What Is an Anti-Phishing Code and How to Use It
An anti-phishing code is a custom phrase exchanges insert into genuine emails so you can instantly spot fake phishing messages. Here's how to set it up.
An anti-phishing code is a custom word or short phrase you set in your exchange account settings that the exchange then automatically includes in every genuine email it sends you, giving you a simple way to tell real communications apart from phishing attempts, since a fake email created by a scammer has no way of knowing or inserting your personal code.
Why this feature exists
Phishing emails impersonating exchanges are one of the most common attack vectors in crypto, often near-perfectly replicating an exchange's logo, formatting, and sender name. Visually, a well-crafted phishing email can be almost indistinguishable from the real thing to a quick glance. An anti-phishing code solves this by adding a piece of information a scammer cannot possibly know or fake: something only you and the exchange's actual systems share.
How it works step by step
- In your exchange account's security settings, find the anti-phishing code (sometimes called "security phrase" or similar) option.
- Set a code — ideally something memorable to you but not guessable by others, and not something you've used publicly elsewhere.
- From that point forward, every automated email genuinely sent by the exchange (login alerts, withdrawal confirmations, marketing, password reset notices) includes your code somewhere in the email body.
- When you receive any email claiming to be from the exchange, check for your code. If it's missing, altered, or the email doesn't include it at all, treat the email as fraudulent regardless of how convincing it otherwise looks.
What the code protects against — and what it doesn't
| Scenario | Does the anti-phishing code help? |
|---|---|
| Fake email impersonating the exchange, sent from a lookalike domain | Yes — the fake email won't have your correct code |
| Fake exchange website (clone site) you're tricked into visiting directly | No — this is a website issue, not an email issue; verify domains separately, see fake exchange scams |
| Compromised exchange account sending you real-looking security alerts | No protection needed here — if it's genuinely from the exchange, your code will correctly appear |
| SMS or phone-call-based phishing | No — the code only applies to email; different defenses are needed for other channels |
| An attacker who has already stolen your code somehow | Reduced — treat the code like a piece of security information, not something to share |
The key limitation to understand: the anti-phishing code only verifies email authenticity. It says nothing about whether a website you're visiting is the real exchange or a clone — that requires separately checking the domain, as covered in our guide on how to verify a crypto exchange is legitimate.
Best practices for choosing and protecting your code
- Don't reuse a code you use for anything else publicly — a code that appears in your social media bio or elsewhere loses its verification value.
- Don't share it with anyone, including anyone claiming to be exchange support asking you to "confirm" it — legitimate support already has it on file and would never need you to state it back to them.
- Check it every time, not just when something feels suspicious — building the habit of glancing for the code on every exchange email makes the one time it's missing far more likely to register.
- Set it immediately upon opening any new exchange account, rather than leaving it as an afterthought once you already suspect a problem.
Combining this with other defenses
An anti-phishing code is one layer in a broader account security setup. It works best alongside hardware-based two-factor authentication, withdrawal address whitelisting, and careful domain verification — see our complete guide on how to secure your crypto exchange account for the full picture. On its own, the code only addresses email-based impersonation; a comprehensive security posture needs to cover website spoofing, credential theft, and withdrawal protections as well.
Why this matters given how convincing modern phishing has become
Phishing kits have grown sophisticated enough to replicate exchange branding, sender formatting, and even realistic "urgent security alert" framing almost perfectly. Relying on gut instinct ("does this look official?") is no longer a reliable filter. An anti-phishing code converts an easily-faked visual judgment into a simple factual check: is my code present, and is it correct? This removes the guesswork entirely and takes only a few seconds to check on any email you receive.
Bottom line
An anti-phishing code is a free, simple feature that turns "does this email look legitimate?" into a fast factual check that scammers cannot replicate without knowing your specific code. Set it immediately on every exchange account you use, check for it on every email claiming to be from that exchange, and remember it only covers email — pair it with domain verification and the broader account security steps in our exchange security guide for full protection.
Related articles
This article is for educational purposes only and is not financial advice. DeFi involves significant risk, including total loss of funds. Always do your own research.