Scams · guide

Caller ID spoofing: what your screen can and cannot tell you

By Alberto Gulotta · Updated · 19 min read

Caller id spoofing is a caller choosing what your screen will display, which is why your bank’s real number appearing there proves nothing at all. No amount of looking harder at the screen is a check. The only one that works leaves the call entirely and reaches the company on a number you picked yourself.

No product is named here and no list of “scam numbers” is published, because such a list is out of date the day it is written. Everything below is quoted from the FCC, the FTC and a state public service commission official, each read in full on 10 September 2026.

What the number on your screen proves, and what it does not The Federal Communications Commission defines spoofing as a caller deliberately falsifying the information transmitted to your caller ID display in order to disguise their identity. The consequence is that the display is a claim made by the caller rather than a fact established by the network: a bank’s real number appearing there is something the caller typed. Nothing you can see on the screen distinguishes the two cases, which is why looking harder at the screen is not a check. THE SCREEN IS A CLAIM, NOT A MEASUREMENT What you see a name and a number, often local, often one you already trust — supplied by the caller What it proves nothing at all about who is calling, because the caller chose what would appear So no amount of looking at the screen is a check The FCC: spoofing is deliberately falsifying what your caller ID displays. AI Tools Primer · figure
The definition is the Federal Communications Commission’s, from its consumer guide on caller ID spoofing, last reviewed 13 November 2024. Figure drawn by AI Tools Primer.

What caller ID spoofing is

The Federal Communications Commission defines it in one sentence: “Spoofing is when a caller deliberately falsifies the information transmitted to your caller ID display to disguise their identity.”

The important word is transmitted. The name and number you see were not worked out by the phone network from where the call came from. They were supplied along with the call, by whoever placed it, and the network passes them along. That makes the display a claim rather than a measurement, and it is why the whole habit of squinting at the screen to decide whether a call is genuine does not work — there is nothing there to inspect.

The FCC also describes what is done with it: scammers “spoof a number from a company or a government agency that you may already know and trust”, and “if you answer, they use scam scripts to try to steal your money or valuable personal information”. So the number on your screen being your own bank’s real number is not evidence of anything at all. It is the easiest thing in the whole interaction to fake, and it is the part the scripts are built around treating as proof.

Neighbour spoofing, and why the caller is paid whether or not you buy anything The FCC describes neighbour spoofing as displaying a phone number similar to your own to increase the likelihood that you will answer. The Mississippi Public Service Commission’s No Call Administrator explains the economics behind the volume: callers are paid for the number of calls placed each day rather than for sales made, so a call that you hang up on has already earned its fee. That is why the calls do not stop when nobody falls for them. WHY IT LOOKS LOCAL, AND WHY IT NEVER STOPS Neighbour spoofing a number close to your own, same area code and prefix — chosen so you answer Paid per call placed “All they have to do is place the call. They don’t have to make a sale or talk to anyone.” Which is why hanging up quickly is still the right move It costs them nothing, and it costs you the only thing they can actually take: time. AI Tools Primer · figure
The neighbour spoofing description is the FCC’s; the quotation is Stacy Harrell of the Mississippi Public Service Commission, in the Mississippi State University Extension Service’s article. Figure drawn by AI Tools Primer.

Why the number looks local, and why the calls never stop

The FCC names the specific trick: “Robocallers use neighbor spoofing, which displays a phone number similar to your own on your caller ID, to increase the likelihood that you will answer the call.” A call from your own area code and your own prefix reads as somebody from round the corner, and that is the entire design.

The part that explains the sheer volume is not on the FCC page. It is in an interview with Stacy Harrell, No Call Administrator for the Mississippi Public Service Commission, published by the Mississippi State University Extension Service. “They get paid based on the number of calls they make per day,” said Harrell. “All they have to do is place the call. They don’t have to make a sale or talk to anyone.” And on the arithmetic: “if you make a million calls a day — even if you only make pennies on the dollar — that’s a lot of money. It’s very profitable, and that’s why it continues.”

