What a QR code contains and how to inspect it before opening
A QR code is not a trust badge: it simply encodes information in an image. It may contain a website, Wi-Fi details, a contact or a message. The useful habit is not to distrust every code, but to check what it is asking us to do.
1. A QR code does not always lead to a website
When a camera reads a QR code, it obtains encoded content. Some readers suggest opening a website; others offer to connect to Wi-Fi, add a contact, prepare a message or create a calendar event. Decoding does not require performing that action. A cautious reader shows the content first and lets you decide.
2. First example: a misleading-looking domain
In this fictional URL, 'cuenta.example' appears before the at-sign, but it is not the destination domain. The actual server name is 'oferta.example'. Both names are used only as examples.
https://cuenta.example@oferta.example/promo
The @ character can separate user information from the server in some URLs. Legitimate websites can use it, but it can also be misleading. Check the parsed domain, not just the first words you see.
3. Second example: tracking does not automatically mean fraud
https://example.com/oferta?utm_source=folleto&fbclid=EJEMPLO
Parameters after a question mark may measure campaigns, preserve filters or affect a page. utm_source and fbclid are commonly used for advertising attribution. Their presence alone does not establish that a website is harmful. Do not remove every parameter indiscriminately: some are needed for links to work.
Understand UTM, fbclid and other parameters.
4. Third example: a QR that includes a password
WIFI:T:WPA;S:Red-Ejemplo;P:clave-ficticia;;
Not every QR should be posted online. A Wi-Fi configuration QR can contain a network name and password. Other codes may include phone numbers, emails or ticket details. Publishing a photo of the QR may publish its encoded content too; concealing the network name does not necessarily remove the password.
5. Real-world risks: replaced stickers and urgent messages
The US Federal Trade Commission (FTC) has warned about counterfeit QR stickers placed over genuine codes on parking meters, as well as messages alleging delivery or account problems. The FBI has also warned about unexpected packages containing a QR code that urges recipients to scan it. The danger is not the black-and-white pattern itself but the destination or action it may trigger.
If a sign looks tampered with, a sticker appears to have been added, or a message demands immediate action, do not enter credentials or payment details on the linked website. Instead, use the organization's official app or type its known address yourself.
6. What QR Radiography shows—and what it cannot guarantee
The Rusadix tool reads a JPG, PNG or WebP image inside your browser and displays the encoded content without visiting its destination. For web links, it shows the browser-parsed domain and flags specific indicators such as unencrypted HTTP, IP addresses, @ signs or common tracking parameters. You can try fictional examples without uploading an image.
The tool does not follow redirects, query external reputation databases, verify who owns a domain or identify every harmful link. A website using HTTPS may still impersonate an organization. No warnings does NOT mean 'safe'.
7. Checklist before scanning or sharing
- Check the QR's physical or digital source: is it pasted over another sticker, or did it come from someone you trust?
- Read the destination before opening it; identify the full domain, not just the words on the sign.
- For payments or account access, prefer the official app or an address you already know.
- Remember that a QR can also reveal private data, such as a Wi-Fi password, contact details or a ticket.
- Do not confuse a lack of warnings with a safety guarantee; if something looks wrong, do not proceed.