What Is an Anti-Phishing Code and Why It Stops Fake Binance Emails
The hardest thing about phishing emails is that they keep getting more convincing — the same red-and-yellow colours, the same font, the same sign-off, even the "your account has a problem, act now" tone nailed down. You really can't judge them by "does this look real." The anti-phishing code flips the approach: instead of making you spot the fakes, it makes the real ones show a secret handshake. Once it's set, every legitimate email and in-app message Binance sends you carries a string only you and Binance know — and anything without it you can basically treat as fake on the spot.
What it actually is: a secret handshake between you and Binance
An anti-phishing code is a string of characters you set yourself inside your Binance account. Once it's in place, the official emails and in-app messages Binance sends you carry that string — the one you chose — in the subject line or the body. In other words, it's a private signal agreed between you and Binance: real messages give the signal, fakes can't.
There's plenty a scammer can fake — the logo, the layout, the sender's display name, even a from-address that looks very close. But there's one thing they can't fake: the string you set in private. They simply don't know what you chose, so a forged email either doesn't have the string at all, or fills in the wrong one. That's the whole logic of the anti-phishing code — simple, but seriously effective.
Why it screens out a huge batch of fake emails
The great majority of phishing emails come from the same mould: manufacture urgency ("unusual login detected," "withdrawal request awaiting confirmation," "your account will be frozen"), then lure you into clicking a link, land you on a page that looks like Binance, and get you to type in your login, password and verification code. In that whole chain, the first step is making you believe the email is real. The anti-phishing code jams that first step dead.
With it in place, your judgement process gets radically simpler. No more squinting at the from-address for an extra letter, no more agonising over whether the wording sounds official — you check one thing only: does this email claiming to be Binance carry the string I set?
- It's there and matches exactly → very likely real (though it's still best not to click links inside the email — get into the habit of going to the site yourself).
- It's missing, or the string is wrong or looks cobbled together → basically a fake. Don't click links, don't reply, don't scan any code.
Precisely because the test becomes this clear-cut, the anti-phishing code filters out a big batch of imitation emails on the email channel outright. It takes two minutes to set, costs practically nothing, and rates among the highest value-for-effort of all your account defences.
What an email looks like with and without the code
Put a real and a fake email side by side and the difference jumps out. Say the code you set for yourself is a meaningless string (we'll use Qm7-River as a placeholder here; yours will be different):
- A real email that matches: it carries Qm7-River somewhere prominent in the subject or body, letter-for-letter the same as what you remember. You can generally take this to have come through a legitimate Binance channel — but even so, don't click the links it wants you to; get into the habit of going to the site yourself.
- A fake email with no code at all: it's all "unusual login detected, verify immediately," the colours and sign-off all look real, but the one thing missing is the string you set. Treat it as fake outright — don't click, don't reply, don't scan any code.
- A fake email with a wrong or made-up code: some phishing emails stuff in a random string posing as an anti-phishing code, betting you can't recall what you set. Which is exactly why the whole thing hinges on you remembering roughly what your string looks like — if it doesn't match, or looks improvised, treat it as fake all the same.
- An email "prompting you to set an anti-phishing code": one line of patter is an email nudging you to "click here to set an anti-phishing code for your account's security," with the link pointing at a phishing site. Remember: setting an anti-phishing code is always something you do by going into the official app or website yourself — never through a link in any email.
At bottom, the anti-phishing code swaps the hard task of "spotting the fake" for the easy one of "checking whether the real one shows its signal." But there's an unspoken condition for it to work — you have to have a mental picture of that string. For anyone who sets it and forgets it, this defence hasn't really landed.
How to set one: a two-minute job
The place to set it is inside Binance's security settings, usually grouped in with two-factor verification and login devices. For the exact name and location, go by what Binance's official pages currently show — the interface gets adjusted now and then — but the rough flow is this:
- Log in to Binance and open your account's security settings page.
- Find the "anti-phishing code" item and tap to enable or edit it.
- Type in the string you want to use, and complete one two-factor verification as prompted.
- Save. From then on, the official emails and in-app messages Binance sends will carry it.
Once it's set, fix a mental note: what the string looks like and where in the email it appears. Walking through my account's security items against the official pages, the anti-phishing code was the quickest of them to finish — but also the easiest to overlook, the one people "can't remember ever setting." It stays quiet day to day and only proves its worth when a fake email actually turns up.
How to make one that's hard to guess
The strength of an anti-phishing code comes down to how hard it is to guess or look up. It won't be brute-forced the way a password can be, but scammers sometimes blast out "probe emails," or infer what you might have set from your public information. So when you set it, steer clear of these:
- Don't use searchable public information: a handle you use everywhere, a social account ID, your email prefix, birthday, the last digits of your phone number — an attacker could get hold of any of these.
- Don't use anything too short or too common: a single dictionary word, a run of consecutive numbers, obvious guesses like "binance" or "safe" — these are next to useless.
- Mix in some randomness: upper and lower case letters plus numbers, a bit longer, into a string with no obvious meaning that you can still remember.
- Don't make it the same as your password or fund password: the anti-phishing code shows up in plain sight in your emails, which is effectively public; if it matches a password, you've exposed that password.
