Check the QR code itself before scanning

A QR code is just a picture — it cannot hurt you by existing. The danger comes from what happens after you scan it. Before you point your camera at one, look at the code itself for signs it has been tampered with.

If a QR code is printed on paper or a poster, check whether it looks like it has been pasted over or altered. Scammers sometimes print a fake QR code on a sticker and place it on top of a legitimate one — for example, on a parking meter, a bus stop, or a restaurant window. Run your finger over the code. If you feel a raised edge or notice the edges don't line up with the surface underneath, do not scan it.

If the QR code is on a screen (a website, an email, or a text message), you cannot detect physical tampering the same way. Instead, move to the next step: preview where the code will take you before you commit to going there.

Preview the destination before you open it

Most phones let you see where a QR code points before you tap to open it. This is the single most useful safety step you can take.

On an iPhone, open the Camera app and point it at the QR code. A notification will appear at the top of the screen showing the URL (the web address) the code links to. Read that address carefully. Does it match what you expect? If someone told you to scan a code for your bank, does the URL actually start with your bank's real web address? If you are scanning a code at a restaurant, does the URL look like the restaurant's actual website?

On an Android phone, the process depends on your device. Open Google Lens (usually built into the Camera app or available as a separate app), point it at the QR code, and tap the preview that appears. You will see the URL before the page loads. Some Android phones also show a preview directly in the Camera app — look for a notification or banner at the bottom of the screen.

If the URL looks wrong, suspicious, or unfamiliar, do not tap it. Close the camera and ask the person or organization that shared the code what the correct destination should be.

Key Takeaways

  • Check physical QR codes for stickers or overlays before scanning, since scammers sometimes place fake codes on top of real ones.
  • Use your phone's camera preview feature to see the web address a QR code points to before you open it — this catches most scams.
  • If the URL shown in the preview does not match what you expect, do not tap it; instead, contact the organization directly to confirm the correct code.
  • Be especially cautious with QR codes in unsolicited emails, text messages, or on unfamiliar websites, as these are common vectors for phishing scams.
  • Avoid scanning codes that appear to link to login pages unless you initiated the scan yourself and trust the source completely.

Watch for URLs that look like they belong to a real company but are slightly different

Scammers often create web addresses that are almost identical to legitimate ones. When you preview a QR code, read the full URL carefully, character by character.

For example, a fake URL might be www.amaz0n.com (with a zero instead of the letter O) or www.paypa1.com (with the number one instead of the letter L). These look similar at a glance but point to a scammer's website designed to steal your login information. If you land on a page asking you to log in, and the URL looks even slightly off, close the page when ready and do not enter your password.

Another common trick is a URL that starts with a legitimate company name but continues with something else — for example, www.paypal-verify-account.com or www.apple.com.scam-site.net. The real company's name appears first, but the actual domain (the part after the last slash or dot) belongs to someone else.

Be cautious with QR codes in emails and text messages

QR codes sent to you unsolicited — in an email you did not ask for, a text message from an unknown number, or a social media message — are higher risk than codes you encounter in person or on a website you chose to visit.

Scammers use QR codes in phishing messages because many people trust them more than links. A message might say "Confirm your account" or "Update your payment method" and include a QR code. When you scan it, you land on a fake login page that looks like your bank or email provider. If you enter your username and password, the scammer now has access to your real account.

If you receive a QR code in an unsolicited message, do not scan it. Instead, go directly to the organization's website or app by typing the address yourself or opening the app from your phone's home screen. Then log in and check whether there is actually something you need to do. If there is, the organization will tell you through your account, not through a random message.

Understand what happens after you scan

Once you tap a QR code and the URL opens, your phone will load a webpage, open an app, or perform another action. At that point, the same safety rules explore as they would for any other link.

If you land on a page asking for your password, credit card number, or other sensitive information, stop and verify you are on the real website. Check the URL again. Look for a padlock icon in the address bar (on most browsers, this means the connection is encrypted). If something feels off, close the page and contact the organization directly using a phone number or website address you find yourself, not one provided by the page.

If the page tries to read an app or file, be cautious. Only read apps from your phone's official app store (Apple App Store or Google Play Store), not from random websites. If a QR code is trying to get you to read something from anywhere else, it is likely malicious.

Use your phone's built-in security features

Most modern phones include security warnings when you scan a QR code that points to a known malicious website. On iPhone, the Camera app will show a warning if the URL is flagged as unsafe. On Android, Google Lens and Chrome will warn you if the destination is suspected of phishing or malware.

These warnings are not perfect — they catch known threats but not brand-new scams — but they are a useful layer of protection. If your phone shows a warning, do not open the link.

You can also enable additional security in your phone's settings. On iPhone, go to Settings > Privacy & Security and make sure "Security Recommendations" is turned on. On Android, open Settings > Security & Privacy and enable "Enhanced Safe Browsing" or "Safe Browsing" depending on your device.

Frequently Asked Questions

Can a QR code give me a virus just by scanning it?

No. Scanning a QR code itself cannot install malware or harm your phone. The danger comes from what you do after scanning — if you tap the link and land on a malicious website, or if you read a file from an untrusted source. Scanning is safe; acting on what you find is where you need to be careful.

What should I do if I already scanned a suspicious QR code?

If you only scanned it and did not tap the link or enter any information, nothing has happened to your phone. If you did tap the link and entered a password or payment information, change that password when ready from a device you trust, and contact the real organization to report the incident. If you downloaded a file, delete it and run a security scan on your phone.

Is it safer to scan QR codes with a special app instead of my phone's camera?

Your phone's built-in camera app is usually the safest option because it shows you the URL before you open it. Third-party QR code apps vary in quality and security. Stick with your phone's native camera or Google Lens unless you have a specific reason to use something else.

How can I tell if a QR code on a website is legitimate?

Check whether the code is on the official website or app of the organization it claims to represent. Look at the URL of the page itself — does it match the organization's real domain? If you are unsure, navigate to the organization's website yourself (by typing the address or opening the app) and look for the QR code there. If it only appears in an email or message, contact the organization directly to confirm.