Seeing where a code goes before going there
The plus gesture anybody can use, and the setting that shows every scanner the destination first.
Add a plus
Put a `+` on the end of any short address of ours and you get a page naming the destination instead of being sent to it: `lynkarr.com/abc123` becomes `lynkarr.com/abc123+`.
It works on anybody's code, not only your own. That is the point — a QR code is the only link in common use that a person cannot read before following, and the person at risk is not the person who made the code.
Looking is not scanning. An inspection is not counted in anybody's figures.
Showing it to everybody
On a dynamic code, turn on **Show people where this goes before sending them**. Every scan then gets the page first, with a button to carry on.
Worth it wherever a scanner has been trained to be suspicious: a payment notice, a parking sign, a letter about somebody's account. It costs you some of them — an extra tap always does — and on a menu or a poster it is usually not worth the friction.
What the page says
The site's name on its own line, large, and the full address underneath. Attackers work in the parts of an address people do not read, so the one part that decides where you land is separated out rather than left for somebody to find in a long string.
It warns about the two oldest tricks: an address carrying a username before the site name (`https://a-familiar-name.com@somewhere-else.example/`), and a site name spelled with letters that only look like ordinary ones.
Nothing on the page comes from the destination. No title fetched from it, no screenshot, no icon from its server — a preview page that renders anything the destination controls has become the attack it exists to prevent.