Email Scam Checker Email Scam Checker
Feature

Anti-Phishing Codes: Verify Email From Your Bank or Exchange

Record the secret phrase your provider puts in every real email. A wrong code beside the label is critical; a match is a green light.

Anti-Phishing Codes: Verify Email From Your Bank or Exchange
P

Pavel Demidovich

Developer and Founder of Email Scam Checker

In short

An anti-phishing code is a short phrase you agree with a service - a bank, a crypto exchange, an email provider - and that the service then prints in every genuine email it sends you. It is a shared secret, and that is the whole point: a scammer who copies the layout, the logo and the legal footer cannot copy a phrase they have never seen. Record your phrases once in the extension, and it will check every message that carries a code label against them.

  • Each code belongs to one service, and you can record as many as you use - one entry per provider.
  • If a message carries the code label and the phrase beside it is not yours, that is a critical finding, and a critical finding means Scam.
  • If it matches, the message gets a green confirmation and a credit against its risk score.
  • Codes live in your browser's own storage. The one exception is a labelled code in a scanned email: all the phrases you set are recorded when it does not match, and the matched phrase when it does, so the panel can show you what was expected.

Why a secret phrase works

Almost every other signal in the extension is a judgement call. A lookalike domain is strong evidence but not proof. Urgency language appears in real invoices every day. A mismatched link is damning right up to the moment a legitimate mailing platform wraps its links. Each of those checks produces a probability, and a verdict is what you get when enough of them agree. The anti-phishing code is the exception. It is not an inference about a sender's intent; it is a fact about whether the sender knows something that only the real service and you could know.

That asymmetry is what a phisher cannot work around. Copying the branding of a bank costs nothing - the logo, the typeface, the footer, the unsubscribe link are all public. The phrase is not public. It was chosen by you at the provider and shown to nobody else, so a message that claims to be from that provider, carries a code label, and carries the wrong phrase is not merely suspicious. It is a message that demonstrably does not come from them. Filters, blocklists and lookalike detection all try to infer intent from how a message is built. This checks one fact that design cannot fake.

It cuts the other way too, which is what makes it useful rather than merely alarming. Almost every other check can only add risk to an email. A matching code is a positive signal: a credit that lowers the score, on the reasoning that a message holding a genuine shared secret has passed a test no forgery passes. It is not a blanket clearance, since a message can carry your real code and still be a mass mailing, and the code does nothing to excuse a suspicious link elsewhere in the same email. Other signals can lower a score too. None of them, though, rests on the sender knowing a shared secret, and that is what makes this one different in kind.

Setting up a code

There are two steps, and the order matters: the phrase has to exist at the provider before the extension can be told about it.

First, set the code where it is offered. At a crypto exchange this is normally under the security settings, described as an anti-phishing code or an anti-phishing phrase; at an email provider it may be called a security phrase or a personal code. Whatever the label, the mechanism is the same: you type a phrase, save it, and from then on the service includes it in the messages it sends you. Pick something that is neither guessable nor derived from your other details. A phrase built from your name, your birthday or a variation on your usual password adds no protection at all, because a scammer who already has those things can guess it.

Second, record it in the extension. Open the popup and go to the Anti-Phishing Codes section, then add a service: give it a name you will recognise - Binance, Gate, Proton Mail - and enter the phrase exactly as you set it at the provider. Save, and the entry joins the list. You can add as many services as you use, and each keeps its own label and phrase, so the entries stay readable as the list grows.

Editing and removing work the same way. Open an entry to change the phrase and save it, or remove the row entirely if you stop using the service. Because the extension reads your codes from storage each time it handles a message and re-checks its cached verdict against them, an edit takes effect on the next message you open. One piece of housekeeping follows from that: if you change a phrase at the provider without updating it here, mail that is genuinely from them will be flagged as a mismatch until you do. It is the only maintenance this feature asks for, and it is worth doing the same day.

