Zhenku
Guard · Verify

What Binance's Anti-Phishing Code Actually Does — and What It Doesn't

Zhenku Editorial · Cheng Mo Updated 2026-09-25 About 8 min
Cover: what a Binance anti-phishing code is

What it does: an anti-phishing code is a short string you choose in your Binance security settings. Once it's on, Binance's help center says it appears in every genuine email and SMS Binance sends you, and that a message showing no code, or the wrong one, may be a phishing attempt and should be reported. What it doesn't do: it doesn't block or filter anything, it never comes up on a phone call or in a Telegram or WhatsApp DM, and it can't tell you whether a website is real, because a fake login page never has to show it. It answers one question — did this email or text really come from Binance — and that matters because phishing mail now copies the colours, the fonts and the "act now" tone well enough that looks alone won't tell you.

What it actually is: a secret handshake between you and Binance

An anti-phishing code is a string of characters you set yourself inside your Binance account. Once it's in place, the emails and SMS Binance sends you carry that string — the one you chose. In other words, it's a private signal agreed between you and Binance: real messages give the signal, fakes can't.

There's plenty a scammer can fake — the logo, the layout, the sender's display name, even a from-address that looks very close. But there's one thing they can't fake: the string you set in private. They simply don't know what you chose, so a forged email either doesn't have the string at all, or fills in the wrong one. That's the whole logic of the anti-phishing code — simple, but seriously effective.

Put plainlyIt doesn't encrypt your email and it isn't a filter. It does one thing: it stamps real emails with a private seal only you recognise, so you can tell real from fake at a glance.

Why it screens out a huge batch of fake emails

The great majority of phishing emails come from the same mould: manufacture urgency ("unusual login detected," "withdrawal request awaiting confirmation," "your account will be frozen"), then lure you into clicking a link, land you on a page that looks like Binance, and get you to type in your login, password and verification code. In that whole chain, the first step is making you believe the email is real. The anti-phishing code jams that first step dead.

With it in place, your judgement process gets radically simpler. No more squinting at the from-address for an extra letter, no more agonising over whether the wording sounds official — you check one thing only: does this email claiming to be Binance carry the string I set?

Precisely because the test becomes this clear-cut, the anti-phishing code filters out a big batch of imitation emails on the email channel outright. It takes two minutes to set, costs practically nothing, and rates among the highest value-for-effort of all your account defences. The natural moment is the day you open the account — the day-one account hardening guide treats it as part of that first session.

What an email looks like with and without the code

Put a real and a fake email side by side and the difference jumps out. Say the code you set for yourself is a meaningless string (we'll use Qm7_Rvr as a placeholder here; yours will be different):

At bottom, the anti-phishing code swaps the hard task of "spotting the fake" for the easy one of "checking whether the real one shows its signal." But there's an unspoken condition for it to work — you have to have a mental picture of that string. For anyone who sets it and forgets it, this defence hasn't really landed.

How to set one: a two-minute job

The place to set it is inside Binance's security settings, usually grouped in with two-factor verification and login devices. The labels below are the ones in Binance's help-center article as of September 2026; the interface gets adjusted now and then, so go by what your app shows:

  1. Log in and open Security. In the app: menu → your profile → Account Info → Security. On the website: hover over the Profile icon → Account → Security, then scroll to Advanced Security.
  2. Tap Anti-Phishing Code, then Create (on the website, click Enable next to it first).
  3. Type your code: 6 to 8 characters, using at least three of uppercase letters, lowercase letters, digits and underscores. Special characters aren't accepted.
  4. Submit, then confirm with your 2FA or a passkey. From then on, every genuine email and SMS from Binance carries it.

Once it's set, fix a mental note: what the string looks like and where in the email it appears. Of the account's security settings, the anti-phishing code is the quickest to finish — but also the easiest to overlook, the one people "can't remember ever setting." It stays quiet day to day and only proves its worth when a fake email actually turns up.

While you're at itWhen you set it, take a quick look at whether the code lands in the subject line or the body. Once you know where it sits, a single glance tells you where to look later, instead of reading the whole thing every time.

