A QR code is just a link wearing a costume. You can't read a square of black-and-white pixels the way you can skim a web address, so the usual advice β "check the URL before you click" β feels impossible. It isn't. Your phone shows you the destination before it opens it, and the scams almost always give themselves away in the seconds before you tap. The threat even has a name now: quishing, QR-code phishing, and it's risen sharply enough that the FTC and FBI have each issued public warnings.
The one habit that matters most
Never let a QR code open a page automatically. Preview the link first, then decide. Both iPhone and Android show you where a code leads before you visit it β the danger is scanning on autopilot and tapping the banner without reading it.
Scan β read the URL banner β stop β does the domain match who I think I'm paying?
That two-second pause between the preview and the tap is where every check below happens. Nothing harmful comes from a scan by itself β the risk is the page it opens and what you type into it.
Six red flags in a QR code
A sticker sitting on top of a printed code
This is the whole parking-meter scam in one move. The machine has a genuine QR code printed or engraved on it; the scammer slaps a cheap sticker over it that points somewhere else. Run a fingernail along the edge β a printed code is flush, a fraudulent one has a lip you can feel. Peeling corners, a code on paper stuck to metal, or one that covers part of the meter's own instructions all mean walk away and pay another way. The BBB and the Identity Theft Resource Center have both tracked this exact pattern across US cities.
The code arrived unexpectedly
A QR code in an email you weren't waiting for, a text from a number you don't know, or β increasingly β printed on a card inside an unsolicited package you never ordered. The FBI issued a public alert in 2025 about "brushing" packages that include a QR code claiming to reveal who sent the gift; scanning it opens a credential or malware trap. If you didn't ask for it and can't explain why it's in front of you, treat the code as hostile.
The preview shows a shortener or a look-alike domain
When you hover your camera over the code, your phone shows the link before you open it. If that preview is a bit.ly / tinyurl-style shortener, you can't see the real destination β legitimate businesses rarely hide a payment page behind one. Worse is a domain that almost matches: parking-cityname.com instead of the city's real .gov site, or paypa1.com with a digit standing in for a letter. Read the two labels right before the first single slash; that's who actually owns the page.
It rushes you toward a payment or login
Scan-to-pay is convenient, and scammers know it. A code that drops you straight onto a page demanding your card number, bank login, or a one-time passcode β with a countdown, a "final notice," or a parking fine you don't remember β is using urgency to skip your judgment. Real payment flows let you slow down. If the page pressures you the instant it loads, that pressure is the scam, not a deadline.
The page asks for more than the task needs
Paying for two hours of parking doesn't require your Social Security number, your full date of birth, or your email password. A restaurant menu doesn't need you to "log in" at all. When the page behind a code asks for credentials that have nothing to do with what you're actually doing, that mismatch is the tell β you've landed on a harvesting form dressed up as a service.
The domain is brand new or unrelated to the brand
If you can reach the destination safely on a computer, a WHOIS lookup on the domain settles a lot. A "city parking" or "package tracking" site registered days ago, or one that has no connection to the operator whose logo it's wearing, is almost always fraud. Established services own their domains for years. A freshly minted domain impersonating a familiar name is one of the strongest single signals there is.
How to preview the link on your phone
You don't need a special app. The scanner built into your phone already shows the destination before it opens β you just have to look at it instead of past it.
- iPhone (Camera app). Open the Camera and hold it over the code β don't press anything. A yellow banner slides in at the bottom showing the domain it will open. Read that domain before you tap the banner. If it isn't the business or operator you expect, don't tap.
- Android (Google Lens / built-in scanner). Point the camera or open Lens; once it registers the code it shows a preview of the URL with a tap-to-open prompt. Same rule β read the link in the preview first, and back out if the domain looks off.
- When the link is a shortener. If the preview is a shortened link that hides the real destination, don't trust it for anything involving money or a login. Expand it with a free "unshorten" or reputation scanner on a computer, or skip the code entirely and reach the service directly.
The safest move of all needs no scanning: when you can, ignore the printed code and reach the service yourself. Type the parking operator's address, open the store's official app, or search for the business and use its real result. Scammers count on you taking their shortcut β take your own path in.
If you already scanned one
A scan on its own doesn't hand anything over β the harm starts only if you entered information or installed something. So work backwards from what you did:
- Entered a password or one-time code? Change that password everywhere you used it and turn on two-factor authentication. Assume the login is compromised until you've reset it.
- Typed in card or bank details? Contact your bank, watch statements for charges you don't recognize, and consider a freeze. In the US, report identity theft at IdentityTheft.gov.
- Installed an app or profile it prompted for? Delete it, run a security scan, and remove any configuration profile you didn't add yourself.
Why a QR code is worth the extra second
Phishing has gotten good at almost everything β cloned pages, believable logos, valid security certificates. The one thing an attacker still can't fake is where the link actually points, and a QR code doesn't change that; it just hides it for a moment longer. CISA's guidance on social engineering comes down to the same instinct that catches a bad link: slow down, don't trust the urgency, and verify the destination yourself before you hand over anything. The pixels are new. The lie underneath them is the same one, and it's caught the same way.
Not sure a link or claim is real?
FAXTR searches 100+ fact-checking organizations in one query β free, no login required. Check a viral claim or a suspicious offer before you trust it.