What is phone number spoofing and how do you stop it?
In brief
Phone number spoofing falsifies caller ID. Learn how spoofed calls work, how to respond safely, and what carrier authentication can do today.

Phone number spoofing is when a caller makes a call or sends a text that displays a phone number other than the number actually used to originate it. You cannot stop another person from selecting a spoofed caller ID, including your own number, but you can reduce the risk: treat unexpected caller ID as unverified, contact organizations through independently found details, and report suspected scams.
At a glance
Quick takeaways
- Phone number spoofing changes the number shown to the recipient, not necessarily the caller's real origin.
- A familiar, local, or trusted-looking number is not proof that a caller is legitimate.
- Caller ID authentication can help carriers identify some illegitimate spoofing, but it does not make every displayed number trustworthy.
- Do not provide passwords, verification codes, payment details, or remote access because of an unexpected call.
- If a caller claims to represent an organization, end the call and use contact details from that organization's official website or statement.
- Phone spoofing and email spoofing both abuse trust in a displayed identity, but they use different technical controls.
How phone number spoofing works
A caller ID display gives the recipient an identifier to recognize or return a call. That identifier can be used legitimately. For example, an organization may present its main published number when staff place outbound calls from different lines.
The risk begins when the displayed number is used to misrepresent who is calling. A fraudster may choose a number that appears local, resembles a known business number, or belongs to an unrelated person. The recipient sees the chosen identifier before they can independently verify the caller.
The Federal Communications Commission describes caller ID spoofing as deliberately falsifying the information transmitted to caller ID display systems. Its caller ID spoofing guidance also explains that spoofing with intent to defraud, cause harm, or wrongfully obtain anything of value is prohibited under US law.
A spoofed display does not, by itself, tell you how a call was placed, who placed it, or whether the number's legitimate subscriber is involved. That distinction matters if your own number appears to have been used. Receiving callbacks from strangers can mean that someone displayed your number on calls to them. It does not establish that your handset, account, or phone service was accessed.

When the answer changes
The safe response depends on what evidence you have, not on how convincing the caller ID looks.
If you were not expecting the call, treat the claimed identity as unverified. This applies even when the display shows your bank, an employer, a government body, a utility, or a local-looking number. End the call without using a phone number provided by the caller. Then find the organization's contact information through its official website, card, invoice, account portal, or another trusted record.
If the call concerns an existing account, use the number you already have for that account. If the caller says there is an emergency, an unpaid bill, a security incident, or a required payment, slow the interaction down. A legitimate organization can normally be contacted through an independently verified route.
Use this decision rule:
- An unexpected call plus a request for money, credentials, one-time codes, remote device access, or urgent action is enough reason to disconnect and verify separately.
- A displayed number matching a known organization does not change that rule.
- A callback request from an unfamiliar person does not prove that your number was compromised.
- A call that you initiate using independently verified details gives you a better basis for discussing an account, though you should still follow the organization's normal authentication process.
A worked response example
Suppose your phone displays the number of a bank and the caller says that suspicious activity requires an immediate verification code. The caller ID is not the evidence you need. The relevant evidence is whether you can independently reach the bank and whether the bank confirms the request through its normal process.
Unexpected call claiming to be a bank
Displayed caller ID: A number that appears to belong to the bank
Caller request: Read out a verification code
Safe response:
1. Do not share the code or account details.
2. End the call.
3. Find the bank's official contact number from its website or card.
4. Call that number and ask whether the request was genuine.
5. Report the suspicious call if it was fraudulent.
A caller ID label, a local area code, and a familiar number are all weak identity signals because each can be presented without proving the caller's authority. The independent callback is the stronger test because you choose the destination from a trusted source.
If your number is being spoofed, preserve useful details such as the time of callbacks, any voicemail, and the number people say they received calls from. Do not ask callers to disclose private information. You can explain briefly that your number may have been spoofed, then report the pattern through the appropriate channels.
What to do with the evidence you have
Start with the least invasive action that matches the evidence.
- If you received an unexpected call or text, do not reply with sensitive information. Block the displayed number if your device or carrier supports it, while recognizing that blocking does not identify the source.
- If the caller impersonated an organization, contact that organization through independently found details and ask whether it wants the incident reported through a particular channel.
- If the call appears fraudulent, submit a report through the Federal Trade Commission's fraud reporting service and, where relevant, the FCC's consumer complaint process.
- If your number appears to be spoofed, tell your phone provider what you observed and keep a short record of dates and callback details.
For the broader impersonation problem, see how to stop spoofing attacks and what spoofing is and how to stop it. Phone number spoofing is one channel. Email impersonation is another, with separate controls and evidence.
Check your domain's email impersonation exposure
A suspicious phone call does not tell you whether someone can also impersonate your organization by email. If you manage a domain, use the Email Security Score to inspect its publicly visible email-authentication posture. For further context on securing business email identity, visit the email security learning hub.
Check your domain's email security score
A public domain check cannot identify the person behind a phone call, prove that a specific email was legitimate, monitor every future sender, or control a phone carrier's treatment of a call. Palisade is agentic DMARC software that analyzes DMARC aggregate-report data, identifies sending and alignment issues, and proposes remediation work for human review. It does not change a phone number's caller ID or decide whether a carrier blocks a call.
Evidence
Sources and further reading
Questions readers ask
Frequently asked questions
Is phone number spoofing illegal?
Only spoofing that is done with intent to defraud, cause harm, or wrongfully obtain something of value is prohibited by the US Truth in Caller ID Act. A displayed number can also have legitimate business uses, so the display alone does not establish intent.
Can someone spoof my number without hacking my phone?
Yes. A person can present your number as caller ID without accessing your phone, SIM, or account. Unexpected callbacks may indicate that your number was displayed on someone else's calls, but they are not proof of an account breach.
Should I call a suspicious number back?
No. Do not call the displayed number back to verify an unexpected claim. Find the organization's contact information yourself through an official website, account portal, statement, or card, then initiate the call.
Does STIR/SHAKEN stop all spoofed calls?
No. Caller ID authentication helps telephone providers validate some caller ID information and reduce illegal spoofing. It does not prove that every call is legitimate or remove the need to verify unexpected requests independently.
Is phone number spoofing the same as email spoofing?
No. Both involve a false-looking identity, but phone caller ID and email sender identity use different systems. Email domains can publish SPF, DKIM, and DMARC controls, while phone networks use caller ID authentication and carrier-level mitigation.

Written by
Ian BussieresCTO & Co-Founder, Palisade
Ian Bussieres is the CTO and co-founder of Palisade, agentic DMARC software for IT teams and MSPs.
More from Ian →


