Zhenku
Guard · Verify

What Is an Anti-Phishing Code and Why It Stops Fake Binance Emails

Zhenku Editorial · Cheng Mo Updated 2026-07 About 8 min
Cover: what a Binance anti-phishing code is

The hardest thing about phishing emails is that they keep getting more convincing — the same red-and-yellow colours, the same font, the same sign-off, even the "your account has a problem, act now" tone nailed down. You really can't judge them by "does this look real." The anti-phishing code flips the approach: instead of making you spot the fakes, it makes the real ones show a secret handshake. Once it's set, every legitimate email and in-app message Binance sends you carries a string only you and Binance know — and anything without it you can basically treat as fake on the spot.

What it actually is: a secret handshake between you and Binance

An anti-phishing code is a string of characters you set yourself inside your Binance account. Once it's in place, the official emails and in-app messages Binance sends you carry that string — the one you chose — in the subject line or the body. In other words, it's a private signal agreed between you and Binance: real messages give the signal, fakes can't.

There's plenty a scammer can fake — the logo, the layout, the sender's display name, even a from-address that looks very close. But there's one thing they can't fake: the string you set in private. They simply don't know what you chose, so a forged email either doesn't have the string at all, or fills in the wrong one. That's the whole logic of the anti-phishing code — simple, but seriously effective.

Put plainlyIt doesn't encrypt your email and it isn't a filter. It does one thing: it stamps real emails with a private seal only you recognise, so you can tell real from fake at a glance.

Why it screens out a huge batch of fake emails

The great majority of phishing emails come from the same mould: manufacture urgency ("unusual login detected," "withdrawal request awaiting confirmation," "your account will be frozen"), then lure you into clicking a link, land you on a page that looks like Binance, and get you to type in your login, password and verification code. In that whole chain, the first step is making you believe the email is real. The anti-phishing code jams that first step dead.

With it in place, your judgement process gets radically simpler. No more squinting at the from-address for an extra letter, no more agonising over whether the wording sounds official — you check one thing only: does this email claiming to be Binance carry the string I set?

Precisely because the test becomes this clear-cut, the anti-phishing code filters out a big batch of imitation emails on the email channel outright. It takes two minutes to set, costs practically nothing, and rates among the highest value-for-effort of all your account defences.

What an email looks like with and without the code

Put a real and a fake email side by side and the difference jumps out. Say the code you set for yourself is a meaningless string (we'll use Qm7-River as a placeholder here; yours will be different):

At bottom, the anti-phishing code swaps the hard task of "spotting the fake" for the easy one of "checking whether the real one shows its signal." But there's an unspoken condition for it to work — you have to have a mental picture of that string. For anyone who sets it and forgets it, this defence hasn't really landed.

How to set one: a two-minute job

The place to set it is inside Binance's security settings, usually grouped in with two-factor verification and login devices. For the exact name and location, go by what Binance's official pages currently show — the interface gets adjusted now and then — but the rough flow is this:

  1. Log in to Binance and open your account's security settings page.
  2. Find the "anti-phishing code" item and tap to enable or edit it.
  3. Type in the string you want to use, and complete one two-factor verification as prompted.
  4. Save. From then on, the official emails and in-app messages Binance sends will carry it.

Once it's set, fix a mental note: what the string looks like and where in the email it appears. Walking through my account's security items against the official pages, the anti-phishing code was the quickest of them to finish — but also the easiest to overlook, the one people "can't remember ever setting." It stays quiet day to day and only proves its worth when a fake email actually turns up.

While you're at itWhen you set it, take a quick look at whether the code lands in the subject line or the body. Once you know where it sits, a single glance tells you where to look later, instead of reading the whole thing every time.

How to make one that's hard to guess

The strength of an anti-phishing code comes down to how hard it is to guess or look up. It won't be brute-forced the way a password can be, but scammers sometimes blast out "probe emails," or infer what you might have set from your public information. So when you set it, steer clear of these:

Don't overlook thisThe anti-phishing code is displayed in your emails — it was never meant to be a secret. Its job is to be an anti-forgery mark, not a passphrase. So never set it to anything that needs to stay secret (a password above all). Think of it as the design carved into your personal seal: others can see it, but they can't forge it and can't guess what you carved.