What the extension does with it

The check only runs if you have recorded at least one code. With nothing saved there is nothing to compare against, and no anti-phishing finding is ever produced.

With codes saved, the extension reads through the message looking for the label phrasings providers use for this feature: the words anti-phishing code and its close variants, and the phrase-based labels such as security phrase and personal code. If none of them appears, this check has nothing to judge and stays silent. The silence is deliberate. The feature is optional at the provider, so a message that never carried a code is not treated as suspicious for the absence. What the check always compares is a labelled code against your recorded phrase; a message with no label never reaches that comparison at all.

When a label is found, the extension reads the text immediately after it - a short window of about 200 characters, stopping at the end of the paragraph - and compares that with the phrases you recorded. Reading only that window is what stops one service's phrase from matching a stray line in an unrelated message, and it is why a code sitting in a newsletter footer elsewhere in the body is ignored.

Then one of two things happens.

  • The phrase matches. The message carries a green confirmation that it contains your personal anti-phishing code and was genuinely sent by your provider. The finding counts in the email's favour, subtracting 10 points from its risk score.
  • The phrase does not match, or nothing follows the label at all. That is a critical finding, the heaviest severity the engine has. A critical finding produces a Scam verdict on its own, however the rest of the message reads and whatever the AI deep scan makes of it.

The check works from the label in the message rather than from the sender, so what a provider needs to offer for this to be useful is a phrase that arrives in the same form every time, next to one of the usual labels. For how severity maps to the verdict, and why a critical finding cannot be argued down, see heuristic scanning.

Which services this covers

Anti-phishing codes are most common where impersonation is most profitable. Crypto exchanges were the early adopters: Binance, Coinbase and Gate all offer them, and mail from those services is expected to carry your phrase. Proton Mail offers the same feature to its users, and other banks, brokers and email providers run their own versions of it under a different name.

The extension is not limited to a list of supported brands. Any service whose code system works the way described here can be recorded, because the check reads the message rather than consulting a directory. What it needs from a provider is a phrase that arrives the same way each time, next to one of the recognised labels.

If a provider does not offer codes, the check simply never fires for their mail, and nothing about that absence is held against them. That is the honest limit of the feature. It can confirm a message from a service that uses codes, and expose one that pretends to, but it stays quiet about the service that never joined in.

Final verdict

The anti-phishing code is the rarest thing in email security: a signal that is not a guess. Every other check weighs evidence and accepts that it might be wrong, which is why their verdicts are calibrated and why a false alarm is always possible. This one asks whether the sender knows a secret. Set-up is small - a phrase configured at the provider, an entry in the popup - and it helps only at the handful of services that offer it, but where it applies it turns a judgement call into a fact in both directions, and where it does not apply it costs nothing.

To see how this fits the rest of the engine, read how Email Scam Checker works.

Frequently asked questions

It is a short personal phrase that a service - a bank, a crypto exchange, or an email provider - includes in every legitimate email it sends you. Because only you and they know it, an email that claims to be from them but does not carry it is not from them.

They are most common at crypto exchanges such as Binance, Coinbase and Gate, and at Proton Mail. Any service that lets you set one can be recorded in the extension.

Open the extension popup, go to the anti-phishing code manager, and add an entry for the service with the phrase you configured at that service. You can edit or remove entries at any time.

A mismatch is treated as a critical scam signal. If a message carries an anti-phishing code label but the code is not the one you recorded, that is about as unambiguous as a phishing signal gets.

You get a green confirmation that the message was genuinely sent by your provider - a positive signal that counts in the email's favour.

In your browser's own storage. The one exception is a labelled anti-phishing code in a scanned email: the phrases you recorded leave your browser with it, all of them when the code does not match and the matched one when it does. That is written to the email's scan record - a private record tied to your installation - so the panel can show you what was expected.

Deep-dive guide

This page covers what the feature does and when it fires. For the longer walkthrough, read How Email Scam Checker Works: Inside the 28 Checks That Detect Phishing and Scams .

Other features