How to make one that's hard to guess

The strength of an anti-phishing code comes down to how hard it is to guess or look up. It won't be brute-forced the way a password can be, but scammers sometimes blast out "probe emails," or infer what you might have set from your public information. So when you set it, steer clear of these:

Don't overlook thisThe anti-phishing code is displayed in every genuine email and text. Its job is to be an anti-forgery mark, not a passphrase. So never set it to anything that needs to stay secret (a password above all). Think of it as the design carved into your personal seal: others can see it, but they can't forge it and can't guess what you carved.

Where it can't reach

The anti-phishing code is very handy, but you have to be clear about its boundaries or it breeds a false sense of security. It only appears in the emails and SMS Binance sends you. Texts carry it but still need care of their own, and on the other channels below it never appears, so "is there an anti-phishing code" can't settle the question there:

So the right way to see it: the anti-phishing code guards the email and SMS doors, and guards them well — but your account has more than one door. Judging authenticity on the other channels takes the method that fits each. Whether a given message is really real, you can run through the three-step check in how to confirm a "Binance" message is genuine, and when you're unsure, work through the phishing-message authenticity self-check item by item.

How it shows across devices, and whether to rotate it

The anti-phishing code is tied to your account, not to any one device. So you set it once, and after that — whether you log into the same account from the phone app, a desktop browser, or another device — the emails and SMS Binance sends carry the same string. Its carrier is "the communications Binance sends you," independent of which device you read them on. This is unlike an authenticator app: the authenticator's rotating code is computed locally on one particular phone, whereas the anti-phishing code is a fixed, account-level mark.

Changing phones, adding a tablet, switching computers — none of it requires re-setting the anti-phishing code; it travels with the account. If you do want to change it, that's something you do deliberately in the security settings, and once you have, the official communications every device receives switch to the new string.

As for rotating it: Binance's help center treats it like a password here, calls updating it regularly good practice, and says to change it as soon as possible if you suspect it has leaked. How often is up to you; these situations call for a change straight away:

Whatever schedule you choose, each new code has to be one you'll recognise on sight. A code you rotate and then forget protects you less than an older one you know by heart.

Using it alongside your other defences

The anti-phishing code doesn't work alone. It and your other defences each cover a stretch, and only stacked together do they seal things up:

How to set all of these in one pass is laid out in order in the complete account-security checklist — just work through it. The anti-phishing code is the "check the message" guard among them; two minutes to set, and after that every Binance email and text gives you one more thing to check.

In one lineThe anti-phishing code defends against "being fooled by a fake email." It can't defend against market swings, and it's no substitute for keeping your own password and seed phrase safe. This piece is about account security only and isn't investment advice of any kind.

FAQ

Does the anti-phishing code appear in texts and phone calls?

In texts, yes; on calls, no. Binance's help center says the code is included in all genuine emails and SMS from Binance, so a text claiming to be Binance with no code, or the wrong one, may be phishing. It never appears on phone calls or in third-party messaging apps, so a caller or a DM claiming to be support has to be checked another way.

What makes a good anti-phishing code?

Make it a string nobody can guess that has nothing to do with your public information. Don't use a nickname, birthday, the last digits of your phone number, or a handle you use everywhere — anything searchable or guessable. Binance accepts 6 to 8 characters, with at least three of uppercase letters, lowercase letters, digits and underscores, and no special characters; use that room for something with no pattern. And don't make it the same as any of your passwords.

Does setting an anti-phishing code mean I can't be phished?

No guarantee. It only helps you judge emails and texts that claim to come from Binance; it can't stop fake calls, fake support DMs, spoofed sites, or an infected device, and even a message with the right code is no reason to follow its links. It's a very cost-effective defence, but use it alongside two-factor verification, a withdrawal whitelist and the rest.

What if I forget the anti-phishing code I set?

Set a new one. In Security, open Anti-Phishing Code and choose Change Anti-Phishing Code, then confirm with your 2FA or a passkey. Binance's help article describes changing the code, not displaying the old one, so pick a replacement you'll recognise at a glance.

CM
Cheng Mo · Zhenku Editorial

"Cheng Mo" is a pen-name and doesn't represent any licensed expert. What we do is explain Binance's official security settings and public rules in an order an ordinary user can follow, checked line by line against Binance's own pages. We don't give investment advice; if you spot something we got wrong, please tell us via corrections.

Sources