Safety
Are QR codes safe to scan?
A code is an envelope, not a verdict. Ten seconds of checking beats ten minutes of account recovery.
Make your own codes instead
Codes you generate yourself carry payloads you reviewed. No redirect, no tracking, no surprises.
Open the generatorThe ten-second check
Read the preview, then decide. Phone cameras show where a code wants to go before opening anything: a domain, an action, a join request. If the preview does not match the claimed sender, stop. A bank never needs you to log in through a sticker on a lamppost.
- Inspect the domain. Misspellings, odd subdomains, and URL shorteners hiding the destination are the classic tells.
- Do not log in on the spot. A scanned link that demands credentials immediately deserves a typed address instead.
- Treat payments as guilty until proven innocent. A code asking for money, gift cards, or crypto is almost never legitimate street furniture.
The exposure runs both ways
Scanning is only half the story. Printing a code publishes its payload to every camera in the room, so a Wi-Fi code on the wall is a password on the wall. Print guest networks, rotate them, and never post code photos online. The same physics protects codes you make: what you encode is exactly what scanners get, with nothing added.
Keep reading
Related QR guides
Questions and answers