Is it safe to scan a QR code

Last updated 16 September 2026

Scanning a QR code is roughly as risky as clicking a link in an email. The code itself is not dangerous. What it points to might be. Since a QR code hides the destination behind a square of black and white, you cannot see where you are going before you get there, and that is the whole problem.

What the risk actually looks like

A QR code contains text. Usually a URL. When you scan, the phone reads the text and offers to open it. There is no code execution, no app install, no virus in the image. The risk is entirely about where that text sends you.

So the real question is not "can a QR code harm my phone". It is "do I trust whoever made this code to send me somewhere safe".

The common tricks

How to check before you scan

Most phones now show the destination before opening it. Make a habit of reading that preview rather than tapping through it.

Physical tampering

Look at the code itself. A printed code that has a sticker over it, a torn corner, or that sits at an odd angle on an otherwise neat sign is worth a second look. Real signage has codes printed as part of the design. A sticker slapped on top is the signature of the attack.

This is especially relevant for parking meters, restaurant tables, and anywhere a payment is expected.

What this means for people making codes

If you are generating codes, a few habits help everyone:

The static versus dynamic question

A static QR code has the destination baked in. It cannot change, so what you scan today is what you get tomorrow. A dynamic code routes through a redirect service, which lets the owner change the destination later. That is useful for marketing, and it is also a trust question, because the destination can change to anything.

This is the distinction to hold on to when you are deciding whether to scan something. A static code is a fixed promise. A dynamic code is a promise that someone else still controls.

What this tool does

sobog.com makes both, and the difference is worth knowing before you scan one of ours in the wild.

So a sobog.com/r/ code follows the dynamic rules, not the static ones. The owner can change where it goes after it is printed, the destination lives on our server rather than in the image, and scans are logged. The privacy page spells out exactly what is kept.

We are telling you this because it is the honest answer, not because it is flattering. If we claimed all our codes were static and untraceable, that claim would be false the moment someone ticked the box.

What that means when you scan

A short link is a redirect, so the destination is not visible in the printed code. You are trusting the person who made it. That is true of every dynamic code, ours included.

The mitigations are the same ones from earlier on this page. Look at where the phone says it is going before you tap through. If a code is labelled, check that the label matches what opens. If a payment page appears and you did not expect to pay, stop.

The short version

Scanning a code is about as dangerous as clicking a link. If it came from a source you trust, in a place you expect, it is almost certainly fine. If it is a sticker on a payment terminal, a code with no context, or anything asking you to log in on a page you did not open yourself, slow down and check where it goes first.

Make a QR code


All guides