← Back to blog

September 2, 2026 · EverScans Team

Is This QR Code Safe? How to Check Before You Scan

A QR code doesn't show you a URL the way a link on a webpage does - you can't hover over it, you can't see the domain before you commit. That's normal, and most QR codes are exactly what they look like: a menu, a WiFi login, a business card. But it's also why a QR code is a convenient place to hide a phishing link ("quishing") - a sticker slapped over a real one on a parking meter, a fake "scan to pay" code, a poster QR that goes somewhere other than what it claims.

Check before you tap, not after

Most phone cameras already do this for you, if you look. On iOS and modern Android, pointing your camera at a QR code shows a preview banner with the actual destination URL before you tap anything - not a fake-looking overlay, the real address the code points to. That preview is the whole check: read it before you tap.

What to look for in that preview:

  • A domain you don't recognize, especially for something that claims to be from a bank, a delivery service, or a company you already have an account with. A real bank isn't going to route you through a random shortened link.
  • A shortened URL with no other context - bit.ly/xyz123 on a poster with no branding around it is a coin flip. A branded link (links.thecompany.com/...) at least tells you who made it.
  • Urgency language on the printed material itself - "Scan now, payment overdue" or "Scan to claim your prize" stickers are a common quishing pattern, especially on parking meters and public payment terminals.

If the preview shows something that doesn't match where you expect to land, don't tap through - close the camera and find another way to get there (search for the business directly, type the URL you actually expect).

If you already scanned and aren't sure

If your camera app already opened a link and you're looking at a short URL with no idea where it actually leads, don't click anything on the page it opened. Instead, paste the link into a URL-expander tool (several free ones exist) to see the real destination without visiting it, or just navigate away and search for what you were trying to reach directly.

This applies just as much to a QR code you never pointed a camera at - one sitting in a screenshot, an email, or a saved photo. See how to scan a QR code from a photo or screenshot for how to read the destination first, before deciding whether to visit it.

What EverScans does about this on its end

If you're the one creating QR codes - for a menu, a business card, a campaign - it matters just as much that the link you're pointing people at is actually safe, not just that it looks legitimate. Every destination you set on EverScans, whether you're creating a new QR code, editing an existing one, or shortening a URL, gets checked against Google Safe Browsing - the same threat database Chrome itself uses - before it's saved. That covers malware, phishing (social engineering), unwanted software, and other flagged applications. If a destination comes back flagged, creation is blocked with a clear reason instead of quietly letting a bad link go live under your brand.

One honest limitation worth knowing: this check runs at the moment you save a destination, not continuously. If a URL is clean when you set it and the site behind it is compromised later, that wouldn't be caught until the destination is next edited and re-checked. It's a real safeguard against publishing a QR code that points somewhere flagged today - not a guarantee against every possible future scenario.

Getting started

Every QR code type on EverScans - menu, vCard, WiFi, event, and the rest - gets this same destination check automatically. Sign up free and it's on by default, no configuration needed.

Ready to try it yourself?

Get started free