How to check a QR code before you open it

A QR code is just a link you can’t read. Scammers stick fake ones on parking machines and signs, and put them in emails, texts and parcels. Here’s how to see where a code goes before you open it.

Updated 6 October 2026 · 3 min read

Check one now

Scan it with LinkGuard

Tap Scan with camera and point it at the code, or pick a photo or screenshot of one. LinkGuard shows where the link really goes, with a clear answer such as Safe, Check first or Scam.

The code is read on your device, and only the web address in it is checked. Codes that aren’t web addresses, like Wi-Fi logins or payment details, stay on your device.

Got a QR code?

Check it before you open it. The code is read in your browser, and only a web address in it is sent for checking.

Only the web addresses in your message are sent for checking. Our server never reads or keeps the rest of it.

Before you open one

Four quick checks

  1. 01

    Look at the code itself

    On a parking machine, sign or poster, a sticker on top of the printed design is a warning sign: scammers cover real codes with their own. If the code looks stuck on, don’t scan it.

  2. 02

    Read the address before you open it

    Your phone’s camera shows where a code points before it opens anything. Find the site name, the part before the first single “/”, and read it from the right: council.gov.uk.park-pay-now.example is really park-pay-now.example. If it isn’t the company you expect, don’t open it.

    https://council.gov.uk.park-pay-now.example/pay

    This code goes to park-pay-now.example, not the council.
  3. 03

    Stop at payment and sign-in pages

    A code that leads to a payment or sign-in page needs extra care. For parking, parcels or your bank, use the official app or a website you already know instead.

  4. 04

    Don’t trust codes you weren’t expecting

    Treat a QR code in a surprise email, text, letter or parcel like any unexpected link, especially one that rushes you: “scan to rebook your delivery”, “scan to see who sent this gift”.

Paying for parking?

Councils across the UK, and New York City, have warned about fake QR code stickers on parking machines and signs that lead to fake payment pages. Some councils, including Dorset, East Lothian and Kensington and Chelsea, say they don’t use QR codes for parking payments at all, and New York City says its meters take payment only in the ParkNYC app or at the meter. Pay in the official parking app or at the machine.

Let LinkGuard do it

Check QR codes and links before you open them.

Already scanned one?

What to do next

  1. 1

    If you only opened the page, close it and don’t type anything into it.

  2. 2

    If you paid or typed card details, call your bank now on the number on the back of your card. In the UK, you can also dial 159 to reach your bank safely.

  3. 3

    If you typed a password, change it on the real website or app, and anywhere else you use it.

  4. 4

    Tell whoever runs the car park, sign or poster, so they can remove the fake code.

Full guide: what to do after a scam link

FAQ

Common questions

Can scanning a QR code hack my phone?

Scanning with your phone’s camera only reads the code: it shows you where the code points and waits for you to tap. The risk starts when you open the link. The page may try to get you to type details, pay or install something, and, rarely, a page can attack a phone that isn’t up to date. So check where it goes first.

Are QR codes on parking machines safe?

Not always. Councils across the UK, and New York City, have warned about fake QR stickers on parking machines and signs. Some councils say they don’t use QR codes for parking payments at all, so a code there is a red flag. Use the official parking app or pay at the machine.

What is quishing?

Quishing is phishing with a QR code. Instead of a link you can read, a scam message or sticker gives you a code that leads to a fake sign-in or payment page.

How do I check a QR code without opening it?

Scan it with LinkGuard on this page or on the phone page. It reads the code on your device, follows the link on LinkGuard’s server and tells you where it really goes, with an answer such as Safe, Check first or Scam, before your browser goes anywhere.