Spoofing: How Faked Caller IDs Work and How to Stay Safe
Spoofing fakes the sender identity on calls, email and text messages. Why the number on your screen proves nothing, and the one habit that reliably protects you.
Your phone rings and the screen shows your bank. Not a number you have to recognise, an actual contact entry with the name attached, because that number has been in your address book for years. A calm voice explains there is a problem with your account. The number is correct and the call may still be coming from a laptop on another continent, because that line of text can be forged. The technique is called spoofing, and it is the reason a displayed number proves nothing at all.
What follows starts with the mechanism: what the term covers and how a faked number actually arrives on your screen. Email and text messages get their own shorter sections, since the same idea works there. The bulk of the article is practical, because that is where it matters. How these calls give themselves away, the single habit that defuses almost all of them, and where to report what happened.
What is spoofing
The word comes from to spoof, to hoax or to imitate. In networking it means forging a sender identity so a connection appears to originate from a trusted source. Only the label is forged. The bank’s phone line, the tax office mailbox and the courier’s mail server are all untouched, and none of them has to be compromised for the deception to land.
The reason sits in the age of the protocols. Telephony and email grew up among a small set of operators who knew each other, in an era where verifying a claimed sender looked like a waste of expensive machine time. That assumption is still in the foundations, and every protection built since has been layered on top of it rather than replacing it.
In everyday life this shows up in three shapes. A call from a forged number does the most damage, because a voice can apply pressure in real time. Forged email is by far the most common, though the large providers now filter it fairly well. Text messages with a fake sender name sit between the two. There are further technical variants, such as forged IP addresses or poisoned name resolution, which matter when someone attacks infrastructure and almost never touch private individuals.
Caller ID spoofing: a stranger’s number on your screen
When a call is set up, the network passes a set of data fields alongside it, separate from the audio itself. One of them carries the caller’s number, known in the trade as Calling Line Identification and to everyone else as the caller ID. Your handset reads that field, matches it against your contacts and displays whatever it found. How the value got into the field is something the device cannot see.
That is where the forgery goes in. Calls injected into the traditional networks through internet telephony bring their sender identity along as a freely settable value. Businesses need that: a switchboard with three hundred extensions should present one central service number, and an outsourced call centre dials on behalf of its client and shows the client’s number. So the capability is a feature rather than a bug, and along the path to your handset it is barely checked.
Abusing it takes neither expertise nor real money. All it requires is access to a telephony provider that passes the sender identity through without asking hard questions about ownership, frequently based well outside the reach of the regulator whose numbers are being borrowed. Cost per call runs in fractions of a cent, dialling is automated, and the operator hangs up the moment somebody sounds suspicious. We are deliberately not naming providers or describing the setup. The point is a different one: because the effort is so small, a trustworthy number on your screen tells you nothing whatsoever about the person speaking.
Which numbers get displayed
Four patterns come round again and again, each aimed at a different reflex.
| Displayed number | Effect on the person called | Typical scam |
|---|---|---|
| your own bank | looks verified, often a saved contact | an intercepted transfer, a request for a code |
| a police or emergency line | instant authority | fake officers, your savings are “not safe” |
| your own area code | feels local and harmless, gets answered | call centres, prize claims, contract sales |
| your own number | confusing enough to be answered | advertising, groundwork for later calls |
Emergency numbers deserve a note of their own. Lines such as 999, 911 or 112 are built to receive calls, not to place them, so a police force will never appear on your screen under that number. Seeing it is already proof that the call is forged.
The same reasoning extends to officialdom in general. Courts, tax authorities and police work on paper. A summons arrives by post, an account freeze does too, and none of these institutions asks over the phone for cash, gold or valuables to be handed to a courier. When a call does exactly that, the question of authenticity has answered itself.
Email spoofing and SMS spoofing
Email works on the same principle and is, if anything, older. The From line your client displays is plain text in the message header, chosen freely by whoever sends it. It carries as much weight as a return address written on an envelope by hand.
Unlike telephony, the defences here have caught up considerably. Three mechanisms work together and are evaluated by every major provider:
- SPF publishes, in a domain’s DNS records, which servers are permitted to send mail for it. A message from anywhere else stands out.
- DKIM attaches a cryptographic signature to the message that can be checked against a public key in DNS. It shows the content arrived unaltered and really came from that domain.
- DMARC ties the two together and states what should happen to a message that fails: accept it, file it as spam or reject it outright.
