Tervix
en

Appearance

Local profile

No name

Only in this browser

Manage profile
Open navigation menu
Digital security

How to use and share QR codes safely

Inspect destinations, recognize replacement stickers and phishing messages, and create QR codes people can verify before opening.

By the Tervix Editorial Team9 min read

Tervix · practical guide

Treat a QR code like a shortened or hidden link: preview the destination, verify the sender through an independent channel and slow down when the message creates urgency.

A QR code is a compact way to carry data, commonly a web address. The pattern itself does not prove who created it or whether its destination is trustworthy. Safety depends on the context, the decoded address and what the destination asks you to do.

1. Preview the destination before opening

Most phone cameras show the decoded domain before navigation. Read it carefully for misspellings, substituted characters, unexpected subdomains or a URL shortener that hides the final destination. HTTPS encrypts a connection but does not prove that the site belongs to the organization it imitates.

If the code supposedly belongs to a bank, government office, delivery company or payment service, open the known app or type the official address yourself. Do not rely on contact details printed beside a suspicious code.

2. Inspect the physical and message context

The FTC warns that scammers may cover legitimate codes on parking meters or send codes in unexpected messages. Look for a sticker placed over another label, damaged printing, inconsistent branding or a code positioned where anyone could replace it.

Unexpected email, text or packages that demand immediate scanning deserve extra caution. Claims about account suspension, unpaid fines, failed deliveries or urgent password changes are common ways to suppress careful checking.

3. Stop when the destination asks for sensitive action

Do not enter a password, payment card, identity number or recovery code merely because a scanned page looks familiar. Check the domain again and compare the request with the service's normal process.

Do not install an application or configuration profile from an unverified QR destination. Keep the phone operating system and browser updated, use unique passwords and enable multifactor authentication on important accounts.

4. Create QR codes that people can verify

When publishing your own code, print the human-readable destination beside it. Use a domain your audience recognizes, explain the purpose and avoid unnecessary redirect chains. Test the code at its final physical size, distance and lighting.

For long-lived signs, use a controlled redirect only when you can maintain it securely. Monitor the physical label for replacement and preserve enough contrast and quiet space around the code. Never frame scanning as proof of identity or safety.

Trustworthy label

  • View the event schedule
  • example.org/schedule
  • You can type the address instead of scanning

5. Respond after a suspicious scan

If you only opened a page, close it and avoid downloads or permissions. If you entered a reused password, change it immediately on the legitimate service and anywhere else it was used, then enable multifactor authentication.

Contact the payment provider promptly after sharing financial data. Remove an installed unknown app or profile, update the device and follow local identity-theft or fraud reporting guidance when personal information was exposed.

Final checklist

  • Preview the domain.
  • Inspect stickers and context.
  • Use an independent official channel.
  • Reject urgent credential or payment requests.
  • Keep devices updated.
  • Print a readable destination beside codes you publish.
  • Act quickly after disclosing information.

Open the Tervix QR code generator

Create a QR code locally, set error correction and download it without sending its content to Tervix.

Open tool

Sources and review

Reviewed July 29, 2026 using current FTC consumer security guidance. A QR code is a data carrier; risk comes from its content, context and requested action.

Responsible application

Example, uses and limits of this guide

Applied example

Scenario
A parking-meter sticker opens a lookalike domain instead of the municipality site.
Result
Close it and reach the service through its known app or a typed official address.
How to interpret it
A QR image does not authenticate its creator; an independent route breaks the attacker’s redirect.

Use cases

  • Check codes before paying.
  • Evaluate codes received in messages.
  • Publish codes with readable destinations.

Limitations

  • !HTTPS does not prove ownership.
  • !A destination can change later.
  • !Short URLs hide useful context.