What Binance's Anti-Phishing Code Actually Does — and What It Doesn't
What it does: an anti-phishing code is a short string you choose in your Binance security settings. Once it's on, Binance's help center says it appears in every genuine email and SMS Binance sends you, and that a message showing no code, or the wrong one, may be a phishing attempt and should be reported. What it doesn't do: it doesn't block or filter anything, it never comes up on a phone call or in a Telegram or WhatsApp DM, and it can't tell you whether a website is real, because a fake login page never has to show it. It answers one question — did this email or text really come from Binance — and that matters because phishing mail now copies the colours, the fonts and the "act now" tone well enough that looks alone won't tell you.
What it actually is: a secret handshake between you and Binance
An anti-phishing code is a string of characters you set yourself inside your Binance account. Once it's in place, the emails and SMS Binance sends you carry that string — the one you chose. In other words, it's a private signal agreed between you and Binance: real messages give the signal, fakes can't.
There's plenty a scammer can fake — the logo, the layout, the sender's display name, even a from-address that looks very close. But there's one thing they can't fake: the string you set in private. They simply don't know what you chose, so a forged email either doesn't have the string at all, or fills in the wrong one. That's the whole logic of the anti-phishing code — simple, but seriously effective.
Why it screens out a huge batch of fake emails
The great majority of phishing emails come from the same mould: manufacture urgency ("unusual login detected," "withdrawal request awaiting confirmation," "your account will be frozen"), then lure you into clicking a link, land you on a page that looks like Binance, and get you to type in your login, password and verification code. In that whole chain, the first step is making you believe the email is real. The anti-phishing code jams that first step dead.
With it in place, your judgement process gets radically simpler. No more squinting at the from-address for an extra letter, no more agonising over whether the wording sounds official — you check one thing only: does this email claiming to be Binance carry the string I set?
- It's there and matches exactly → very likely real (though it's still best not to click links inside the email — get into the habit of going to the site yourself).
- It's missing, or the string is wrong or looks cobbled together → basically a fake. Don't click links, don't reply, don't scan any code.
Precisely because the test becomes this clear-cut, the anti-phishing code filters out a big batch of imitation emails on the email channel outright. It takes two minutes to set, costs practically nothing, and rates among the highest value-for-effort of all your account defences. The natural moment is the day you open the account — the day-one account hardening guide treats it as part of that first session.
What an email looks like with and without the code
Put a real and a fake email side by side and the difference jumps out. Say the code you set for yourself is a meaningless string (we'll use Qm7_Rvr as a placeholder here; yours will be different):
- A real email that matches: it carries Qm7_Rvr somewhere prominent in the subject or body, letter-for-letter the same as what you remember. You can generally take this to have come through a legitimate Binance channel — but even so, don't click the links it wants you to; get into the habit of going to the site yourself.
- A fake email with no code at all: it's all "unusual login detected, verify immediately," the colours and sign-off all look real, but the one thing missing is the string you set. Treat it as fake outright — don't click, don't reply, don't scan any code.
- A fake email with a wrong or made-up code: some phishing emails stuff in a random string posing as an anti-phishing code, betting you can't recall what you set. Which is exactly why the whole thing hinges on you remembering roughly what your string looks like — if it doesn't match, or looks improvised, treat it as fake all the same.
- An email "prompting you to set an anti-phishing code": one line of patter is an email nudging you to "click here to set an anti-phishing code for your account's security," with the link pointing at a phishing site. Remember: setting an anti-phishing code is always something you do by going into the official app or website yourself — never through a link in any email.
At bottom, the anti-phishing code swaps the hard task of "spotting the fake" for the easy one of "checking whether the real one shows its signal." But there's an unspoken condition for it to work — you have to have a mental picture of that string. For anyone who sets it and forgets it, this defence hasn't really landed.
How to set one: a two-minute job
The place to set it is inside Binance's security settings, usually grouped in with two-factor verification and login devices. The labels below are the ones in Binance's help-center article as of September 2026; the interface gets adjusted now and then, so go by what your app shows:
- Log in and open Security. In the app: menu → your profile → Account Info → Security. On the website: hover over the Profile icon → Account → Security, then scroll to Advanced Security.
- Tap Anti-Phishing Code, then Create (on the website, click Enable next to it first).
- Type your code: 6 to 8 characters, using at least three of uppercase letters, lowercase letters, digits and underscores. Special characters aren't accepted.
- Submit, then confirm with your 2FA or a passkey. From then on, every genuine email and SMS from Binance carries it.
Once it's set, fix a mental note: what the string looks like and where in the email it appears. Of the account's security settings, the anti-phishing code is the quickest to finish — but also the easiest to overlook, the one people "can't remember ever setting." It stays quiet day to day and only proves its worth when a fake email actually turns up.
How to make one that's hard to guess
The strength of an anti-phishing code comes down to how hard it is to guess or look up. It won't be brute-forced the way a password can be, but scammers sometimes blast out "probe emails," or infer what you might have set from your public information. So when you set it, steer clear of these:
- Don't use searchable public information: a handle you use everywhere, a social account ID, your email prefix, birthday, the last digits of your phone number — an attacker could get hold of any of these.
- Don't use anything common: a dictionary word with a digit tacked on, a run of consecutive numbers, obvious guesses built on "Binance" — the format rules block some of these, not all.
- Use the room you get: Binance allows only 6 to 8 characters, so mix cases, digits and an underscore into something with no obvious meaning that you can still recognise.
- Don't make it the same as your password or fund password: the anti-phishing code shows up in plain sight in your emails, which is effectively public; if it matches a password, you've exposed that password.
