Check the preview first
Most phone camera apps show the link or domain before opening it, and that preview is the most important safety check. Read the whole domain, the part just before the first single slash, and ask whether it matches the business or place displaying the code. If the preview shows something unrelated or unexpected, do not open it.
- Read the full domain, not just the start of the link
- Look for lookalike spellings, extra words or unusual endings
- Be wary of unknown shortened links that hide the destination
- Check whether the code is a sticker placed over another code
- Do not install apps or profiles a scanned page asks for
Spotting lookalike domains
Scam sites often use domains that look right at a glance. Common tricks include swapped or doubled letters, a real brand name followed by extra words, a different top-level domain, or the real name placed in a subdomain such as citypark.example-payments.com. The part that matters is the registered domain directly before the ending, which here is example-payments.com, not citypark.
Rules for payments and logins
Never enter a password, one-time code or card number on a page reached from a QR code in an unsolicited email, text or letter. For parking, bills and deliveries, use the official app or type the organization’s web address yourself. A QR code safety checker can also decode the code and flag known risky or unusual links before you open them.