Understand the request before the link
Ask what you are expected to do: read a programme, pay, sign in or authorise a device. The NCSC describes pressure and impersonation as ways to provoke rapid action. A polished message can still be deceptive. Pause when a sender claims an unusual emergency, especially if the proposed action differs from your normal relationship with them.
Read the destination, not just the label
A link’s visible label is not necessarily its address. Where the interface offers a destination preview, examine it before continuing; a shortened link may hide the final destination. A brand in the address path is not enough to identify the site’s operator. A padlock indicates an encrypted connection, not validation of the organisation. Do not open a suspicious destination merely to investigate it.
Treat a QR code as an invitation
A QR code makes opening an address easier but does not validate its author. The NCSC notes its use in phishing messages and recommends the phone’s built-in scanner rather than downloading an app solely for scanning. Review the proposed destination where your device allows it. A payment or sign-in request following a scan needs the same scrutiny as one delivered in a message.
Return through a known route
When unsure, open your usual app or find the official website independently of the message. Contact the organisation through official details, as the NCSC recommends. Do not use the number supplied in the suspicious message to validate it. If you have already shared credentials, follow the account recovery and security journey; closing the tab does not retract information you sent.
A fictional case to apply the process
Fictional example: a member receives a QR code claiming their association account will be suspended. They avoid the proposed sign-in and open the service through the usual app. They look for the alert inside the account and contact support through that independent route.
Template to adapt
Copy this outline into your working document without passwords or unnecessary personal data.
Received message, without sensitive details: Requested action: Visible destination: Reason for concern: Independent official route: Confirmation obtained: Information already shared, if any: Next action:
Your check before use
0 / 4
Useful questions
Is a QR code always dangerous?
No. Examine its context and the request that follows. It does not prove identity or guarantee a trustworthy destination.
Can a tool check a private link?
Avoid submitting links containing personal access, tokens or private documents to a third-party service. Find the service through its official route instead.
Related steps
Sources and scope
Sources consulted on 10 October 2026 for the points specified below. The method, template and example are editorial proposals; they are not service tests.
- NCSC — Spot scams — Pressure and impersonation in messages; verification through an independent official contact.
- NCSC — QR Codes: what is the real risk? — QR codes used in phishing messages and the benefit of the phone’s built-in scanner.
- Mozilla — Connection security — The security indicator concerns encryption of the connection to the displayed website.