That changes what counts as success on your side. You are not trying to win an argument or waste the caller’s time, because their time is not the cost. Hanging up in three seconds is the whole of the correct response.

The same official describes what the display looks like when it is done well: “Spoofed numbers will have an area code and prefix — the first six numbers — that are the same as or similar to the phone number of the person being called.”

The one rule that works when you cannot tell

Leave the conversation and reach the organisation by a route you chose yourself. Not a number the caller gave you, not a link in a message, not the number that appeared on the screen: the number printed on your card, the app you already have, the address you typed by hand. The Federal Trade Commission puts the sharp end of it plainly: “Never use the number the caller gave you; it’ll take you to the scammer.”

A real bank, a real courier and a real government office all survive that perfectly well. It costs you two minutes and it works without your having to decide whether the call was genuine — which is the point, because the spoofed display has removed the evidence you would need to decide.

The FCC’s own list of habits is short and worth having in advance. “Don’t answer calls from unknown numbers. If you answer such a call, hang up immediately.” And the one people get wrong: “If you answer the phone and the caller — or a recording — asks you to hit a button to stop getting the calls, you should just hang up. Scammers often use this trick to identify potential targets.” Also: “Do not respond to any questions, especially those that can be answered with ‘Yes’ or ‘No.’”

And one that is easy to fix tonight, from the same page: “If you have a voice mail account with your phone service, be sure to set a password for it. Some voicemail services are preset to allow access if you call in from your own phone number. A hacker could spoof your home phone number and gain access to your voice mail if you do not set a password.”

When faking a number is illegal, and when it is not Under the Truth in Caller ID Act, FCC rules prohibit transmitting misleading or inaccurate caller ID information with the intent to defraud, cause harm or wrongly obtain anything of value, and anyone illegally spoofing can face penalties of up to ten thousand dollars for each violation. The same FCC page states that spoofing is not always illegal and gives legitimate examples: a doctor calling a patient from a personal mobile while displaying the office number, or a business displaying its toll-free call-back number. THE TRUTH IN CALLER ID ACT, IN THE FCC’S OWN WORDS Illegal misleading or inaccurate caller ID “with the intent to defraud, cause harm or wrongly obtain anything of value” Legal a doctor calling from a personal mobile but showing the office number; a business showing its toll-free call-back number Penalties of up to $10,000 for each violation — and it is still constant A law that is hard to enforce across borders does not make the screen trustworthy. AI Tools Primer · figure
Both columns and the penalty are quoted from the FCC’s consumer guide on caller ID spoofing. Figure drawn by AI Tools Primer.

What the law says, and why it has not fixed it

The relevant United States rule is the Truth in Caller ID Act. The FCC states its effect: “Under the Truth in Caller ID Act, FCC rules prohibit anyone from transmitting misleading or inaccurate caller ID information with the intent to defraud, cause harm or wrongly obtain anything of value. Anyone who is illegally spoofing can face penalties of up to $10,000 for each violation.”

Notice the qualifier, because it is doing real work: the prohibition is on doing it with that intent. The same page is explicit that the technique itself is not banned: “spoofing is not always illegal. There are legitimate, legal uses for spoofing, like when a doctor calls a patient from her personal mobile phone and displays the office number rather than the personal phone number or a business displays its toll-free call-back number.”

So there is no switch to turn off, and there was never going to be one. What the FCC is doing instead is at the network level: on the same page it states that, to combat neighbour spoofing, it is requiring the phone industry to adopt a robust caller ID authentication system. That is why some calls now arrive labelled, and the FCC describes the labelling honestly — “If a telephone number is blocked or labeled as a ‘potential scam’ or ‘spam’ on your caller ID, it is possible the number has been spoofed” — which is a probability, not a verdict. An unlabelled call is not thereby a safe one.

