Anti-Phishing Code

Last Updated Sep 24, 2026

In One Sentence

An anti-phishing code is a user-chosen marker that a service includes in supported communications to help recipients recognize expected messages.

Definition

An anti-phishing code is usually a recognizable text string configured in account security settings. A service inserts it into certain messages so the user can compare the displayed marker with the one they chose. It is different from a one-time login code and should not be used as the account password. Availability and message coverage depend on the provider.

How It Works

The marker can help identify crude imitations that omit it or display the wrong value. However, it is not a digital signature and does not cryptographically authenticate the entire message. Someone who sees a legitimate message may copy the code into a fraudulent one. A message may also contain a real code while misleading the recipient about why an action was initiated.

Key Considerations

Treat the code as an additional clue, not definitive proof. Check the sender, destination domain and requested action independently. Navigate to the known application or saved website instead of following unexpected links, especially when a message asks for credentials or urgent transfers. A missing code warrants caution, but the meaning depends on which message types the service actually supports. If the code is exposed, update it through the trusted account interface and review other account-security signals.