Allow me to explain in detail:
The QR code as appears in the management console is dynamic. This means that if you log on to your management console using the local IP of the PBX, it will build a provisioning link with the IP.
Same goes if you login via the FQDN, it will build a link using the FQDN.
Now depending on how your mobile connects to the internet in relation to the server, it may not be able to reach the link in the QR code. If you use a QR scanner app, it will reveal the link to you (in case you want to compare and see how it works, and justify why it failed).
The email on the other hand, will include the FQDN. So when your mobile tries to reach the FQDN externally (ie from LTE or from some public WiFi) it will succesfully reach your server and provision as intended.
Now there is also a special case scenario, where you scan the email-QR while you are in the office, connected to the same lan as the PBX: your firewall will see that you are requesting to connect to your public FQDN's IP while you are behind that same public IP (you loopback from inside, to outside, and back inside again) and many firewalls tend to not allow this.