Deep dive · SC-07 · Fake official email

That email from "Binance" — real or fake? An anti-phishing code settles it

It says your account needs verifying, a withdrawal has been blocked, an unknown device just signed in. Below it sits a red "Resolve now" button. The layout, the logo, the tone all match the real thing. The catch is this: how do you actually know it came from Binance? The sender name proves nothing — that part can be faked.

A phishing email disguised as official Binance mail, with the spoofable sender name and a suspicious link marked out
Chain Scam Index · fake official email and phishing mail specimen

What a fake email looks like

Phishing email doesn't win by being crude. Quite the opposite: today's fakes are polished. Binance's black-and-yellow palette, the official logo, the small-print disclaimer in the footer — all copied across. Where it actually goes for you is your emotions: it wants you tense and rushing to "resolve this right now".

The scripts are a handful of familiar ones. A "security alert" claims an unknown device has signed in and asks you to click and confirm it was you. An "account verification" notice says a policy update means you must re-verify your identity or be restricted. A "withdrawal blocked" message says a withdrawal is being processed and to click here to cancel it if it wasn't you. And there are fake system notices about "rewards credited" or "KYC about to expire".

What they share is that they all push you toward the same single act: click the button, land on a page that looks like Binance, and type in your password and verification code. That page isn't Binance — it's a phishing site the scammer built, and the moment you type, your account is theirs.

Urgency is the engine of a phishing email. Any message that makes you feel "something bad happens if I don't click now" deserves a pause. A real account problem will show up when you open the official app yourself or go in from your bookmark — you never need the button inside that email.

Why the sender name can't be trusted

Plenty of people judge an email by glancing at the sender first. They see "Binance" or "Binance Official Team" and let their guard down. That's exactly the blind spot.

An email's display name — the line you see in your inbox list — is a separate thing from the actual sending address. The display name can be set to anything; a scammer can write "Binance Security" or "Binance Support Centre" just as easily. Even if you expand it and see something resembling @binance.com, it could be a look-alike domain spelled with near-identical letters, or the sending side could be forged (the term is spoofing), and the naked eye won't catch it cleanly every time.

So the conclusion is plain: don't treat "the sender looks right" as a reason to trust the email. The sender field is the easiest part for an attacker to tamper with. Reliable judgement rests on the next two things — the anti-phishing code, and checking a link's real address.

What an anti-phishing code is, and how to set it

The anti-phishing code is a genuinely useful Binance feature, and the idea behind it is reassuringly simple: in your account settings you choose a string of text or numbers only you know, and once it's set, every email Binance officially sends you carries that code inside it.

That makes the call clean. An email claiming to be from Binance that contains your anti-phishing code might be real; one without the code, or with the wrong code, can be deleted as phishing on the spot. A scammer can't know the code you set privately, so they can't fake it. We consider this one of the first security switches a newcomer should turn on.

Roughly how to set it

Go to the security-settings area of your Binance account, find the "anti-phishing code" item, and create a code you'll remember but others can't guess — not your birthday, not your account name, nothing easy to associate with you. After it's set, it will appear at the top of, or somewhere prominent in, the notification emails that come from the official side.

Worth flagging: Binance's interface, menu names and their locations can shift between versions, so this page doesn't pin down a step-by-step menu path. Go by the official page you actually see after logging in, and when in doubt cross-check against the Binance help centre.

Once your anti-phishing code is set, build a habit: every time a "Binance" email arrives, look for your code first. If it's not there, don't read on and certainly don't click any button. That one move blocks the vast majority of impersonation emails.

Hover over a link to see its real address

A button or blue link text in an email can show one thing and point somewhere completely different. The text reads "binance.com" but clicking sends you to another domain — in phishing email, that's standard practice.

On a computer there's a free, effective habit: move your cursor over the link without clicking, and your browser or mail app will surface the link's real address in the bottom-left corner, or beside the cursor. If that address isn't a familiar official domain — if it's a jumble of unfamiliar letters, an odd subdomain, or has "binance" buried in the middle of a long string — leave it alone.