These are United States rules and they bind United States carriers. Elsewhere the same behaviour is regulated under other names by other regulators, and quoting one country’s rule as though it were universal would be worse than saying nothing.

If it is your number that other people are seeing

This is the second reason people arrive here, and it deserves an answer of its own because the fear attached to it is misplaced.

Nothing of yours has been broken into. Somebody typed your number into the field that sets what the caller ID displays. That requires nothing from your phone, your SIM, your accounts or your passwords, and there is no infection to find and nothing to reset. It is closer to somebody writing your address on the back of an envelope than to anything technical.

The FCC’s advice for it is practical and slightly bleak: “If you get calls from people saying your number is showing up on their caller ID, it’s likely that your number has been spoofed. We suggest first that you do not answer any calls from unknown numbers, but if you do, explain that your telephone number is being spoofed and that you did not actually make any calls. You can also place a message on your voicemail letting callers know that your number is being spoofed.”

And then the part that is genuinely reassuring: “Usually, scammers switch numbers frequently. It is likely that within hours they will no longer be using your number.” There is nothing to do except wait it out, and waiting is not resignation — it is the accurate response to a thing that is not happening to your equipment.

Where these get reported

Two different places, for two different things, and it is worth knowing which is which.

A call. The FCC takes complaints about spoofed calls directly, through its consumer complaint centre, and it is the agency that enforces the Truth in Caller ID Act. Its own page puts it simply: if you think you have been the victim of a spoofing scam, you can file a complaint with the FCC.

A text. The FTC gives three routes for an unwanted message, and the first is the least visible of them: “Copy the message and forward it to 7726 (SPAM). This helps your wireless provider spot and block similar messages in the future.” The other two are reporting it inside the messaging app, and reporting it to the FTC at ReportFraud.ftc.gov.

Neither of these gets your evening back, and neither stops the next call. What they do is feed the two systems that decide which calls get labelled and which numbers get blocked before they reach anybody — which is the only lever that operates at the scale the problem has.

If money has already left an account, none of this is the priority: the deadlines start immediately and they are on a different page.

The rule, decided in advance

All of this is free, and none of it requires you to judge whether a call is real.

Treat the screen as decoration The FCC’s definition makes it a claim supplied by the caller. A trusted name appearing there is not evidence of anything.
Hang up, then call back on a number you chose The one on your card, in your app, or typed by hand. The FTC: “Never use the number the caller gave you”.
Never press a button to make the calls stop The FCC: scammers use that to identify targets. Just hang up.
Put a password on your voicemail The FCC notes that some services grant access to a call that appears to come from your own number — which is exactly what spoofing can produce.
Report the call to the FCC, and forward texts to 7726 It does not stop the next one. It feeds the systems that label and block at scale.

The call that sounds like somebody you know. Spoofing changes the number; a different technique changes the voice, and the two arrive together often enough that people conflate them. What to do about a voice you recognise asking for money urgently is on the voice scams page, where the defence is a word agreed in advance rather than anything you can hear.

Where this sits. A faked number is one door among several in phishing and scam calls. If the same trick reached you by message rather than by ringing, reducing spam texts is the nearer page, and a code arriving out of nowhere has its own explanation on the verification code page. If somebody already has enough about you to be convincing, that material usually came from somewhere public: your digital footprint. And if the number itself stopped working rather than being displayed elsewhere, that is a SIM swap.

The name for this, and its two siblings. A scam delivered by telephone is called vishing and one delivered by text is smishing, and the reason the words are worth anything is practical: a call leaves nothing behind to forward, while a text does. The text version you are most likely to receive claims to be about a parcel, and the usual advice about it is false.

Where to start

Four ways into this page.

“My bank’s number is calling me. Is it them?”
What the screen proves — what it is
“Why is it always a local number?”
Neighbour spoofing, and the money — neighbour
“What do I actually do when it rings?”
One rule, decided in advance — what to do
“People say I called them. I did not.”
Your number, not your phone — your own number

The other things that arrive by phone

The faked number is the wrapper. What comes through it is one of a small number of scripts, and each has its own page.

