Practical guide
A QR Code Does Not Prove an Account Request Is Genuine
Treat a scanned account-warning code with the same care as an unfamiliar sign-in link.
The square does not establish trust
A QR code can make an account action feel official because it looks like something a service would generate. But the code itself does not prove who placed it in a message or on a page. The FTC warns that scammers use QR codes to direct people to spoofed sites. Think of the code as a way to carry a destination, not as a security seal. Before scanning, ask why this particular action requires you to move to a new destination.
Notice when the task changes devices
An email on your laptop might tell you to scan a code with your phone to confirm your account. That switch can make it harder to compare the original message with the new sign-in screen. Pause before the handoff. If you were not already completing a verified account action, open the service independently on your own device and investigate there. Do not let the extra step make an unexplained request feel more trustworthy simply because two devices are now involved.
Check the context of a physical code
A code printed on a card or shown on a poster deserves the same question: who controls this destination, and does it match the action I want? For example, a community event handout might include several links, but an unexpected account-recovery request is still a different task. If the code's purpose is unclear, ask the organizer through a known contact route. You can decline to scan it without needing to prove that the material has been tampered with.
Keep scanning separate from entering secrets
If you do open a destination, do not treat the act of scanning as permission to enter credentials, codes, or personal documents. Review the new page as a new request. The FTC recommends inspecting a QR destination and avoiding unexpected codes that create urgency. Your own practical stopping rule can be even simpler: an unsolicited code does not decide where you sign in. Follow up through the service you intended to use, and record any suspicious message without circulating its live link unnecessarily.
Sources checked
Linked reference pages checked on 2026-09-09. Product details can change. No paid-membership test or sponsorship is implied.
FTC: harmful links hidden in QR codes ↗