New users frequently receive emails signed "Binance." Mixed in among them are plenty of phishing emails — if you fall for one and click the link, your account password gets intercepted. This article gives you a five-step method to spot phishing emails. If you want to check whether your account currently has an anti-phishing code set, you can log into the Binance Official Site and check the "Account Security" page; mobile users can set it in the same place inside the Official Binance App; iPhone users should check the iOS Installation Guide.
Binance sends official emails from exactly three domains:
Any "Binance email" that doesn't come from one of these three domains is fake. Common forged domains include:
Go to Account Center > Security > Anti-Phishing Code and set a string of 4-20 characters. Once enabled, this string appears in the subject or body of every official Binance email. Any "Binance email" without the anti-phishing code is fake.
Setting an anti-phishing code adds no risk. We recommend a string that only you can remember and that doesn't appear anywhere else.
In your email client, open "show full sender" and compare it against the three official domains above. Note: the display name alone ("Binance") can be forged — you must check the domain after the @ symbol.
Hover your mouse over a "log in" or "verify" link in the email, and your browser or email client will show the actual destination. The link must start with https://www.binance.com, https://accounts.binance.com, or https://binance.cc.
Any domain containing "-login," "-verify," "-help," or an underscore is phishing. For example, https://binance-verify.com or https://login-binance.com.
Advanced users can check the SPF, DKIM, and DMARC verification results in the email header. Official Binance emails show PASS on all three. If any one of them shows FAIL, the sender failed domain verification and the email is very likely forged.
The way to view this differs by client: Gmail uses "Show Original," Outlook uses "View Source," and QQ Mail uses "Original Message."
If the email says "you logged in at X time" or "a withdrawal was requested," immediately log into the Binance Official Site and check the "Account Activity" page against your actual login and withdrawal history. If there's no matching record in your account, the email is fake.
The table below lists the most common phishing email types and typical wording seen in 2025-2026.
| Type | Typical Wording | Real Goal |
|---|---|---|
| Account freeze | "Your account will be frozen due to risk, please verify immediately" | Steal your login password |
| Withdrawal confirmation | "You requested a withdrawal of 5 BTC, click to confirm or cancel" | Get you to click a fake "cancel" link |
| Fiat deposit | "Your bank card has been credited 5,000 USD, please confirm" | Get you to log into a fake Binance account |
| Mandatory KYC update | "Regulators require you to resubmit your ID" | Steal photos of your ID document |
| Limited-time event | "Limited-time airdrop of 0.5 BTC, click to claim" | Get you to authorize your wallet |
| Support follow-up | "Your ticket has been resolved, please review" | Steal your login credentials |
| 2FA re-verification | "Your Google Authenticator is about to expire, please re-bind" | Get you to type your 2FA code for the attacker |
Don't click any more links in the email. Close your email client and don't reply.
Open the Binance official site from your browser bookmark or a trusted entry point like this site, then log in and immediately change your password.
Go to the "Account Activity" page and check whether there's been a login from an unfamiliar location, a withdrawal request, or an API key creation in the past 24 hours. If you see anything abnormal, freeze your account immediately.
Go to Account > Security > Two-Factor Authentication and reset Google Authenticator. Your original Authenticator becomes invalid immediately, and any device that relied on it needs to re-bind.
Submit a ticket through the support icon on the official site, choosing "Account Compromised" as the category, and attach a screenshot of the phishing email with its timestamp. Binance's risk control team will review it manually.
Below is an example of the header section from a real Binance email (not a complete reproduction):
Authentication-Results: spf=pass (sender IP is xxx.xxx.xxx.xxx)
smtp.mailfrom=post.binance.com;
dkim=pass (signature was verified)
header.d=binance.com;
dmarc=pass action=none header.from=binance.com;
Return-Path: <bounce@post.binance.com>
From: "Binance" <do-not-reply@post.binance.com>
In a phishing email, you'll see something like this instead:
Authentication-Results: spf=fail
dkim=none
dmarc=fail
Return-Path: <attacker@anyhost.tk>
From: "Binance Team" <support@binance-help.com>
If spf, dkim, or dmarc shows fail on even one of them, the email is forged.
Email clients by default only show "Binance" as the display name. Phishers set their sender display name to "Binance Security," but the actual address is attacker@xxxx.tk. You have to open the full sender info to see the real address.
The link text displayed reads https://www.binance.com, but the actual href points to https://binance-help.com. Hovering over or long-pressing the link reveals the real destination.
The entire "log in" button is actually an image, and clicking the image redirects to the phishing site. Prevention: don't automatically display external images — only load them when needed.
The letters l (lowercase L), I (uppercase i), and 1 (the digit one) are easily confused. For example, in "binаnce.com," the а is actually a Cyrillic character that looks identical to the Latin letter a.
The simplest and most effective step. Once enabled, forged emails can't insert the correct anti-phishing code into the subject or body.
Register an email address used only for Binance, nowhere else. That way, any "Binance email" from a non-Binance sending domain is immediately suspicious.
Even if your password is stolen, an attacker can't log in without your 2FA. Even if they can log in, they can't withdraw to an unfamiliar address without your whitelist.
Delete any unused API keys right away. With IP restriction enabled, even a leaked key can only be used from your specified IP.
Official Binance announcements live at binance.com/en/support/announcement. Any major policy change is always published there first — email is just a supplementary notice.
Q: If an email comes from @post.binance.com, is it 100% real? The header must pass SPF, DKIM, and DMARC verification to be confirmed. Looking only at the From field isn't enough, since it can be spoofed (though it's much harder to do now, the risk isn't zero).
Q: Can I show my anti-phishing code to someone else? Your anti-phishing code is essentially an "email password" — don't reveal it to anyone. Even Binance support will never ask you for it.
Q: Why do genuine Binance emails sometimes get marked as spam? Different email providers apply different anti-spam policies to sending domains. We recommend whitelisting @post.binance.com and @directmail.binance.com.
Q: How do I view the full sender on my phone? On iOS Mail, tap the sender's name to expand the full address; on the Android Gmail app, tap the arrow below the email subject to expand it.
Q: An email says "your assets are about to be frozen, please provide additional documents" — is this real or fake? This wording is 99% phishing. Binance never asks for "additional documents" by email — KYC updates are always prompted inside your account, never handled through an email link.
Q: How much time do I have to recover after being phished? Recovery odds are highest within the first hour. Immediately changing your password, resetting 2FA, and freezing your account can prevent an attacker from completing a withdrawal in time.