On a phone there's no "hover", so previewing is harder, which is why the next rule matters even more on mobile: simply don't click. If you want to check whether an address is clean, paste it character by character into our look-alike domain checker to set it side by side with the official domain and see whether letters have been swapped or a tail added. More on what fake addresses look like and how to spot them is in how to spot a fake exchange.

Never click the link in the email — go in from your bookmark instead

After all those spotting techniques, there's one rule that's easier and harder to get wrong: however real the email looks, never log in through the link inside it. Go to the official site yourself from your bookmark, or open the official app to check.

The logic runs like this. If the email is genuine and your account really has a problem, you'll see that notice just the same when you log in from your bookmark — you won't miss it. If the email is fake, you never touched the phishing link, so you can't be caught by it. In both cases "walking in yourself" is the right move, and that habit alone strips a phishing email of most of its bite.

So do one thing now: add the Binance site to your browser bookmarks, and from now on only ever log in by clicking that bookmark. Why the bookmark matters so much, how to set it, and how to tell at a glance whether an address is right — we go into that in detail in the golden rule of logging in from a bookmark.

  • Look for the anti-phishing code first: no code, and the email is already a problem.
  • Don't trust the sender name: that field can be faked, so reading it is no help.
  • Hover to see the real address: the text and the actual destination often differ.
  • Don't click links in the email: to log in, go in from your bookmark or open the official app.
  • Don't enter your password or codes on a page the email sends you to: above all, never enter your seed phrase or private key. No official email ever asks for these.

Reading a phishing email line by line

It helps to slow down and take a suspicious "Binance" email apart one field at a time. Most fakes survive only a quick glance; under a careful read, something almost always gives. Here is the order to read in, from the part attackers find easiest to fake to the part they can't.

The sender: read the address, not the name

Start at the top, but don't stop at the friendly name. The bit your inbox shows in bold — "Binance", "Binance Official Team" — is just a label the sender typed in, and they can type anything. Tap or click to expand it and read the actual address, the part after the @. That domain is what matters. A real domain ends cleanly, like @binance.com. The tells are the near-misses: binance-support.com (a hyphen turning "binance" into a subword of a domain the scammer owns), or binance.security-team.com (where the real registered domain is security-team.com and "binance" is just a label stuck on the front). Read these right to left — the last two parts before the slash are the part nobody can fake without owning that domain.

One honest caveat, so you don't lean on this alone: a sending address can be spoofed, which means a fake email can sometimes show a perfect @binance.com and still be a fraud. So reading the address is necessary but not sufficient. A wrong-looking domain proves the email is bad; a right-looking one doesn't prove it's good. That's exactly why the next check carries the weight.

The anti-phishing code: the part the scammer cannot supply

Everything above can be copied or faked. Your anti-phishing code can't, and the reason is worth understanding rather than just trusting. The code is a private string that exists in two places only: your account settings, and the genuine emails Binance generates for you. A scammer mass-sending fake mail has no way to read what you set, so there is nothing for them to paste in. They can copy the logo, the colours, even the sending address — but the one field that depends on a secret they don't hold, they have to leave blank or guess at.

So read a "Binance" email looking for your code, and let the result decide. The code present and correct: the email is very likely genuine. The code missing, or a different string sitting where it should be: delete it, it's phishing, and you don't need to study any other field. A guess is worse than blank, because it tells you the sender tried and failed. The protection only holds if the code is genuinely unguessable, so don't set it to your name, your nickname, your birthday, or anything someone could pull off your social profiles — pick something with no link to you. And it shows up in real official mail, near the top or in a prominent spot, which is the whole point: you're meant to find it at a glance before you read a word of the body.

The button: hover for the destination, long-press on a phone

The visible text on a link lies freely. A button can read "Log in to binance.com" and carry a destination pointing somewhere else entirely. On a computer, rest your cursor on the button without clicking and read the real address your mail app or browser shows at the corner of the screen — judge that, not the words on the button. On a phone there's no cursor, so press and hold the link instead: a preview panel opens showing where it actually goes, and you can read it and then cancel without ever loading the page. Either way you're checking the same thing — does the real destination land on the official domain, or on something dressed up to look like it.

