Definition
An anti-phishing code is usually a recognizable text string configured in account security settings. A service inserts it into certain messages so the user can compare the displayed marker with the one they chose. It is different from a one-time login code and should not be used as the account password. Availability and message coverage depend on the provider.
How It Works
The marker can help identify crude imitations that omit it or display the wrong value. However, it is not a digital signature and does not cryptographically authenticate the entire message. Someone who sees a legitimate message may copy the code into a fraudulent one. A message may also contain a real code while misleading the recipient about why an action was initiated.
Key Considerations
Treat the code as an additional clue, not definitive proof. Check the sender, destination domain and requested action independently. Navigate to the known application or saved website instead of following unexpected links, especially when a message asks for credentials or urgent transfers. A missing code warrants caution, but the meaning depends on which message types the service actually supports. If the code is exposed, update it through the trusted account interface and review other account-security signals.