For you as a recipient this means a crude forgery in the name of a well maintained domain usually never reaches the inbox. What is left are messages from lookalike domains, one letter swapped or a hyphen added, which pass every technical check because the attacker genuinely owns them. The display name is no help, since it is free text. Looking at the full address behind the name is worth the two seconds.
SMS spoofing replaces the sender number with text, the alphanumeric sender ID. It exists so companies can appear under their own name instead of a number, which is exactly what makes it useful for deception. When a forged message arrives under the same name as earlier genuine ones, many phones file it into the same thread, lending the fake the credibility of the real. The term for these messages is smishing, from SMS and phishing. One rule covers it: never tap the link, open the app or type the address yourself.
How to protect yourself from spoofing
Here is the part that counts. There is nothing you can improve about the display itself, because the forgery happens on the way to you, long before your device sees anything. What protects you is a small set of habits, and they work remarkably well.
Call back on the official number
This is the most important paragraph in the article. When a call wants something involving money, credentials or access, you end it and call back yourself. Not the number on the display, not the number the caller gives you, and not the redial button in your call log. The number on your bank card, on the official website, on an old statement, in the directory.
Why it works comes down to direction. A spoofed call travels towards you, and the forgery only functions that way round. When you dial, your network builds a connection to the line that actually holds that number. Nothing can be inserted in between.
Things that never happen on a real call
There is a short list of requests that legitimate organisations simply do not make. Knowing it means you never have to judge the story on its merits.
| The caller wants … | Legitimate organisations … | What you do |
|---|---|---|
| a one-time code or authentication token | never ask, under any circumstances | hang up |
| your password or PIN | never ask | hang up |
| remote access software installed | only for support you initiated yourself | hang up |
| a transfer to a “safe account” | no such thing exists | hang up |
| cash or valuables handed to a courier | never, least of all authorities | hang up, call the police |
| you not to tell anyone | never | hang up, talk to someone |
That last row deserves attention. The request for secrecy and the insistence that you stay on the line are not incidental, they are the method. They exist to stop you consulting a second person, because that conversation ends the scam almost every time.
Hanging up is allowed
Politeness is a lever, and it gets used. People raised not to interrupt stay on the line far longer than is good for them, and that is factored in. A call that applies pressure, sets you a deadline or threatens consequences can be ended without explanation. No legitimate matter collapses because you called back ten minutes later.
With older relatives it is worth having this conversation properly rather than leaving a leaflet on the table. The grandparent scam and the fake police officer routine now run almost entirely on forged numbers, which makes them far more convincing than the versions from a decade ago. A family code word and a second, independent call to the grandchild in question cost nothing and settle the matter in a minute.
What technology can contribute
A few tools help around the edges without solving the underlying problem. Modern handsets flag suspicious numbers, though doing so means sending numbers off to the vendor for checking. Landline routers can keep blocklists and reject withheld numbers. Two-factor authentication on your accounts means a password talked out of you over the phone is worth much less on its own.
At network level there is real progress. North America has deployed STIR/SHAKEN, a framework that cryptographically signs the caller ID when a call is injected and lets the terminating carrier check that signature. Results have been mixed but measurable. European regulators have imposed comparable duties on carriers to drop foreign calls presenting domestic numbers. Neither is something to rely on yet, because the gaps sit precisely where the abusive traffic enters.
We have looked at the other direction of this before. When you call anonymously you hide your own number rather than borrowing someone else’s. Both touch the same field in the signalling data. One is a free, legally guaranteed option available to anyone, the other is number misuse.
Reporting spoofing
Two kinds of authority matter here, and they do not exclude each other.
Your telecom regulator or national fraud reporting service handles number misuse. In the United States that is the FTC for the fraud and the FCC for the caller ID rules, in the United Kingdom Ofcom alongside Action Fraud, in Germany the Bundesnetzagentur, and most other countries have an equivalent. They can have numbers disconnected, bar carriers from billing and issue fines. Useful details are the date, the time, the number displayed and a couple of sentences about the call. Even when nothing happened to you, the report has value: regulators identify abuse by volume, and a single complaint is one data point in a pattern.
The police come in the moment there is a loss, meaning money transferred, credentials handed over or valuables collected. Most forces take reports online as well as in person. Call your bank at the same time, since transfers can occasionally still be halted in the first hours. After that the usual applies to evidence: screenshots of the call log, statements, notes on what was said, keep all of it.
