Direct answer and scope

Use a visible, human-readable destination as the starting point. Ask whether a destination is printed or otherwise displayed outside the QR image. If it is visible, read the URL before taking any action. For a recognizable address, compare the spelling and letter order with the destination you expected. The FTC specifically identifies misspellings and switched letters as spoofing indicators to notice.

A visible destination supports inspection, but it does not settle every question. A QR image, its underlying destination, control of the domain or account, control of redirects, and the presence of a human-readable fallback are separate evidence states. Evidence about one state should not be converted into a conclusion about another. A QR image alone therefore does not establish what controls exist behind it or whether access will continue.

The scope is limited to interpreting official consumer guidance and organizing questions. No QR code is scanned, no image is analyzed, no URL is inspected, and no destination is opened. No conclusion is reached about a memorial, host, domain operator, QR provider, device, account, or visitor.

How to use the official evidence

Use the FTC consumer alert for two distinct purposes. First, it provides the destination-inspection step: inspect the URL before opening it and look for spelling changes or switched letters when the address is recognizable. Second, it provides broader context about what malicious QR codes can do, including directing someone to a spoofed site or malware and attempting to steal information entered after scanning.

Apply those points as questions, not as findings about a specific code. Is a human-readable destination available outside the image? If so, is the URL recognizable? Does its spelling match what the visitor expected, or are letters missing, changed, or switched? These questions implement the FTC’s inspection guidance without claiming that visual inspection will identify every problem.

Keep device and account practices in their own evidence category. The FTC recommends maintaining current phone software, using strong passwords, and enabling multi-factor authentication. Those practices concern phones and online accounts. They do not perform destination inspection, identify who controls a domain, reveal redirect control, or answer whether a particular destination should be opened.

The official alert and the validated publisher method serve different functions. The alert supplies federal consumer guidance about harmful QR links, URL inspection, and phone or account practices. The publisher method keeps the QR image, destination, domain or account control, redirect control, fallback, export, independent copies, testing, and continuity handoff as separate evidence states. Neither source supplies a vendor-specific finding for this guide.

Decision framework

Begin with the visible-destination question. If no human-readable destination is available outside the code image, record that destination inspection is unresolved. Do not replace the missing visible text with an assumption derived from the QR image. If a destination is displayed, preserve it as the text available for inspection rather than as proof about the code’s behavior.

Next, apply the FTC’s URL question to the visible text. For an address you recognize, check for misspellings and switched letters before opening it. Record only what can be observed in the displayed text. The absence of an indicator you noticed is not a validation of the URL, and the inspection step does not authenticate a memorial, operator, account, domain, or redirect.

Then separate operational questions. The underlying destination may differ from the QR image as an evidence item. Domain or account control is distinct from redirect control. A printed fallback is distinct from the destination’s operation. Export, independent copies, periodic tests, and continuity handoff are also separate states. Do not use a positive answer about one layer to fill an unanswered field in another.

Finally, note the action actually performed. Reading a printed destination is not scanning a code. Comparing visible spelling is not opening a destination. Following general phone and account practices is not inspecting a URL. The resulting status should identify selected observations and unresolved questions without producing a score, choosing a provider, or recommending that a hosted memorial proceed.

Limits and what to verify next

No vendor-specific evidence is attached. There is no validated manifest for a portrait artist, digital-memorial vendor, hosting platform, QR provider, domain operator, processor, product, feature, account control, export method, backup process, price, availability, review, rating, or turnaround. Those values remain unknown unless separate primary evidence passes review.

The unresolved items should stay explicit. A visitor may still need evidence identifying the underlying destination, the party controlling the relevant domain or account, the party controlling any redirect, and the availability of a human-readable fallback. Questions about export, independent copies, periodic tests, and continuity handoff should remain separate rather than being inferred from the presence of a QR code.

