Why check QR codes first, then open them?
A QR code is not human-readable: you see a pattern, not the destination. That's exactly what attackers exploit: in so-called quishing (phishing via QR code), manipulated stickers are pasted over genuine codes, for example on parking ticket machines, restaurant tables or parcel labels. The scan then leads to a deceptively realistic fake page that harvests login or payment details.
Because many smartphones' camera apps show the destination only briefly and truncated, the decisive tap often happens before anyone has really read the domain. A reader that shows the content as text first interrupts this reflex, and you consciously decide whether to open the destination.
What to look for in the verified link
Look closely at the domain immediately before the first slash; attackers work with typos and appended additions that are easy to miss when reading quickly. You should also be sceptical of redirects via URL shorteners, where the actual destination stays hidden, and of codes that arrive unsolicited by post or email demanding immediate payment.
Conversely: if you use QR codes yourself, always link to your own domain rather than a third-party shortener. That builds trust and makes manipulation easier to spot. You can create your own codes right away with our QR code generator.