fetching or visiting anything, and nothing is uploaded to us. It reads codes made by anyone, not only ours. What it cannot tell you is where a short address leads, because that needs the redirect to run, and running it is the thing you are avoiding.

Why almost every code goes through a short link

A printed code cannot be edited, so the businesses that print them point the code at a short address they control and keep the real destination behind it, editable. That is what a dynamic code is, and it is legitimate: it is how a menu code survives a new website and how a recalled product's code can be pointed at the recall notice. It also means the first domain you see is a middleman's, and the page you end up on belongs to whoever made the code.

Some services put a screen between the scan and the page. Codes made with taproute can show one that names the brand and says which hostname you are heading to, and where the owner has proved they control that domain by a DNS record it carries a verified mark. It is there so you can read the destination before the redirect. It appears because the owner turned it on, so its absence is not a signal of anything, and the middleman having a name does not tell you who wrote the page at the end. If the short address you were sent is on tap2u.link, that page says exactly who is in the middle and what we check.

What screening can and cannot promise

Reputable link services check destinations against blocklists of known malware and phishing sites. Ours does, when a link is created, whenever its owner repoints it, and again nightly; a match is refused, and a live link that starts matching is disabled on every printed copy at once. Our free generator checks the link a downloaded code will point at, and only that.

The limit applies to every such check, including ours: a blocklist says a destination is not known to be bad, which is not the same as saying a link is meant for you. New phishing sites outrun blocklists, and if a check cannot reach its blocklist at that moment the link is allowed through rather than refused. No screening replaces reading the address yourself. That is why the three checks above come first and the screening comes last.

If it looks wrong

  • Do not enter anything. A page reached from a poster does not need your password. Close it.
  • Pay another way. For a meter, a charger or a ticket machine, use the card reader or the operator's own app, found through a search rather than through the code.
  • Tell someone. The venue, the operator, the council. And if the code went through one of our addresses, report it to us: every report reaches a person, and a link that breaks our acceptable-use policy is disabled on every copy of the code already printed.

If you are the one printing codes

Everything above is what your customers are, quite rightly, checking. The way to pass those checks is to give them something to read: a code on your own domain, so the banner shows your name rather than a middleman's, and a preview screen with a verified mark, so the destination is stated before the redirect. Both are things you set on a dynamic code, and neither changes the printed pattern.

Questions

Can scanning a QR code hack my phone?

Scanning by itself runs nothing. A QR code is text, and the camera shows you that text · a web address, a WiFi network, a contact card · and waits. The risk is in what you do next: opening a link that leads to a fake login page, joining a network you did not intend to, or sending a message the code pre-filled. The safe habit is reading what the phone shows before tapping it.

How can I see where a QR code goes without opening it?

Most phone cameras show the address in a banner before you tap it, and that banner is the check. If it shows only a short link, the destination is hidden behind another hop. To read the exact contents of a code without visiting anything, use a decoder that works from a photo, such as our free one, which reads the text out of the pattern and never fetches it.

Are QR codes on parking meters and posters safe?

A code that has been stuck over another one is the commonest real attack, because paper is easy to replace and nobody checks. Look at the edges: a sticker on top of printed artwork, a code that does not match the design around it, or a payment link on a meter that also has a card reader are all reasons to pay another way and tell whoever runs the site.

Is a QR code that goes through a short link safe?

Not more or less than the destination behind it. Nearly every printed code goes through a short address so that its owner can change where it points, which is legitimate and useful. It also means the address you see first is not the one you end up on. Judge the final page, and treat an unexpected code the way you would treat an unexpected link in a message.

What should I check on the page a QR code opens?

The domain, read from the first slash backwards: the part just before it is the real owner, whatever comes earlier. Then whether the page asks for something a poster never needs · a password, a card number, a code from your bank. A page that asks for those from a scan deserves a search for the company's real site and a fresh visit there instead.

What is a "verified brand" preview on a QR code?

Some codes made with taproute show a screen naming the brand and the destination hostname before continuing, and where the owner has proved control of that domain by a DNS record it carries a verified mark. It exists so a scanner can read the hostname before the redirect. It appears because the owner turned it on, so a code without one is not suspicious on that account.