ITIT Lunchroom
Cybersecurity Awareness Essentials
Browser, Download, and QR Safety
Learn how to tell whether a link, a file you're asked to open or send, or a code you're asked to scan really belongs to what you're doing—before you act on it.
Before you open, send, or scan anything, three things should all make sense: where it came from, where it's actually going, and why it's part of what you're doing.
Last reviewed 2026-06-17 by the IT Lunchroom Editorial Team. General guidance, not professional security or legal advice.
What you will learn
I can decide whether a link, a file I'm asked to open or send, or a code I'm asked to scan really belongs to what I'm doing.
You leave with one simple check you can use again and again—where it came from, where it's going, and why—for any link, file, or code you're asked to open, send, or scan.
the where-from, where-to, and why checkdeciding which files are safe to openbeing careful about what you send outwhy a code you scan can take you somewhere unexpectedbrowser warning signshow to double-check and who to tell
What's really happening when you click
Every time you follow a link, open a file, or scan a code, something is moving in or out. A link takes you somewhere new. Opening a file brings it onto your device. Sending a file pushes your information out to someone else. And one of those square patterns you scan with your phone (often called a QR code) is really just a hidden web address that takes you somewhere. Each one is a small decision about where your information goes—not just a harmless click.
How a bad link, file, or code catches people out
Trouble usually comes from a small mismatch you didn't notice. A link or a code to scan can show friendly text while quietly pointing somewhere else. A file you open can carry hidden, harmful software instead of the thing you expected. And sending a file can push out more of your information than you meant to. The people behind this are counting on you acting before you stop to check where it's all going.
Signs it's worth slowing down
Slow down when something doesn't add up about where it came from, where it's going, or why. Common signs: a file that starts saving or a code to scan that you never asked for, a web address that doesn't match the company it claims to be from, a nudge to ignore a safety warning, a request to send more files than you actually need to, or pressure to hurry. Any one of these on its own is a good reason to pause.
The simple check you can use every time
Before you open a file, send one, or scan a code, check three quick things. Where it came from: do I trust the sender, and was I expecting this? Where it's going: where is this link or file actually taking me or my information, and does the web address match? And why: does this clearly fit what I'm doing right now? If any one of the three doesn't make sense, stop and double-check before you go ahead—using a way you already trust.
How this plays out in real life
Say a message asks you to scan a code to see a bill you supposedly owe. Run the check. Where it came from: you weren't expecting it and can't be sure who sent it—so that's already shaky. Where it's going: the code points to a web address that doesn't match the company you normally deal with. And why: bills usually reach you the way they always have, not through a surprise scan. Two of the three don't hold up, so the safe move is simple—don't scan it. Instead, check with whoever you'd normally trust, or pass it along to whoever handles this kind of thing.
Practice and evidence
Optional practice lets you walk through made-up examples—links, files, things to scan—and decide which ones really fit the task, without touching anything real.
Write a short note for yourself about how you checked where a link, file, or code came from, where it was going, and why—and what you decided. Leave out the actual web address, the file, and anything private.
Common questions
What should be true before you open a link, open or send a file, or scan a code?
Where it came from, where it's going, and why all make sense. If even one of those—where it came from, where it's going, or why—doesn't add up, that's a reason to stop. A nice-looking page and a sense of urgency don't prove anything is safe.
Why is one of those square codes worth checking before you scan it?
It's a hidden web address, and it can point anywhere. A code like that just holds a web address you can't read with your eyes, so it deserves the same check as any link: where it came from, where it's going, and why.
Something asks you to send more files than you actually need to. What does this suggest?
Whoever is on the other end may be getting more of your information than they should. Sending out more than you really need to is risky, so share only what's actually needed—and double-check first if the request seems to be asking for a lot.
What should you do if a file you never asked for starts saving to your device, or a message pushes you to open an attachment to see something important?
Don't open it. Check where it came from, where it's going, and why—and if it doesn't clearly fit what you're doing, double-check using a way you trust, or tell whoever handles this kind of thing. A file you never asked for fails two of the checks—where it came from and why—so the safe move is to double-check before opening, not to trust it.
What should you do if a code or link asks you to sign in, confirm a payment, or send in documents, and the web address isn't the one you'd expect from that company?
Stop before you type anything in. Go to the site yourself using a web address you already know and trust, and if it still doesn't match, check with someone you trust or pass it along to whoever handles this kind of thing. A web address that doesn't match the company you expected is a strong warning sign, so go there yourself using a way you already trust, not the one you were just handed.
Make it stick
Do the hands-on version of this lesson, then create a free account to save your progress. Finish a whole track and you earn a shareable certificate you can add to a résumé or job application. No payment, no catch.