
Participant: your anti-phishing phrase
Set a phrase that appears in every genuine email the platform sends you — so telling a real message from a fake one is one thing to check, not a judgement call.
Overview
You will receive emails from the platform: requests for documents, for signature, for payment. How do you know they are genuine?
An anti-phishing phrase is a phrase you choose, which the platform then includes in every genuine email it sends you.
"Once configured, your anti-phishing phrase will be included in all genuine emails we send you."
So the rule is simple:
Your phrase is present → the email genuinely came from the platform.
Your phrase is missing → treat the email as suspicious, however convincing it looks.
For anyone being asked to hand over identity documents and bank details, that is the single most useful control available to you. Set it as soon as your account exists.
Steps
Open your profile and go to the security section, Anti-phishing phrase.
Enter a phrase you will recognise.
Save.
From then on, check for it at the top of every email you receive from the platform.
Choosing a phrase
Pick something you would notice the absence of. A phrase you recognise instantly beats a clever one.
Do not reuse a password, and do not use anything that is itself a credential.
Avoid something a stranger could guess about you from public information — the value lies in an attacker not knowing it.
Short is fine. It only has to be recognisable.
It does not need to be secret in the way a password does. It needs to be yours.
What to do if the phrase is missing
Do not click any link in the email, and do not reply to it.
Go to the platform directly, sign in, and check whether the task the email describes actually exists on your dashboard. If it does not, the email was not genuine.
That is the practical payoff: instead of judging whether an email looks right, you have one thing to check.
Related
B1.1 — Participant: why you received an invitation · the wider context for trusting a request
B1.2 — Participant: creating your account and signing in · set the phrase here, at the start
B1.3 — Participant: your dashboard · where to verify a task really exists
B1.7 — Participant: making your payment · the request most worth verifying
Tutorial details
3 mins
Procedure
In this course