Where it can't reach

The anti-phishing code is very handy, but you have to be clear about its boundaries or it breeds a false sense of security. It only covers the emails and in-app messages Binance sends you. On the channels below it never appears, so of course you can't use "is there an anti-phishing code" to judge them:

So the right way to see it: the anti-phishing code guards the email door, and guards it well — but your account has more than one door. Judging authenticity on the other channels takes the method that fits each. Whether a given message is really real, you can run through the three-step check in how to confirm a "Binance" message is genuine, and when you're unsure, work through the phishing-message authenticity self-check item by item.

How it shows across devices, and whether to rotate it

The anti-phishing code is tied to your account, not to any one device. So you set it once, and after that — whether you log into the same account from the phone app, a desktop browser, or another device — the official emails and in-app messages Binance sends carry the same string. Its carrier is "the communications Binance sends you," independent of which device you read them on. This is unlike an authenticator app: the authenticator's rotating code is computed locally on one particular phone, whereas the anti-phishing code is a fixed, account-level mark.

Changing phones, adding a tablet, switching computers — none of it requires re-setting the anti-phishing code; it travels with the account. If you do want to change it, that's something you do deliberately in the security settings, and once you have, the official communications every device receives switch to the new string.

As for "should I rotate it periodically like a password" — there's really no need to force a schedule. The reason is that it's on plain display in your emails to begin with: by design it isn't a secret, so being seen isn't a risk, and it doesn't grow more dangerous over time the way a password does. Only these situations are worth a one-off change:

Beyond that, set one random enough that you can still remember it, keep using it long-term, and don't burden yourself with a "change it monthly" rule. Spending your effort on "don't forget it, don't make it a password" is worth more than spending it on "how often to rotate."

Using it alongside your other defences

The anti-phishing code doesn't work alone. It and your other defences each cover a stretch, and only stacked together do they seal things up:

How to set all of these in one pass is laid out in order in the complete account-security checklist — just work through it. The anti-phishing code is the "check the message" guard among them; two minutes to set, and after that every Binance email gives you one more layer of confidence.

In one lineThe anti-phishing code defends against "being fooled by a fake email." It can't defend against market swings, and it's no substitute for keeping your own password and seed phrase safe. This piece is about account security only and isn't investment advice of any kind.

FAQ

Does the anti-phishing code appear in texts and phone calls?

No. It only covers the emails and in-app messages Binance sends you; it never appears in SMS, phone calls, or third-party messaging apps. If you get a text with a verification code or a call from someone claiming to be support, you can't tell real from fake by whether the anti-phishing code is present — you have to verify it another way.

What makes a good anti-phishing code?

Make it a string nobody can guess that has nothing to do with your public information. Don't use a nickname, birthday, the last digits of your phone number, or a handle you use everywhere — anything searchable or guessable. Mixing in upper and lower case letters and numbers, and making it a bit longer, is safer. And don't make it the same as any of your passwords.

Does setting an anti-phishing code mean I can't be phished?

No guarantee. It only settles the real-or-fake question for the email and in-app-message channel; it can't stop fake texts, fake calls, fake support DMs, spoofed sites, or an infected device. It's a very cost-effective defence, but use it alongside two-factor verification, a withdrawal whitelist and the rest.

What if I forget the anti-phishing code I set?

Go to Binance's security settings to view or reset it — the process is like setting it the first time and requires one two-factor verification. For the exact entry point, go by what Binance's official pages currently show.

CM
Cheng Mo · Zhenku Editorial

"Cheng Mo" is a pen-name and doesn't represent any licensed expert. What we do is explain Binance's official security settings and public rules in an order an ordinary user can follow, and walk through the steps ourselves to check them where we can. We don't give investment advice; if you spot something we got wrong, please tell us via corrections.

Sources