If the call worked

These are the pages for after somebody has been convincing, rather than before.

Questions people also ask

What is an example of caller ID spoofing?

A call that displays your own bank’s real number, or a number with your area code and prefix. The FCC describes both: scammers “spoof a number from a company or a government agency that you may already know and trust”, and use neighbour spoofing to show a number similar to your own so that you answer.

Is caller ID spoofing illegal?

Only with a particular intent. The FCC: under the Truth in Caller ID Act its rules “prohibit anyone from transmitting misleading or inaccurate caller ID information with the intent to defraud, cause harm or wrongly obtain anything of value”, with penalties of up to $10,000 per violation. The same page notes legitimate uses, such as a doctor showing the office number.

Can you stop caller ID spoofing?

Not at your end, because nothing at your end is involved. The FCC’s approach is at the network level: it states that to combat neighbour spoofing it is requiring the phone industry to adopt a robust caller ID authentication system. What you can change is your own rule about calling back on a number you chose yourself.

Someone is using my phone number to make calls. Have I been hacked?

No. Somebody entered your number into the field that sets what the caller ID shows; nothing on your phone or in your accounts was involved. The FCC adds the reassuring part: “Usually, scammers switch numbers frequently. It is likely that within hours they will no longer be using your number.”

Why do I get so many of these calls even though nobody falls for them?

Because the caller is paid for placing the call. “They get paid based on the number of calls they make per day,” said Stacy Harrell of the Mississippi Public Service Commission. “All they have to do is place the call. They don’t have to make a sale or talk to anyone.”

Does a call labelled “Scam Likely” mean the rest are safe?

No. The FCC describes the label as a probability produced by analytics: if a number is labelled, “it is possible the number has been spoofed”. An unlabelled call has simply not been flagged, which is not the same as having been checked.

Not covered here. It does not publish a list of numbers to block. Numbers are spoofed and rotated constantly, such a list is out of date the day it is written, and treating an absent number as a safe one is exactly the mistake this page exists to prevent.

It does not explain how to falsify a caller ID, and it will not. The sections above are written from the regulator’s published material, at the level the regulator publishes it.

And it does not sell a blocking service. The habits described here are free, the reporting routes are free, and there is no affiliate link on the page. What holds instead is simple: the definition, the law, the penalty and the advice are quoted from the FCC’s own consumer guide with the date it was last reviewed, the economics are quoted from a named state commission official, no list of numbers is published, and nothing is sold.

Sources

  1. Federal Communications Commission — Caller ID Spoofing (last reviewed 13 November 2024): the definition of spoofing as deliberately falsifying the information transmitted to a caller ID display, the description of neighbour spoofing and the requirement placed on the industry to adopt caller ID authentication, the Truth in Caller ID Act prohibition and the penalty of up to $10,000 per violation, the legitimate uses, the advice not to answer unknown numbers and never to press a button to stop calls, the voicemail password warning, and what to do when your own number is the one being displayed — www.fcc.gov, read 10 September 2026.
  2. Mississippi State University Extension Service — Take steps to avoid caller ID spoofing scams (22 April 2022): Stacy Harrell of the Mississippi Public Service Commission on why spoofed numbers share the first six digits of the number being called, and on the economics — that callers are paid for calls placed rather than for sales made, which is why the volume does not fall when nobody is deceived — techoutreach.extension.msstate.edu, read 10 September 2026.
  3. Federal Trade Commission — What’s a verification code and why would someone ask me for it? (March 2024): the instruction to reach a bank only on a number you already trust, and never on a number supplied by the caller — consumer.ftc.gov, read 10 September 2026.
  4. Federal Trade Commission — How To Recognize and Report Spam Text Messages: the three reporting routes for an unwanted message, including forwarding a copy to 7726 so that the wireless provider can spot and block similar messages — consumer.ftc.gov, read 10 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 10 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.