Spoofing: when the caller ID lies to you
-
Key takeaways
Spoofing disguises a caller, sender, or website’s true identity to make it appear trustworthy or familiar.
Caller ID spoofing can make a scam call display a local number or even a real company or agency’s name.
Caller ID display alone is not reliable proof of who’s actually making contact.
The FCC offers tools and reporting channels for spoofed calls, and providers increasingly use authentication technology to catch them.
Remitly’s official communications only come through its own verified app, website, and listed contact channels.
Just because a caller ID shows a familiar name or number doesn’t mean it’s genuine. Here’s how spoofing works and how to protect yourself.
What is spoofing?
According to the FCC(opens in new window), spoofing is when a caller deliberately falsifies the information transmitted to a caller ID display to disguise their true identity. Scammers often use this to make an incoming call appear to come from a local number, a trusted business, or even a government agency already familiar to the target, specifically to increase the odds the call will be answered and believed.
How spoofing is used in financial fraud
A spoofed call might display the name and number of an actual bank, prompting trust and an answered call that’s actually from a scammer. Neighbor spoofing displays a number with the same area code and prefix as the recipient’s own, exploiting the instinct to answer a call that looks local. Beyond phone calls, similar spoofing techniques can disguise the sender address on an email or text message, making a phishing attempt look like it’s coming from a legitimate company or even someone in the recipient’s own contacts.
Why caller ID alone isn’t proof of anything
It’s worth internalizing clearly that caller ID display, however official or familiar it looks, is not reliable verification of who’s actually calling. The technology behind spoofing has become accessible enough that faking a caller ID requires no special skill or access, meaning a convincing display is unfortunately no guarantee of a genuine call.
How Remitly protects you
Remitly’s official communications come only through its own app, website, and clearly listed contact channels. A call or message that appears to be from Remitly but asks for sensitive information or an urgent payment shouldn’t be trusted based on caller ID or sender name alone; verifying by contacting Remitly directly through the official app or website is the safer path.
Red flags to watch for
A call from a number that looks local or familiar but leads to an unexpected, urgent request. Local-looking caller ID is easily faked and proves nothing.
A caller claiming to be a bank, a government agency, or a known company, asking for confirmation of sensitive information. Hang up and call back using a number already known to be correct.
An email or text that appears to come from a known contact or company but contains an unusual request or link. The sender name can be faked just as easily as a phone number.
Being told the caller ID service itself confirms identity. No caller ID system verifies identity in a way that would make this claim meaningful.
The technology behind why spoofing is possible
Caller ID and sender information were designed decades ago around a basic assumption of trust between telecommunications providers, an assumption that modern technology has made considerably easier to exploit than the system’s original designers anticipated. Industry-wide efforts like caller ID authentication technology are gradually making spoofing harder to pull off undetected, but until adoption is complete across every provider, treating caller ID as informative rather than definitive proof remains the safest approach.
Spoofing versus legitimate number masking
Not every altered caller ID is malicious. Legitimate businesses sometimes use call masking to display a general company number rather than an individual employee’s direct line, for entirely reasonable privacy and organizational purposes. The distinction that matters is intent: masking for a legitimate business purpose is disclosed and expected, while spoofing to deceive someone about who’s actually calling, in order to extract money or information, is what this glossary entry, and the law, is specifically concerned with.
What to do if you’re the one being impersonated
Discovering that scammers are spoofing your own phone number to target other people is worth reporting to your phone carrier, since they may have tools to help, and posting a brief public notice to your own contacts warning them that calls appearing to come from your number may not actually be you is a reasonable step. While a number generally can’t be fully protected from being spoofed, taking these steps limits confusion and potential harm to people who trust you.
A simple habit that neutralizes most spoofing attempts
Making it a consistent personal rule to never share sensitive information or send money based solely on an incoming call or message, regardless of what the caller ID or sender name displays, neutralizes the vast majority of spoofing-based scams before they can succeed, since it removes the one thing the scammer is actually counting on: trust in the displayed identity. For general guidance on recovering after any kind of fraud has already occurred, Remitly’s scam recovery guide(opens in new window) covers the practical steps worth taking.
Reporting spoofed calls contributes to broader enforcement
While an individual complaint to the FCC about a spoofed call may not resolve that specific situation directly, this reporting feeds into broader enforcement efforts and policy decisions aimed at reducing spoofed robocalls at a systemic level. Treating a report as a contribution to a larger effort, rather than expecting an individual resolution, helps set realistic expectations while still making the report worthwhile.
Common questions about spoofing
-
How can I tell if an incoming call has been spoofed?
It’s often not possible to tell immediately just by looking at the display, which is exactly the point of spoofing. If the call involves any request for money or personal information, hanging up and independently verifying by calling a number already known to be correct for that person or organization is the safer response.
-
What should I do if I think I’ve received a spoofed call?
Don’t provide any personal or financial information. The suspected spoofed call can be reported to the FCC, which uses these reports to inform enforcement efforts and policy decisions, even though it typically doesn’t resolve individual complaints directly.
-
Can spoofing happen through text messages and email too, not just phone calls?
Yes. The same underlying idea, disguising the true sender to appear trustworthy, applies to a faked email sender address or a text message that appears to come from a legitimate short code or contact, not just a phone call’s caller ID.
In Summary
Spoofing exploits the trust naturally placed in a familiar caller ID, sender name, or number, which is exactly why verifying independently, rather than trusting the display alone, is the protection that actually works.
This publication is provided for general information purposes only and is not intended to cover all aspects of the topics discussed herein. This publication is not a substitute for seeking advice from an applicable specialist or professional. The content in this publication does not constitute legal, tax, or other professional advice from Remitly or any of its affiliates and should not be relied upon as such. While we strive to keep our posts up to date and accurate, we cannot represent, warrant, or otherwise guarantee that the content is accurate, complete, or up to date.