What does not help is calling the displayed number back to give someone a piece of your mind. It almost always belongs to an uninvolved subscriber who is already having a rough week.
When your number is the one being used
That uninvolved subscriber can be you. Strangers start calling to complain about a call you never made, and some of them are not polite about it.
The important part first: your line has not been hacked. There is no access to your phone, no malware, no compromised SIM. Your number was written into a data field, which can be done from anywhere and never touches your device. It usually comes from a block being counted through automatically rather than from anyone choosing you.
Preventing it is largely impossible, which is the uncomfortable half. Having your number barred achieves nothing, because the abuse never runs through your line. What remains is a report to the regulator, a short factual voicemail greeting and some patience. These waves typically last days to a couple of weeks before the operator moves on to the next block. If it persists, carriers will change your number, though that carries its own cost, and how firmly a phone number works as a long-lived identifier is something we covered in our piece on digital identity.
What it comes down to
Spoofing is not a sophisticated attack. It exploits a trust assumption baked into our communication networks decades ago, one that cannot simply be removed because countless legitimate uses now depend on it. Email got a verification layer retrofitted in SPF, DKIM and DMARC, and it works reasonably well. Voice telephony is still waiting for its equivalent to arrive everywhere.
For you it collapses into one rule that is easy to remember and holds in every case. A number on a screen is a claim. When money, credentials or pressure are involved, you hang up and dial a number you sourced yourself, from somewhere nobody read out to you. That habit costs two minutes and outperforms every detection system currently on the market.
Frequently asked questions
- What is spoofing?
- Spoofing means faking a sender identity so that a message or a call appears to come from a source you trust. On the phone that identity is the displayed number, in email it is the from address, in text messages it is the sender name. Only the label gets forged. The account or line behind it stays untouched, which is exactly why the attack is cheap: nobody has to break into anything.
- How does phone spoofing work?
- The number your handset displays travels as a data field alongside the call setup, separate from the audio. Anyone who injects a call through an internet telephony provider can set that field to a value of their choosing, because the protocol treats it as a claim by the caller and the networks in between rarely verify it. That is how a bank, a police line or even your own number can appear on the screen while the call originates somewhere else entirely.
- How can I recognise a spoofed call?
- Not from the number, and that is the whole problem. What you can read is the shape of the conversation: an unexpected call from an organisation that normally writes to you, sudden time pressure, a threat, a request for a one-time code, a password, remote access software or a transfer. Being told to stay on the line and not to discuss it with anyone is a particularly reliable tell. The only way to verify anything is to hang up and call back on a number you looked up yourself.
- What is caller ID spoofing?
- Caller ID spoofing, sometimes written call ID spoofing, is the technical term for a forged number on the display. The caller ID is the field your phone reads out of the signalling data and shows on screen. When it is spoofed, that field holds a number the caller does not own. The same mechanism has entirely legitimate uses: a company switchboard presents one central service number for three hundred extensions. Misused, it is the engine of most phone fraud.
- Is making a fake call with someone else stolen number illegal?
- In most jurisdictions, yes, when the intent is to defraud or cause harm. The United States prohibits it under the Truth in Caller ID Act, the United Kingdom treats it under the Communications Act and Ofcom rules, and German law forbids using a number that has not been allocated to you at all. Add financial loss and it becomes fraud on top, with impersonating a police officer carrying its own charge. A prank call with a borrowed number is already a regulatory offence.
- Are there apps for spoofing a number?
- Such services do exist, and their availability is precisely why this form of fraud is so widespread. Naming them here would be beside the point: displaying a number that is not yours is unlawful in most countries, and depending on intent it becomes fraud. If you simply do not want to reveal your own number, you do not need one of these services. Caller ID withholding is free on every network, and a second SIM covers the rest.
- Where do I report spoofing?
- Report the number misuse to your national telecom regulator or fraud reporting service: the FTC and the FCC in the United States, Ofcom together with Action Fraud in the United Kingdom, the Bundesnetzagentur in Germany. Include the date, the time, the number that was displayed and a short description. If money moved or credentials were handed over, contact the police as well, and call your bank immediately, since transfers can sometimes still be stopped within the first hours.
- Someone is calling people using my number, what can I do?
- The reassuring part first: your line has not been hacked and there is nothing wrong with your phone. Your number was simply written into a data field, which happens remotely and requires no access to your device at all. There is very little you can do to stop it. Report it to your regulator, put a short factual message on your voicemail, and wait it out. These waves usually move on to the next block of numbers within days.