QR Codes and Malicious URLs
The biggest QR risk isn't the code — it's the link inside. How to inspect a QR's URL before you trust it.
With QR codes, the link is the risk. A code is just a way to carry a web address, so the entire question of safety comes down to inspecting that address before you open it — spotting look-alike domains, hidden shorteners, and sneaky redirects. Here's how to read a link like a pro. 🐾
Every safe-scanning habit ultimately rests on one skill: judging a URL. When you can glance at a web address and sense whether it belongs to who it claims to, malicious QR codes lose almost all their power. The code was never the threat; it's a wrapper around a link, and the link is what you need to read. Let's build that skill in plain language.
Why the URL is the whole story
A QR code that holds a website address does nothing except hand that address to your phone and offer to open it. It can't disguise the destination once it's decoded — the true link is right there to be read. That's a gift, because it means you always have a chance to catch a bad code: preview the link, read the domain, and decide. The catch is that criminals work hard to make dangerous links look trustworthy. For the bigger context, see can a QR code hack your phone?
How do I read a URL correctly?
The single most important part of any web address is the domain — and specifically the part right before the first single slash. Consider:
https://accounts.google.com.verify-login.xyz/reset
At a glance this looks like it involves Google. But read carefully: the real domain is verify-login.xyz. Everything before it (accounts.google.com.) is just a subdomain the attacker chose to fool you. The rule: find the last two labels before the first slash — that's the true domain. Everything to the left of it can be faked freely.
What tricks make malicious links look legitimate?
Look-alike domains
Attackers register domains that resemble a real brand:
- Character swaps —
paypa1.com(a "1" for an "l"),rnicrosoft.com("rn" for "m"). - Added words —
apple-support-verify.com,amazon-secure-login.net. - Wrong endings — the real brand but a
.top,.xyz, or unexpected country ending instead of the genuine one. - Homoglyphs — letters from other alphabets that look identical to Latin ones.
URL shorteners
A shortened link (like bit.ly/abc123) hides the true destination entirely. Shorteners have legitimate uses, but in a QR code they're a warning sign, because they strip away your ability to read the domain. If a scanned code resolves to a bare shortener, treat it with caution until you can see where it really goes. This overlaps with how dynamic QR codes route every scan through a redirect you can't see inside.
Redirect chains
Some links pass you through several hops before landing on the final page. A tracking or redirect service can point somewhere harmless today and somewhere hostile tomorrow, all behind the same printed code. This silent-change ability is part of why unexpected redirects deserve scrutiny; we touch on the mechanics in QR code redirects and tracking.
A quick reference for judging a scanned link
| What you see | Verdict |
|---|---|
| The exact, familiar domain of the brand | Reassuring |
| Brand name buried in a subdomain of another site | Suspicious — read the true domain |
| Slight misspelling or extra hyphenated words | Likely a look-alike |
| A bare URL shortener | Unknown destination — be cautious |
| Unusual or mismatched domain ending | Verify before trusting |
| The link wants to download a file | High caution — never install from a random code |
How do I inspect a link before I tap it?
The practical workflow is short:
- Preview, don't open. Most phone cameras show the decoded address before loading it. A scanner that lets you scan a code safely puts the real destination in front of you first, so you can read it calmly.
- Find the true domain. Locate the part just before the first single slash and check it against the organization you expect.
- Distrust shorteners and odd endings. If you can't see the real destination, don't assume it's safe.
- Never enter secrets on a link you're unsure of. Passwords and payment details should only go into sites you navigated to yourself.
What if I can't tell whether a link is safe?
When in doubt, don't route through the code at all. Open the official app or type the address you already know into your browser. For a bank, a parcel service, or your employer, going direct is always safer than trusting a link handed to you by a code — especially an unexpected one. This is the same principle behind avoiding QR codes in phishing emails and fake parking meter codes.
You never lose anything by reaching a site the way you already know how. The code is a shortcut, and shortcuts are exactly where traps get placed.
Building the habit
Reading URLs feels fiddly at first and becomes automatic fast. After a week of glancing at the domain before you open anything, you'll spot a look-alike in a fraction of a second — the same way you'd notice a misspelled sign. Pair this with our full QR code safety checklist and you've covered the vast majority of QR risks. And when you create codes yourself, you can create a free QR code that encodes your real link directly, so the people scanning it can read exactly where it goes.
Frequently asked questions
How do I find the real domain in a web address?
Look at the part immediately before the first single slash, then take the last two labels of that section. In login.example.com the real domain is example.com. Anything to the left, like extra brand names, can be faked, so read from the right.
Are URL shorteners in QR codes always bad?
Not always — they have legitimate uses — but they hide the true destination, which removes your ability to judge it. In a QR code, especially an unexpected one, a bare shortener is a reason to be cautious until you can confirm where it actually leads.
What is a look-alike domain?
It's a web address crafted to resemble a trusted brand, using character swaps, extra words, or unusual endings — like paypa1.com or apple-verify-login.net. The goal is to make a phishing page's address pass a quick glance.
Can a QR code's link change after it's printed?
If the code contains a redirect or shortener rather than a direct link, then yes — whoever controls that redirect can change the final destination silently. A static code with the real link baked in cannot change, which is one reason to prefer them.
What's the safest thing to do with a suspicious link?
Don't open it. If you need to reach the service, use its official app or type the website you already know into your browser. Never enter passwords or payment details on a page you reached from a scanned link you couldn't verify.
Make a QR code the honest way 🐾
Free forever, no tracking, no expiry — generated right in your browser.