The subject line: fear is the trigger

Look back at the subject with fresh eyes, because it was written to get you moving before you think. "Account suspended." "Unauthorised login detected." "Withdrawal pending — cancel now." Each one manufactures a small emergency and offers the click as the way out, betting that a jolt of fear shortens the gap between reading and clicking. Treat that pressure as a signal in itself. A real problem with your account doesn't expire in the next sixty seconds, and it'll still be waiting for you when you open the site yourself. The more a subject line insists on now, the more it's worth slowing down.

The small tells: greeting, attachments, QR codes

A few more fields reward a second look:

  • The greeting. Bulk phishing often opens generically — "Dear user", "Dear customer" — because the sender is firing at a list and doesn't know your name. A specific greeting isn't proof of safety (a targeted attacker can learn your name), but a vague one alongside an urgent demand is a fair reason to distrust the whole message.
  • Attachments you didn't ask for. A "statement", an "invoice", a "security report" arriving as a file you never requested is a classic delivery method for malware or a fake login form. Genuine account notices live on the site, not in a file you have to open.
  • QR codes in the body. A newer move is to drop the malicious link inside a QR code image instead of a clickable link. The image dodges link scanners that read text, and it pushes you onto your phone's camera — away from the desktop where hovering is easy. A QR code in an email asking you to scan and log in deserves the same suspicion as any link, and more.

What real Binance emails never do

Knowing the boundary makes the fakes stand out. A genuine official email will not ask you for your password, your two-factor code, or your wallet's seed phrase — there is no legitimate reason for an email to collect any of these, and a request for them is itself the scam. It won't tell you that the only way to keep your account is to click an emailed link and "verify" through it. Real notices inform you; they don't herd you down a single link under threat. If an email is doing the herding, that's your answer.

And the habit that ties all of this together: don't act from the email at all. However the fields read, close it, open the official site from your own bookmark or the official app, and check your notifications there. If something genuinely needs your attention, it'll be waiting on the inside — and if it isn't, you've spent nothing but a moment.

We checked a few emails

We laid out a few of the "Binance" notification emails we'd received ourselves and ran them down the anti-phishing-code line. Once the code is on, a genuine official email carries the string you set — and that's the easy one: instead of squinting at whether the sender address has an extra letter, you just check whether the code is there. The setting lives in account security settings, and Binance's interface shifts with versions, so rather than memorising which submenu it's under, remember which line to look at. We don't hard-code the path below — go by the official page you see after logging in.

Treat this page as a checklist. When you're vetting an email that claims to be from Binance, keep your eyes on three columns. First, does the email contain the anti-phishing code you set? No code means high suspicion. Second, when you hover over the button or link, is the real address the official main domain? Third, is the email pushing you to act "right now, immediately, or else"? That urgency is itself the step to be most wary of. If any one column is off, don't click — go in from your bookmark and check for yourself.

FAQ

I already clicked the link and typed my password on the page. What now?

Treat the account as compromised. Go to the real site from your own bookmark, change your password, check and reset two-factor authentication, and review your login devices and withdrawal whitelist for changes. If you've already lost funds, follow the first steps after a scam to preserve evidence and report it.

If I set an anti-phishing code, could a scammer guess it?

The code lives only in your account settings and in genuine emails Binance sends you. A scammer sending a fake email doesn't know what you chose, so they can't reproduce it. The condition is that you don't set it to something easy to associate with you, like a birthday or nickname, and that you tell no one.

What about links in text messages or app notifications?

Same rule. Don't log in through a link in a message; go in yourself from your bookmark or the official app. Impersonation isn't limited to email — SMS and direct messages are just as common, and the reasoning doesn't change.

2026-06-22 · Entry created, covering how to spot fake emails and how to set an anti-phishing code.