New users frequently receive emails signed "Binance." Mixed in among them are plenty of phishing emails — if you fall for one and click the link, your account password gets intercepted. This article gives you a five-step method to spot phishing emails. If you want to check whether your account currently has an anti-phishing code set, you can log into the Binance Official Site and check the "Account Security" page; mobile users can set it in the same place inside the Official Binance App; iPhone users should check the iOS Installation Guide.

1. The Correct Senders For Official Binance Emails

Binance sends official emails from exactly three domains:

Any "Binance email" that doesn't come from one of these three domains is fake. Common forged domains include:

2. The Five-Step Verification Method

Step 1: Check The Anti-Phishing Code

Go to Account Center > Security > Anti-Phishing Code and set a string of 4-20 characters. Once enabled, this string appears in the subject or body of every official Binance email. Any "Binance email" without the anti-phishing code is fake.

Setting an anti-phishing code adds no risk. We recommend a string that only you can remember and that doesn't appear anywhere else.

Step 2: Check The Full Sender Address

In your email client, open "show full sender" and compare it against the three official domains above. Note: the display name alone ("Binance") can be forged — you must check the domain after the @ symbol.

Step 3: Check The Link

Hover your mouse over a "log in" or "verify" link in the email, and your browser or email client will show the actual destination. The link must start with https://www.binance.com, https://accounts.binance.com, or https://binance.cc.

Any domain containing "-login," "-verify," "-help," or an underscore is phishing. For example, https://binance-verify.com or https://login-binance.com.

Step 4: Check The Email Header

Advanced users can check the SPF, DKIM, and DMARC verification results in the email header. Official Binance emails show PASS on all three. If any one of them shows FAIL, the sender failed domain verification and the email is very likely forged.

The way to view this differs by client: Gmail uses "Show Original," Outlook uses "View Source," and QQ Mail uses "Original Message."

Step 5: Cross-Check Your Account Activity

If the email says "you logged in at X time" or "a withdrawal was requested," immediately log into the Binance Official Site and check the "Account Activity" page against your actual login and withdrawal history. If there's no matching record in your account, the email is fake.

3. Common Types Of Phishing Emails

The table below lists the most common phishing email types and typical wording seen in 2025-2026.

Type Typical Wording Real Goal
Account freeze "Your account will be frozen due to risk, please verify immediately" Steal your login password
Withdrawal confirmation "You requested a withdrawal of 5 BTC, click to confirm or cancel" Get you to click a fake "cancel" link
Fiat deposit "Your bank card has been credited 5,000 USD, please confirm" Get you to log into a fake Binance account
Mandatory KYC update "Regulators require you to resubmit your ID" Steal photos of your ID document
Limited-time event "Limited-time airdrop of 0.5 BTC, click to claim" Get you to authorize your wallet
Support follow-up "Your ticket has been resolved, please review" Steal your login credentials
2FA re-verification "Your Google Authenticator is about to expire, please re-bind" Get you to type your 2FA code for the attacker

4. Emergency Response If You've Been Phished

Step 1: Pause All Actions

Don't click any more links in the email. Close your email client and don't reply.

Step 2: Open The Real Binance Site From A Bookmark

Open the Binance official site from your browser bookmark or a trusted entry point like this site, then log in and immediately change your password.

Step 3: Check Your Account Activity

Go to the "Account Activity" page and check whether there's been a login from an unfamiliar location, a withdrawal request, or an API key creation in the past 24 hours. If you see anything abnormal, freeze your account immediately.

Step 4: Re-Bind 2FA

Go to Account > Security > Two-Factor Authentication and reset Google Authenticator. Your original Authenticator becomes invalid immediately, and any device that relied on it needs to re-bind.

Step 5: Submit A Ticket

Submit a ticket through the support icon on the official site, choosing "Account Compromised" as the category, and attach a screenshot of the phishing email with its timestamp. Binance's risk control team will review it manually.

5. Key Fields In An Email Header

Below is an example of the header section from a real Binance email (not a complete reproduction):

Authentication-Results: spf=pass (sender IP is xxx.xxx.xxx.xxx)
 smtp.mailfrom=post.binance.com;
 dkim=pass (signature was verified)
 header.d=binance.com;
 dmarc=pass action=none header.from=binance.com;
Return-Path: <bounce@post.binance.com>
From: "Binance" <do-not-reply@post.binance.com>

In a phishing email, you'll see something like this instead:

Authentication-Results: spf=fail
 dkim=none
 dmarc=fail
Return-Path: <attacker@anyhost.tk>
From: "Binance Team" <support@binance-help.com>

If spf, dkim, or dmarc shows fail on even one of them, the email is forged.

6. Common Disguise Tactics

Tactic #1: Display Name Spoofing

Email clients by default only show "Binance" as the display name. Phishers set their sender display name to "Binance Security," but the actual address is attacker@xxxx.tk. You have to open the full sender info to see the real address.

Tactic #2: Link Redirect Spoofing

The link text displayed reads https://www.binance.com, but the actual href points to https://binance-help.com. Hovering over or long-pressing the link reveals the real destination.

Tactic #3: Image Instead Of A Text Link

The entire "log in" button is actually an image, and clicking the image redirects to the phishing site. Prevention: don't automatically display external images — only load them when needed.

Tactic #4: Look-Alike Character Deception

The letters l (lowercase L), I (uppercase i), and 1 (the digit one) are easily confused. For example, in "binаnce.com," the а is actually a Cyrillic character that looks identical to the Latin letter a.

7. Reducing Your Risk Of Being Phished

Measure #1: Turn On Your Anti-Phishing Code

The simplest and most effective step. Once enabled, forged emails can't insert the correct anti-phishing code into the subject or body.

Measure #2: Register A Dedicated Email Address

Register an email address used only for Binance, nowhere else. That way, any "Binance email" from a non-Binance sending domain is immediately suspicious.

Measure #3: Turn On 2FA And A Withdrawal Whitelist

Even if your password is stolen, an attacker can't log in without your 2FA. Even if they can log in, they can't withdraw to an unfamiliar address without your whitelist.

Measure #4: Regularly Clean Up API Keys

Delete any unused API keys right away. With IP restriction enabled, even a leaked key can only be used from your specified IP.

Measure #5: Follow Official Binance Announcements

Official Binance announcements live at binance.com/en/support/announcement. Any major policy change is always published there first — email is just a supplementary notice.

8. Frequently Asked Questions

Q: If an email comes from @post.binance.com, is it 100% real? The header must pass SPF, DKIM, and DMARC verification to be confirmed. Looking only at the From field isn't enough, since it can be spoofed (though it's much harder to do now, the risk isn't zero).

Q: Can I show my anti-phishing code to someone else? Your anti-phishing code is essentially an "email password" — don't reveal it to anyone. Even Binance support will never ask you for it.

Q: Why do genuine Binance emails sometimes get marked as spam? Different email providers apply different anti-spam policies to sending domains. We recommend whitelisting @post.binance.com and @directmail.binance.com.

Q: How do I view the full sender on my phone? On iOS Mail, tap the sender's name to expand the full address; on the Android Gmail app, tap the arrow below the email subject to expand it.

Q: An email says "your assets are about to be frozen, please provide additional documents" — is this real or fake? This wording is 99% phishing. Binance never asks for "additional documents" by email — KYC updates are always prompted inside your account, never handled through an email link.

Q: How much time do I have to recover after being phished? Recovery odds are highest within the first hour. Immediately changing your password, resetting 2FA, and freezing your account can prevent an attacker from completing a withdrawal in time.