The validated organizer does not request a name, contact details, address, information about the deceased, a story, an image, vendor identity, account, URL, domain, filename, file content, free text, upload, payment data, or biometric input. Its controlled selections reset locally and are not sent to the publisher. It does not scan a code, analyze an image, inspect a URL, or open a destination.

A visitor who needs to evaluate a real destination must perform that verification outside the organizer and consult current official guidance. The organizer can preserve selected labels, scope notes, and unanswered questions, but it does not turn an unanswered status into a positive conclusion or provide a legal or technical determination.

Evidence behind this page

Each point below is restricted to what the cited primary source supports. Administrative listing status is not a quality endorsement.

Claim-level evidence used on this page
EvidenceSupported pointScope and limitation
Evidence 1Explain why a physical memorial should show a human-readable destination and why a visitor should inspect a destination before opening it.Do not claim that a memorial QR code is malicious, safe, secure, permanent, authenticated, monitored, or protected from later destination changes.
Evidence 2Include a scan-safety note and a checklist question for a visible, verifiable destination outside the code image.Do not validate a URL, scan a code, open a destination, promise detection of spoofing, or substitute the note for device or security guidance.
Evidence 3Link to the official consumer alert as general scan and account-safety context.Do not assess a device, account, password, authentication method, QR destination, memorial host, or visitor's security posture.
Evidence 4Publish official method guidance and vendor-question fields only, leaving vendor-specific values unknown until a separate primary-evidence manifest passes review.Do not name, list, rank, recommend, contact, quote, compare, review, or imply a feature or capability of any vendor or platform.
Evidence 5Keep every layer visible and unresolved rather than using a QR-present badge as proof of persistence.Do not guarantee a QR code, link, URL, domain, redirect, account, host, export, backup, restore, or memorial will remain accessible.
Evidence 6Describe the tools as anonymous in-page organizers whose controlled selections reset locally and are not sent to the publisher.Do not add image analysis, face recognition, biometric processing, generation, restoration, personalization, cloud export, saved project, account connection, vendor submission, or background request.
Evidence 7Show selected labels, unresolved questions, scope notes, and internal reading routes with a reset action.Do not calculate a score, select a vendor, provide a legal result, or recommend proceeding with a commission or hosted memorial.

Questions people ask

Why inspect a memorial QR destination before opening it?

The FTC warns that a malicious QR code can lead to a spoofed site or malware and may be used to steal information entered by the person scanning it. The FTC therefore advises inspecting the URL before opening a QR destination. That general warning does not establish that a particular memorial code is malicious.

Which URL spoofing indicators does the FTC consumer alert mention?

For recognizable URLs, the FTC alert identifies misspellings and switched letters as indicators to check. Looking for those indicators is an inspection step, not validation of the address or a promise that every deceptive destination will be detected.

Can a QR code lead to a spoofed site or harmful content?

The FTC warns that a malicious QR code can direct a scanner to a spoofed site or malware. This is general consumer guidance and does not determine the status of any particular memorial QR code or destination.

Does the guide scan a code, inspect a URL, or open a destination?

No. It does not scan a QR code, analyze an image, inspect a supplied URL, or open a destination. The validated organizer does not request URLs, domains, files, images, free text, uploads, account information, or payment data, and its controlled selections are not sent to the publisher.

Do updated software, strong passwords, or multi-factor authentication establish that a destination can be trusted?

No. The FTC recommends current phone software, strong passwords, and multi-factor authentication as protective practices for phones and online accounts. Those practices do not inspect or validate a particular QR destination, domain, redirect, device, account, or memorial host.

Can I paste a URL, upload a QR image, identify a memorial, or report an incident?

No. The validated organizer asks for no URL, domain, image, photograph, filename, file content, free text, upload, name, contact information, decedent information, vendor identity, or account information. It organizes controlled selections locally and does not submit reports or send those selections to the publisher.

Primary sources

  1. Federal Trade Commission — Scammers Hide Harmful Links in QR Codes Verified 2026-08-26
  2. Memorial Portrait and Digital Continuity Desk validated source and checklist methodology Verified 2026-08-26