Before opening a destination
Review the domain shown by the camera. Avoid misspelled, unrelated or Unicode-lookalike domains and never enter sensitive data on suspicious pages.
For QR platform operators
Allow only necessary schemes, block local-network targets and known malicious hosts, rate-limit creation and maintain a fast abuse process.
Dynamic account security
Use a unique strong password, enable MFA when available, grant least privilege and review destination changes in audit logs.
Physical security
Public stickers can be covered by fraudulent ones. Inspect placements, print the expected brand domain and tell users what destination to expect.
Frequently Asked Questions
Can a QR contain a virus?
It is not an executable file, but it can lead to a malicious page or download.
How do I report a suspicious code?
Use the abuse form and include the QR ID, URL and observed behavior.
Is a short link automatically safe?
No. Safety depends on the redirect provider and final destination.