Skip to main content
QRSenBuilt for business
Core Concepts

How to Check Where a QR Code Leads Before Scanning

Point your phone's camera at the code without tapping anything, and the camera app will show a preview of the destination link before you open it. Read that preview carefully, check that the domain looks legitimate and matches where you'd expect it to lead, and only tap through if it does.

Modern iOS and Android camera apps recognize a QR pattern automatically and display a small banner or popup showing the decoded URL, no separate app needed. This happens the moment the camera focuses on the code, before anything opens, which means most people already have a built-in safety check they simply aren't using.

In that preview, the actual domain name is what matters, not the path or query string after it. A link that reads something like yourbank-secure-login.something-unfamiliar.com is a red flag even if the word 'bank' appears in it, while a link that goes straight to a domain you recognize and expect is generally fine. Shortened links are harder to evaluate from the preview alone since the real destination is hidden behind the redirect, which is worth extra caution.

Context matters as much as the link itself. A QR code stuck as a standalone sticker on a parking meter, included in unsolicited mail, or printed on a random flyer deserves more scrutiny than one printed directly into a restaurant's own menu or a product's original packaging, since a sticker can be placed over a legitimate code by anyone. If a code looks physically added after the fact, peeling at the edges or sitting slightly crooked on top of a printed surface, treat that as a signal to check the link extra carefully or skip it entirely.

Checking the destination before tapping through handles most of the risk, but the same caution that applies to any link online still applies once you're on the page. Don't enter login credentials or payment details on a page you didn't expect, and don't act on urgent pressure to 'verify your account immediately' just because a QR code is what got you there.

A separate QR reader tool that decodes and displays the raw content without automatically opening it is a useful extra layer of caution for anyone scanning codes from unfamiliar public sources regularly — a parking app, a public bulletin board — since it puts the full decoded text in front of you with zero risk of an accidental tap-through, giving more time to evaluate the destination than a fast-moving camera preview banner sometimes allows.

Frequently asked questions

Older phones or third-party scanner apps sometimes open the link directly without a preview step, in which case it's worth switching to your phone's built-in camera app, which includes the preview feature on nearly all modern iOS and Android devices. If you're unsure, you can also use a separate QR reading tool that decodes the content without opening it automatically.
Scanning itself is safe, it just reads the pattern and shows you the link preview, the risk only starts if you tap through to an unfamiliar or suspicious destination and then act on what's there. Treat an unfamiliar QR code the same way you'd treat an unfamiliar link in an email or text message.
No, decoding a QR code just reveals the encoded text or link, it doesn't execute or install anything on its own. The actual risk only appears if you choose to open the link and then take an action on the destination page, like entering credentials or downloading a file.