
Set a private, recognizable phrase inside the official account. When an email arrives, check the code, sender domain and link destination. Confirm the claimed event in your account or through official support. Do not click when any signal conflicts.
What does an anti-phishing code prove?
The anti-phishing code described in Binance’s account-security guide helps distinguish mail using your account setting from generic impersonation. It is not a cryptographic guarantee that the whole message is safe. Forwarded mail, compromised accounts and look-alike links still require attention.
Choose a phrase that is not your password, recovery answer or public nickname.
Where should you set or change it?
Use the security settings reached from a bookmarked official Binance page or app. Never set it through an email link. If the option is unavailable, consult the support page shown for your account.
Change the code if it has been exposed in a public screenshot or suspicious conversation.
What if an email has no code?
Do not act on the message until you verify the claimed event through the account or official support. Some service messages may follow different templates, but a missing expected code removes one useful signal.
Open Binance independently and review any related notifications or support messages. If you cannot confirm the event, do not act on the email; keep it for reporting when appropriate.
Can an email with the right code still be dangerous?
Yes, so check the sender and destination as well. Never reveal a password or one-time code through a link. Hover or inspect the actual URL and be alert to punycode, added words and unfamiliar subdomains.
If the event is unclear, ask official support through the account reached independently before acting.
How should you handle urgent security mail?
Urgency should slow you down, not speed you up. Do not call numbers in the message, scan an attached QR code or install a “security update.” Secure the email first if you suspect compromise.
Use the official account or support bookmark. Real support does not need a seed phrase, private key or authenticator backup.
What should you preserve when reporting phishing?
Keep the sender address, headers, destination URL and time without opening attachments. Submit them through the reporting route listed by the platform or your email provider. Remove unrelated personal information.
If credentials were entered, change them from a trusted device, terminate sessions and review withdrawals and API keys immediately.
How can you test the code without trusting an email?
Change the phrase from the signed-in security settings, then wait for a routine platform message that you can independently confirm. Never trigger a withdrawal or disclose account data merely to create a test. If the new phrase appears, it confirms the setting is being used for that message type; it does not certify every link or attachment.
Keep the phrase memorable to you but useless as an authentication secret. A code that contains your password fragment, recovery answer or public handle can weaken other safeguards if a message is exposed.