How to use and share QR codes safely
Inspect destinations, recognize replacement stickers and phishing messages, and create QR codes people can verify before opening.
Tervix · practical guide
Treat a QR code like a shortened or hidden link: preview the destination, verify the sender through an independent channel and slow down when the message creates urgency.
A QR code is a compact way to carry data, commonly a web address. The pattern itself does not prove who created it or whether its destination is trustworthy. Safety depends on the context, the decoded address and what the destination asks you to do.
1. Preview the destination before opening
Most phone cameras show the decoded domain before navigation. Read it carefully for misspellings, substituted characters, unexpected subdomains or a URL shortener that hides the final destination. HTTPS encrypts a connection but does not prove that the site belongs to the organization it imitates.
If the code supposedly belongs to a bank, government office, delivery company or payment service, open the known app or type the official address yourself. Do not rely on contact details printed beside a suspicious code.
2. Inspect the physical and message context
The FTC warns that scammers may cover legitimate codes on parking meters or send codes in unexpected messages. Look for a sticker placed over another label, damaged printing, inconsistent branding or a code positioned where anyone could replace it.
Unexpected email, text or packages that demand immediate scanning deserve extra caution. Claims about account suspension, unpaid fines, failed deliveries or urgent password changes are common ways to suppress careful checking.
3. Stop when the destination asks for sensitive action
Do not enter a password, payment card, identity number or recovery code merely because a scanned page looks familiar. Check the domain again and compare the request with the service's normal process.
Do not install an application or configuration profile from an unverified QR destination. Keep the phone operating system and browser updated, use unique passwords and enable multifactor authentication on important accounts.
4. Create QR codes that people can verify
When publishing your own code, print the human-readable destination beside it. Use a domain your audience recognizes, explain the purpose and avoid unnecessary redirect chains. Test the code at its final physical size, distance and lighting.
For long-lived signs, use a controlled redirect only when you can maintain it securely. Monitor the physical label for replacement and preserve enough contrast and quiet space around the code. Never frame scanning as proof of identity or safety.
Trustworthy label
- View the event schedule
- example.org/schedule
- You can type the address instead of scanning
5. Respond after a suspicious scan
If you only opened a page, close it and avoid downloads or permissions. If you entered a reused password, change it immediately on the legitimate service and anywhere else it was used, then enable multifactor authentication.
Contact the payment provider promptly after sharing financial data. Remove an installed unknown app or profile, update the device and follow local identity-theft or fraud reporting guidance when personal information was exposed.
Final checklist
- ✓Preview the domain.
- ✓Inspect stickers and context.
- ✓Use an independent official channel.
- ✓Reject urgent credential or payment requests.
- ✓Keep devices updated.
- ✓Print a readable destination beside codes you publish.
- ✓Act quickly after disclosing information.
Open the Tervix QR code generator
Create a QR code locally, set error correction and download it without sending its content to Tervix.
Open toolSources and review
Reviewed July 29, 2026 using current FTC consumer security guidance. A QR code is a data carrier; risk comes from its content, context and requested action.