Let's get straight to it: a Binance anti-phishing code is a custom phrase you set yourself. Once enabled, every genuine Binance email will display that phrase in the subject line or at the start of the body — any email missing it is a phishing attempt. It takes about 1 minute to set up and lets you identify fake Binance emails with near-100% accuracy. Enable it under Security Settings on the Binance Official Site; on mobile, the same setting is found in the Official Binance App; iPhone users should check the iOS installation guide to download the app. Of all Binance's security features, this is the one with the lowest cost, the best payoff, and the fewest users who actually turn it on.
Phishing emails drain hundreds of millions of dollars from Binance users every year. Scammers forge email subject lines, sender addresses, and entire login pages that look nearly identical to the real thing, and ordinary users often can't tell the difference. But with an anti-phishing code enabled, every fake email is instantly exposed — because the scammer has no idea what your code is.
Before sending you an email, Binance's servers automatically insert the code you've set. For example, if you set BinGuru-Apple-2026, that exact string will appear in the subject line or at the beginning of every genuine email.
Phishing emails come from third-party servers whose senders have no idea what your code is, so it will never appear in their messages. A single glance at the subject line or opening text tells you whether it's real.
The mechanism boils down to this:
Log in at binance.com, click your avatar in the top-right corner → "Account" → "Security" from the left-hand menu.
App users: tap your avatar in the top-left corner → "Security Settings".
Scroll down to find the "Anti-Phishing Code" row (labeled "Anti-Phishing Code" in the English interface). Its status shows either "Not Set" or "Enabled". New users default to "Not Set".
Click "Create" next to "Anti-Phishing Code". A dialog box will pop up asking you to set a string of 4-20 characters.
Binance requires the anti-phishing code to:
The worst thing you can do is use something generic like "binance123", "abc123", or "888888". If a scammer sends out a mass phishing campaign and happens to randomly include something like Binance-Security, you won't be able to tell real from fake.
Characteristics of a good anti-phishing code:
Examples:
| Not recommended | Recommended |
|---|---|
| binance | TomCat-2026-x9k |
| 123456 | mAjk3-fRog-77 |
| security | apple-Donut-Run42 |
| safe2026 | KitKat-9w-Banana |
The input field shows a preview as you type — confirm it's correct before submitting.
After clicking "Submit", Binance requires triple verification:
Once all three codes are entered correctly, your anti-phishing code is saved and its status changes to "Enabled".
After setting it up, have Binance send you a test email. The simplest way:
If it does, it's working. Every important email Binance sends (login notifications, withdrawal confirmations, password changes, API creation, etc.) will include this phrase.
Once it's set up, make it a habit to check the anti-phishing code the moment you open any Binance email.
Example of a real email:
Subject: [BinGuru-Apple-2026] Login Notification for Your Account
Body: Dear user, your account was logged into on 2026-04-25 at 14:23 (UTC+8) from IP 1.2.3.4...
Example of a phishing email:
Subject: [Urgent] Unusual Activity Detected on Your Binance Account!
Body: Unusual login activity has been detected on your account. Please click the link below to verify immediately...
The first email carries the anti-phishing code → it's genuine. The second email has no anti-phishing code → it's phishing. Delete it immediately and don't click any links.
| Practice | Notes |
|---|---|
| 1. Change it every 3-6 months | Reduces the risk of it being memorized after long-term exposure |
| 2. Never write it in a public place | Don't post it on Twitter, social media, or public notes |
| 3. Never tell anyone | Including so-called "support staff" — real support never asks for it |
| 4. Combine it with other security settings | On its own, its effectiveness is limited |
| 5. Be suspicious of any email without it | No code means it's fake — don't click any links |
Misconception 1: Thinking the anti-phishing code appears in the email's URL
Wrong. The anti-phishing code only appears in the email's subject line and body text. The links inside the email use the binance.com domain and never contain the anti-phishing code.
Misconception 2: Thinking SMS verification codes also carry the anti-phishing code
Wrong. SMS codes have strict character limits and never include the anti-phishing code. The anti-phishing code is used exclusively for identifying emails.
Misconception 3: Thinking that setting an anti-phishing code means you're completely safe
Not true. The anti-phishing code can only identify phishing emails — it can't stop other kinds of attacks:
The anti-phishing code is one layer of "email authenticity verification" — it's not a complete defense on its own.
Misconception 4: Thinking the anti-phishing code encrypts the email content
It doesn't. The anti-phishing code is purely an identity marker — it doesn't encrypt the body of the email. The email content could still be exposed to a man-in-the-middle attack.
Knowing how scammers operate makes them much easier to spot.
Tactic 1: Manufactured urgency
"Unusual login activity detected on your account — verify immediately!" — creates a sense of urgency so you click the link without thinking.
Tactic 2: Fake withdrawal confirmation
"A withdrawal of 10 BTC has been initiated on your account. If this wasn't you, cancel it immediately!" — you panic at the thought of a real withdrawal and click the fake link in a rush.
Tactic 3: Reward bait
"Congratulations, you've received an airdrop of 1000 USDT — claim it now!" — nothing is ever free; Binance never distributes rewards through email links.
Tactic 4: Expired KYC
"Your KYC is about to expire — please re-verify your identity!" — directs you to a fake Binance site to enter your identity information.
Tactic 5: Fake support follow-up
"Your previously submitted ticket requires additional materials — please click here to upload them." — once opened, it prompts you to enter your password and 2FA code.
A single glance at the anti-phishing code exposes every one of these tricks.
Q: Can the anti-phishing code use non-Latin characters? A: The global version of Binance only supports letters and numbers, not non-Latin characters. Some regional versions (such as Binance Japan) support local-language characters, but global users should stick to letters and numbers.
Q: Can Binance staff see my anti-phishing code? A: The anti-phishing code is stored encrypted in Binance's database. Regular support staff can't see it — only a small number of backend technical staff have access. This is exactly why support will never ask you for it, even over the phone.
Q: What if I forget my anti-phishing code? A: Log in to your account → Security Settings → Anti-Phishing Code → click "Modify" and enter a new one. Once changed, the old code is invalidated immediately. Modifying it doesn't require knowing the old code.
Q: Will the anti-phishing code show up if I log in from a different device? A: Yes. The anti-phishing code isn't tied to any device — it's bound to your Binance account. Any device that checks your email will see the same code.
Q: Why do some Binance emails not include the anti-phishing code? A: A very small number of pure marketing emails (like feature announcements or holiday greetings) may not carry it. But every email related to account security — logins, withdrawals, password changes, API activity, security settings changes — always includes it.
Q: Does the code need to be at least 4 characters long? A: Yes. Binance's minimum requirement is 4 characters, but 10-15 characters is strongly recommended. The longer it is, the harder it is to guess or accidentally match by a scammer's random string.
Q: Can I set multiple anti-phishing codes at once? A: No. A single Binance account can only have one anti-phishing code at a time, though you can change it as often as you like with no limit.
Q: Does the anti-phishing code show up in Binance app notifications? A: Usually not — push notifications have character limits. The anti-phishing code is mainly used for verifying email authenticity, not app notifications.
Once you've set up your anti-phishing code, go turn on your withdrawal address whitelist and Google Authenticator 2FA too. This three-piece combo forms the security baseline for every Binance account — none of them are optional.