How to check a QR code before opening it
Short answer
Decode the image first and inspect the actual hostname before following a link. Utilumo’s QR Code Reader shows the contents locally and waits for your decision. It does not certify that a destination is safe.
Read first, open second
A QR code stores data. A reader can display those data without visiting a website. Reading the code, opening its link, entering a password and installing something are separate actions. A decoded result alone is not evidence that an account or device has been compromised.
- Use an image you already haveChoose a PNG, JPG, WebP, GIF or BMP screenshot, or paste an image into the workspace. Crop around one complete QR code and leave its blank border intact.
- Read the decoded contentCheck whether it is a website, Wi-Fi configuration, contact card or another type of data. Utilumo displays non-web payloads as text without launching an app.
- Compare the hostnameLook at the separate hostname field, not just a brand name somewhere in the full address. Read spelling, hyphens and subdomains carefully. For sensitive tasks, compare with an address you already trust.
- Decide independentlyOpen the inspected link only if it fits the task and source. You can instead use the service’s official app, a saved bookmark or a known address. Clear the workspace when finished.
What can go wrong with an unfamiliar QR code?
The FTC describes replacement stickers on parking meters and unexpected delivery or account messages. The code can lead to a fake payment or sign-in page that collects information you enter, or to a harmful download. Check the physical label and sender; pressure to act quickly is a reason to pause.
QR phishing is also called quishing. As the UK NCSC explains, hiding a link in an image can help a phishing email evade some checks and move the interaction to a personal phone. Treat an unsolicited request to scan and sign in as carefully as an unsolicited login link.
A familiar word is not the destination
https://bank.example@payments.example.net/login
Actual hostname: payments.example.net
https://payments.example.net/bank.example
Actual hostname: payments.example.netThe reader withholds its open action for URLs with embedded credentials or literal invisible/control characters. Internationalized domains are shown in their ASCII hostname form. These are details to inspect, not a blacklist or an automated judgment about who owns a site.
Limits and private content
This reader handles one QR code at a time. Unsupported text encodings produce an error instead of a partial link. A tiny, blurred or heavily skewed code may fail; try a closer screenshot. Treat decoded Wi-Fi passwords, contact details, ticket codes and login tokens as private. Do not share a screenshot of a result just because the original looked like a harmless pattern.