Where it can't reach
The anti-phishing code is very handy, but you have to be clear about its boundaries or it breeds a false sense of security. It only appears in the emails and SMS Binance sends you. Texts carry it but still need care of their own, and on the other channels below it never appears, so "is there an anti-phishing code" can't settle the question there:
- SMS: Binance's help center now says genuine texts carry your code too, so a "Binance" text without it, or with the wrong one, is a red flag. The reverse doesn't make a text safe to act on — don't click any link in a text, only enter a verification code when you've actively logged in yourself, and never read it out to anyone. If you think your number is at risk of being hijacked, demote SMS from being your only 2FA and switch to a security key or an authenticator.
- Phone calls: a call from so-called "Binance support" certainly won't read out your anti-phishing code. Burn this one line into memory: official Binance will not call you out of the blue to ask for a password or verification code, or to have you transfer funds to "prove" or "unfreeze" your account. Hang up on a call like that, and don't read out any code over the phone.
- Third-party messaging apps: a DM on Telegram, WeChat or WhatsApp claiming to be "official" has nothing to do with the anti-phishing code. Official Binance won't DM you first. A stranger adding you, pulling you into an "official group," or DMing you "perks / airdrop / support" links is a scam — treat it as one. If you need help, go through the support entry inside the official app; don't get into it with a "support agent" over IM.
- Spoofed websites: a phishing site is out to trick you into entering your password. The anti-phishing code governs "is this email real," not "is this website real." Reach the site by typing the address yourself or using a bookmark — not by clicking through from search results or a link someone sent you. For how to tell the real site and real app, see how to confirm the Binance app you downloaded is the real one.
So the right way to see it: the anti-phishing code guards the email and SMS doors, and guards them well — but your account has more than one door. Judging authenticity on the other channels takes the method that fits each. Whether a given message is really real, you can run through the three-step check in how to confirm a "Binance" message is genuine, and when you're unsure, work through the phishing-message authenticity self-check item by item.
How it shows across devices, and whether to rotate it
The anti-phishing code is tied to your account, not to any one device. So you set it once, and after that — whether you log into the same account from the phone app, a desktop browser, or another device — the emails and SMS Binance sends carry the same string. Its carrier is "the communications Binance sends you," independent of which device you read them on. This is unlike an authenticator app: the authenticator's rotating code is computed locally on one particular phone, whereas the anti-phishing code is a fixed, account-level mark.
Changing phones, adding a tablet, switching computers — none of it requires re-setting the anti-phishing code; it travels with the account. If you do want to change it, that's something you do deliberately in the security settings, and once you have, the official communications every device receives switch to the new string.
As for rotating it: Binance's help center treats it like a password here, calls updating it regularly good practice, and says to change it as soon as possible if you suspect it has leaked. How often is up to you; these situations call for a change straight away:
- You suspect you originally made it too easy to guess (used a nickname, birthday, last digits of your phone number, that sort of thing) — swap it for a meaningless string.
- You can't remember what you set — and if you can't remember it, this defence has effectively failed, so just reset a memorable, patternless one and lock it in.
- You set it, by mistake, to match one of your passwords — change it immediately (the reason is the red line in the next section).
Whatever schedule you choose, each new code has to be one you'll recognise on sight. A code you rotate and then forget protects you less than an older one you know by heart.
Using it alongside your other defences
The anti-phishing code doesn't work alone. It and your other defences each cover a stretch, and only stacked together do they seal things up:
- Two-factor verification (2FA): even if phishing gets your password, without that 2FA step they still can't log in. The anti-phishing code makes you less likely to take the bait; 2FA is the safety net for the time you do.
- Withdrawal whitelist: even if your account really is logged into, with a whitelist on, withdrawals can only go to addresses you've set in advance — an unfamiliar address gets nothing.
- The habit of going to the site yourself: however real an email looks, try not to get things done through its links; instead open your browser bookmark or type the official address yourself and log in. This one habit fends off phishing better than any single setting.
How to set all of these in one pass is laid out in order in the complete account-security checklist — just work through it. The anti-phishing code is the "check the message" guard among them; two minutes to set, and after that every Binance email and text gives you one more thing to check.
FAQ
Does the anti-phishing code appear in texts and phone calls?
In texts, yes; on calls, no. Binance's help center says the code is included in all genuine emails and SMS from Binance, so a text claiming to be Binance with no code, or the wrong one, may be phishing. It never appears on phone calls or in third-party messaging apps, so a caller or a DM claiming to be support has to be checked another way.
What makes a good anti-phishing code?
Make it a string nobody can guess that has nothing to do with your public information. Don't use a nickname, birthday, the last digits of your phone number, or a handle you use everywhere — anything searchable or guessable. Binance accepts 6 to 8 characters, with at least three of uppercase letters, lowercase letters, digits and underscores, and no special characters; use that room for something with no pattern. And don't make it the same as any of your passwords.
Does setting an anti-phishing code mean I can't be phished?
No guarantee. It only helps you judge emails and texts that claim to come from Binance; it can't stop fake calls, fake support DMs, spoofed sites, or an infected device, and even a message with the right code is no reason to follow its links. It's a very cost-effective defence, but use it alongside two-factor verification, a withdrawal whitelist and the rest.
What if I forget the anti-phishing code I set?
Set a new one. In Security, open Anti-Phishing Code and choose Change Anti-Phishing Code, then confirm with your 2FA or a passkey. Binance's help article describes changing the code, not displaying the old one, so pick a replacement you'll recognise at a glance.
Sources
- Binance Help Center · entries on the anti-phishing code (binance.com/en/support)
- Binance Help Center · What Is an Anti-Phishing Code and How to Set It up on Binance? (binance.com/en/support/faq, updated 2026-08-28, checked 2026-09-25)