Where it can't reach
The anti-phishing code is very handy, but you have to be clear about its boundaries or it breeds a false sense of security. It only covers the emails and in-app messages Binance sends you. On the channels below it never appears, so of course you can't use "is there an anti-phishing code" to judge them:
- SMS: Binance's SMS verification codes don't carry your anti-phishing code, so you can't judge a fake text by "is the code there." Defend this channel on its own — don't click any link in a text, only enter a verification code when you've actively logged in yourself, and never read it out to anyone. If you think your number is at risk of being hijacked, demote SMS from being your only 2FA and switch to a security key or an authenticator.
- Phone calls: a call from so-called "Binance support" certainly won't read out your anti-phishing code. Burn this one line into memory: official Binance will not call you out of the blue to ask for a password or verification code, or to have you transfer funds to "prove" or "unfreeze" your account. Hang up on a call like that, and don't read out any code over the phone.
- Third-party messaging apps: a DM on Telegram, WeChat or WhatsApp claiming to be "official" has nothing to do with the anti-phishing code. Official Binance won't DM you first. A stranger adding you, pulling you into an "official group," or DMing you "perks / airdrop / support" links is a scam — treat it as one. If you need help, go through the support entry inside the official app; don't get into it with a "support agent" over IM.
- Spoofed websites: a phishing site is out to trick you into entering your password. The anti-phishing code governs "is this email real," not "is this website real." Reach the site by typing the address yourself or using a bookmark — not by clicking through from search results or a link someone sent you. For how to tell the real site and real app, see how to confirm the Binance app you downloaded is the real one.
So the right way to see it: the anti-phishing code guards the email door, and guards it well — but your account has more than one door. Judging authenticity on the other channels takes the method that fits each. Whether a given message is really real, you can run through the three-step check in how to confirm a "Binance" message is genuine, and when you're unsure, work through the phishing-message authenticity self-check item by item.
How it shows across devices, and whether to rotate it
The anti-phishing code is tied to your account, not to any one device. So you set it once, and after that — whether you log into the same account from the phone app, a desktop browser, or another device — the official emails and in-app messages Binance sends carry the same string. Its carrier is "the communications Binance sends you," independent of which device you read them on. This is unlike an authenticator app: the authenticator's rotating code is computed locally on one particular phone, whereas the anti-phishing code is a fixed, account-level mark.
Changing phones, adding a tablet, switching computers — none of it requires re-setting the anti-phishing code; it travels with the account. If you do want to change it, that's something you do deliberately in the security settings, and once you have, the official communications every device receives switch to the new string.
As for "should I rotate it periodically like a password" — there's really no need to force a schedule. The reason is that it's on plain display in your emails to begin with: by design it isn't a secret, so being seen isn't a risk, and it doesn't grow more dangerous over time the way a password does. Only these situations are worth a one-off change:
- You suspect you originally made it too easy to guess (used a nickname, birthday, last digits of your phone number, that sort of thing) — swap it for a meaningless string.
- You can't remember what you set — and if you can't remember it, this defence has effectively failed, so just reset a memorable, patternless one and lock it in.
- You set it, by mistake, to match one of your passwords — change it immediately (the reason is the red line in the next section).
Beyond that, set one random enough that you can still remember it, keep using it long-term, and don't burden yourself with a "change it monthly" rule. Spending your effort on "don't forget it, don't make it a password" is worth more than spending it on "how often to rotate."
Using it alongside your other defences
The anti-phishing code doesn't work alone. It and your other defences each cover a stretch, and only stacked together do they seal things up:
- Two-factor verification (2FA): even if phishing gets your password, without that 2FA step they still can't log in. The anti-phishing code makes you less likely to take the bait; 2FA is the safety net for the time you do.
- Withdrawal whitelist: even if your account really is logged into, with a whitelist on, withdrawals can only go to addresses you've set in advance — an unfamiliar address gets nothing.
- The habit of going to the site yourself: however real an email looks, try not to get things done through its links; instead open your browser bookmark or type the official address yourself and log in. This one habit fends off phishing better than any single setting.
How to set all of these in one pass is laid out in order in the complete account-security checklist — just work through it. The anti-phishing code is the "check the message" guard among them; two minutes to set, and after that every Binance email gives you one more layer of confidence.
FAQ
Does the anti-phishing code appear in texts and phone calls?
No. It only covers the emails and in-app messages Binance sends you; it never appears in SMS, phone calls, or third-party messaging apps. If you get a text with a verification code or a call from someone claiming to be support, you can't tell real from fake by whether the anti-phishing code is present — you have to verify it another way.
What makes a good anti-phishing code?
Make it a string nobody can guess that has nothing to do with your public information. Don't use a nickname, birthday, the last digits of your phone number, or a handle you use everywhere — anything searchable or guessable. Mixing in upper and lower case letters and numbers, and making it a bit longer, is safer. And don't make it the same as any of your passwords.
Does setting an anti-phishing code mean I can't be phished?
No guarantee. It only settles the real-or-fake question for the email and in-app-message channel; it can't stop fake texts, fake calls, fake support DMs, spoofed sites, or an infected device. It's a very cost-effective defence, but use it alongside two-factor verification, a withdrawal whitelist and the rest.
What if I forget the anti-phishing code I set?
Go to Binance's security settings to view or reset it — the process is like setting it the first time and requires one two-factor verification. For the exact entry point, go by what Binance's official pages currently show.
Sources
- Binance security page · security feature descriptions (binance.com/en/security, go by the current official page)
- Binance Help Center · entries on the anti-phishing code (binance.com/en/support)