What is tap2u.link?
tap2u.link is the address that QR codes and short links made with taproute point at. We operate it. If you scanned a code or were sent a link and arrived at a domain you have never heard of, this page is the answer to the question you have · including what to do if the link was not something you expected.
The short answer
taproute is a QR and short-link service. When someone makes a code with it, the code encodes
an address on our domain · tap2u.link/ followed by a short identifier · and every
scan is a request to us asking where that code currently points. We forward the phone to the
destination its owner set.
So the domain in front of you is ours, and the destination behind it belongs to whoever made the code. That distinction is the whole of it, and it is the reason the rest of this page exists: knowing who runs the middle does not tell you who wrote the end.
Why a printed code points at a domain you do not recognise
A QR code is ink. Once it is on a menu, a label or ten thousand flyers, the pattern cannot be edited. If that pattern spelled out the destination directly, the code would be frozen at the moment it went to print, and every change of address would mean a reprint.
Pointing it at a short address instead moves the destination off the paper and into a record its owner can edit. That is what a dynamic code is, and it is why nearly every printed code you scan sends you through a domain that is not the one you end up on. The trade is deliberate: the owner keeps control of the printed object, and you get one more party in the path.
Is it safe to open?
What actually happens behind the address:
- Destinations are screened. Every destination is checked against Google Web Risk for malware, phishing and unwanted software when a link is created, again whenever its owner repoints it, and again in a nightly sweep over links already live. A match is refused at creation, and a link already published that starts matching is disabled.
- A disabled link stops forwarding. It does not quietly keep working. It serves a notice saying the link was disabled, on every printed copy at once.
- Nothing is inserted in the path. A scan is a redirect at the network edge. We do not put advertising or interstitial pages between a scan and its destination, and we do not sell that space · that promise is published as our pledge.
And the honest limit, because a page like this is worth nothing without one: screening tells you a destination is not on a blocklist, which is not the same as telling you a link is meant for you. A short link is indirection by design, blocklists lag new phishing sites by hours or days, and if our check cannot reach Web Risk at that moment the link is allowed through rather than blocked. No shortener · ours included · can vouch for a message you were not expecting. Judge the link the way you would judge any other unexpected link, and use the section below if it looks wrong.
Seeing where a link goes first
Some codes show a preview screen that names the destination hostname and waits for you to continue. That screen appears because the code's owner turned it on, so its absence is not a signal of anything; most codes do not have it. Where the owner has additionally proved control of the destination domain by DNS record, that preview also carries a verified mark.
We do not publish a lookup that resolves any tap2u.link address on request. That would turn the domain into a browsable directory of our customers' links, which is a worse outcome than the problem it solves. If what you have is the printed code rather than the link, our free QR decoder reads the exact address out of the pattern without visiting it.
If you got one you did not expect
Report it. Phishing, malware, fraud, impersonation, a link copying your brand: the report form takes the address and reaches a person. Links that break our acceptable use policy are disabled, and because the destination lives on our side rather than on the paper, disabling one takes effect on every copy of that code already in circulation.
If you are checking on behalf of an organisation and need something to point a colleague at,
this page is a stable URL for that purpose. Security contact details for the redirect hosts
are published at tap2u.link/.well-known/security.txt in the usual place.
tap01.link, and codes on other domains
tap01.link is our second link domain and it does one job: resolving GS1 Digital
Links, the identifiers printed on product packaging · a GTIN, a batch code, a serial number ·
into whatever the brand that owns them publishes. It is a separate domain from tap2u.link on
purpose, because a shortener and a resolver printed on packaging for the life of a product
should not share a reputation. It serves nothing else. More about GS1 Digital Links.
You may also meet a taproute code on a domain belonging to the business that made it, rather than on either of ours · owners can connect their own domain, in which case the address you see is theirs and the machinery behind it is still this.
If you are the one printing codes
Everything above is the reason to care which service is in the middle of your own printed codes, because whoever it is inherits that position for as long as the print exists. Ours charges per code and per scan rather than by subscription, shows nothing between a scan and your page, and lets you point the codes at your own domain so that the address on the paper is yours rather than ours. If a code of yours is already printed and pointing at the wrong place, the rescue check says in one screen whether it can be repointed.
Questions
What is tap2u.link?
It is the redirect address for QR codes and short links made with taproute. A code printed on a menu, a poster or a package encodes a tap2u.link address, and scanning it asks that address where to go next. taproute operates the domain; the destination belongs to whoever made the code.
Is tap2u.link safe?
The domain is not a scam domain, and destinations are checked against Google Web Risk when a link is created, whenever its owner repoints it, and again in a nightly sweep. But a short link is indirection by design, and no shortener can vouch for a link you were not expecting. Treat an unexpected tap2u.link the way you would treat any unexpected link, and report it to us if it is being used against you.
Why does a QR code point at tap2u.link instead of the real website?
Because that indirection is what lets the code be repointed after it is printed. The pattern on the paper never changes; the address it asks is a record its owner can edit. A code that encoded the destination directly would be frozen at the moment it went to print.
How can I see where a tap2u.link goes before I open it?
Some codes show a preview screen naming the destination hostname before continuing, because their owner turned it on. Most do not, and we do not publish a lookup that resolves any address on request · that would turn the domain into a directory of our customers’ links. If you have the printed code rather than the link, our free decoder reads the address out of the pattern without visiting it.
I got a tap2u.link I did not expect. What should I do?
Do not open it, and report it. Every report reaches a person, and a link that breaks our acceptable use policy is disabled · after which the address stops forwarding and serves a notice instead, on every copy of the code already printed.
What is tap01.link?
A second domain of ours that resolves GS1 Digital Links: identifiers printed on product packaging, such as a GTIN, a batch or a serial number. It is deliberately separate from tap2u.link and serves nothing but that resolver.