What QRbolt Checks (and What It Doesn't)
An honest look at what the threat check can and can't catch.
What QRbolt checks
When you scan a code, QRbolt checks the destination URL against real-time threat databases and inspects the redirect chain and HTTPS status before your browser opens it. This happens before you ever land on the page, not after.
What it can't catch
A brand-new phishing domain that hasn't been reported anywhere yet, or a technically "safe" page that's still trying to scam you — for example, a legitimate-looking form asking for information it shouldn't need.
Reading the verdict
"No Warnings Found" means the link wasn't on any list we checked. It does not mean the destination is certified safe. New or targeted scams may not appear in any threat list yet — always use your judgment before opening unfamiliar links, even after a clean check.
Where the data comes from
QRbolt checks scanned links against a local threat database sourced from PhishTank and OpenPhish, and, when configured, Google Safe Browsing. These are widely-used, crowdsourced and industry threat feeds, not an infallible in-house system — which is exactly why a clean result is treated as "nothing found yet," not a guarantee.