Link and QR safety

Suspicious links and QR codes: check before opening

A link or QR code is only a route to a destination. The visible text, button or printed sticker does not prove where it leads, and several redirects can hide the final site.

Read the domain carefully

The important part is the registered domain immediately before the first single slash. Extra words before it may be subdomains, and extra words after it are only a path. Scammers use spelling changes, added hyphens and unfamiliar endings to imitate trusted services.

  • Misspelled brand or institution
  • Raw IP address instead of a normal domain
  • HTTP rather than HTTPS
  • Very long or encoded destination

QR codes need the same caution

A QR code can cover the destination until it is scanned. Stickers can also be placed over legitimate codes on parking machines, menus or public signs. Preview the destination and cancel if it is unexpected.

  • Payment page from a public sticker
  • Immediate request to install an app
  • Login page on an unrelated domain
  • Request for BankID or card details

Use an independent route

If the link claims to be from a bank, authority, delivery company or workplace, open the known official app or type the address yourself. Do not open an unknown destination merely to investigate it.