THIS WEEK Top 9 Free Instagram Apps to Enhance Your Influence Read this week's article →

Spot Fake QR Codes: Essential Tips for Secure URL Shortening

Published February 27, 2025 · GoTo.now Team

Spot Fake QR Codes: Essential Tips for Secure URL Shortening - Illustration

TL;DR - Scammers stick fake QR codes over real ones on parking meters, menus, and posters, then steal card details on look-alike websites. The fix is simple: check the preview URL before you tap, peel-test suspicious stickers, and verify short links with a free checker before opening them.

Key points

  • The most common trick is a fake sticker placed over a real QR code
  • Your phone shows the destination URL before opening it - Actually read it
  • Misspelled domains and odd endings like .top or .xyz are red flags
  • Paste any suspicious short link into a link checker to see where it leads
  • Businesses can protect customers by using branded, verifiable codes

QR codes are everywhere now - You scan them to pay for parking, read menus, and enter contests without thinking twice. Scammers noticed. "Quishing" (QR phishing) is now a real thing with real victims.

The good news: fake codes are easy to beat once you know what to look for. Here's the playbook.

How the scam actually works

A QR code is just a pattern - Your eyes can't read it, so you can't tell a good one from a bad one by looking at the squares. Scammers exploit that blindness in a few standard ways:

  • The sticker swap. They print their own QR code on a sticker and slap it over a legitimate one - On a parking meter, a restaurant table tent, a charging station, a poster.
  • The fake notice. They put codes on things that never had them: fake parking tickets on windshields, fake package-delivery slips on doors.
  • The look-alike site. The code opens a page that copies a real brand - Same logo, same colors - With a form asking for your card number or login.

Cities across the US and Europe have reported waves of the parking meter version. People scan, "pay," and the money goes straight to the scammer while their real parking goes unpaid.

Warning signs you can spot in five seconds

Before you scan anything in a public place, run this quick check:

Check What's suspicious
The surface A sticker sitting on top of another sticker or printed sign
The edges Bubbling, peeling corners, or a code that's crooked on the design
The context A QR code where one makes no sense (a random lamppost, a windshield flyer)
The pitch Urgency: "pay within 10 minutes," "your package will be returned"
The match Branding that doesn't match the business it claims to be

None of these alone proves a scam. But two together? Walk away, or find the official website yourself.

Read the URL before you tap - Every time

Here's the habit that beats almost every QR scam: when you scan a code, your phone shows the destination URL in a small banner before it opens anything. Most people tap without reading. Don't be most people.

Look for these red flags in that preview:

  • Misspelled brands - Paypa1.com, starbuks-menu.com
  • The brand in the wrong place - Paypal.secure-login.xyz is not PayPal; the real domain is whatever comes right before the final dot
  • Odd endings where you'd expect .com - .top, .xyz, .icu show up in scams a lot
  • http:// instead of https:// on any page asking for information

And if the preview shows a shortened URL you can't judge? Don't guess. Paste it into a free URL checker first - It shows you the real destination without visiting it. Ten seconds, zero risk.

One more rule: no legitimate QR code needs your password or card number "to continue." If a scanned page asks, close it and go to the official app or website directly.

If you run a business, you're part of this too

Fake QR codes hurt businesses twice: customers get burned, and then they stop trusting your codes. A few habits keep your codes credible:

  • Walk your locations. If codes are posted in your store or venue, check them regularly for sticker-swaps. Print codes directly on materials when you can - Stickers are what scammers imitate.
  • Use a branded link. A code that previews as your own custom domain is instantly recognizable, and it's something a scammer can't fake.
  • Keep codes updatable. Make your codes with the free QR generator on GoTo.now and they stay editable - If a linked page ever gets compromised or moves, you change the destination in your dashboard instead of recalling printed material. Scans are unlimited and the code never expires.
  • Tell customers what to expect. A small line like "This code opens ourcafe.com" gives people something to verify against.

Spotting fakes becomes second nature

You don't need to fear QR codes - You need a three-second routine. Glance at the surface for tampering. Read the preview URL before tapping. When in doubt, check the link before you open it or type the official address yourself.

That's it. Scammers rely on autopilot scanning, and the routine above switches autopilot off. Scan smart, and QR codes go back to being what they should be: the fastest safe way to get from the real world to the right webpage.

Step-by-step guides for this topic

Try it yourself: shorten your next link free on the GoTo.now homepage, or make a trackable QR code in your brand colors.