Scams · guide
Caller ID spoofing: what your screen can and cannot tell you
By Alberto Gulotta · Updated · 19 min read
Caller id spoofing is a caller choosing what your screen will display, which is why your bank’s real number appearing there proves nothing at all. No amount of looking harder at the screen is a check. The only one that works leaves the call entirely and reaches the company on a number you picked yourself.
No product is named here and no list of “scam numbers” is published, because such a list is out of date the day it is written. Everything below is quoted from the FCC, the FTC and a state public service commission official, each read in full on 10 September 2026.
What caller ID spoofing is
The Federal Communications Commission defines it in one sentence: “Spoofing is when a caller deliberately falsifies the information transmitted to your caller ID display to disguise their identity.”
The important word is transmitted. The name and number you see were not worked out by the phone network from where the call came from. They were supplied along with the call, by whoever placed it, and the network passes them along. That makes the display a claim rather than a measurement, and it is why the whole habit of squinting at the screen to decide whether a call is genuine does not work — there is nothing there to inspect.
The FCC also describes what is done with it: scammers “spoof a number from a company or a government agency that you may already know and trust”, and “if you answer, they use scam scripts to try to steal your money or valuable personal information”. So the number on your screen being your own bank’s real number is not evidence of anything at all. It is the easiest thing in the whole interaction to fake, and it is the part the scripts are built around treating as proof.
Why the number looks local, and why the calls never stop
The FCC names the specific trick: “Robocallers use neighbor spoofing, which displays a phone number similar to your own on your caller ID, to increase the likelihood that you will answer the call.” A call from your own area code and your own prefix reads as somebody from round the corner, and that is the entire design.
The part that explains the sheer volume is not on the FCC page. It is in an interview with Stacy Harrell, No Call Administrator for the Mississippi Public Service Commission, published by the Mississippi State University Extension Service. “They get paid based on the number of calls they make per day,” said Harrell. “All they have to do is place the call. They don’t have to make a sale or talk to anyone.” And on the arithmetic: “if you make a million calls a day — even if you only make pennies on the dollar — that’s a lot of money. It’s very profitable, and that’s why it continues.”
That changes what counts as success on your side. You are not trying to win an argument or waste the caller’s time, because their time is not the cost. Hanging up in three seconds is the whole of the correct response.
The same official describes what the display looks like when it is done well: “Spoofed numbers will have an area code and prefix — the first six numbers — that are the same as or similar to the phone number of the person being called.”
The one rule that works when you cannot tell
Leave the conversation and reach the organisation by a route you chose yourself. Not a number the caller gave you, not a link in a message, not the number that appeared on the screen: the number printed on your card, the app you already have, the address you typed by hand. The Federal Trade Commission puts the sharp end of it plainly: “Never use the number the caller gave you; it’ll take you to the scammer.”
A real bank, a real courier and a real government office all survive that perfectly well. It costs you two minutes and it works without your having to decide whether the call was genuine — which is the point, because the spoofed display has removed the evidence you would need to decide.
The FCC’s own list of habits is short and worth having in advance. “Don’t answer calls from unknown numbers. If you answer such a call, hang up immediately.” And the one people get wrong: “If you answer the phone and the caller — or a recording — asks you to hit a button to stop getting the calls, you should just hang up. Scammers often use this trick to identify potential targets.” Also: “Do not respond to any questions, especially those that can be answered with ‘Yes’ or ‘No.’”
And one that is easy to fix tonight, from the same page: “If you have a voice mail account with your phone service, be sure to set a password for it. Some voicemail services are preset to allow access if you call in from your own phone number. A hacker could spoof your home phone number and gain access to your voice mail if you do not set a password.”
What the law says, and why it has not fixed it
The relevant United States rule is the Truth in Caller ID Act. The FCC states its effect: “Under the Truth in Caller ID Act, FCC rules prohibit anyone from transmitting misleading or inaccurate caller ID information with the intent to defraud, cause harm or wrongly obtain anything of value. Anyone who is illegally spoofing can face penalties of up to $10,000 for each violation.”
Notice the qualifier, because it is doing real work: the prohibition is on doing it with that intent. The same page is explicit that the technique itself is not banned: “spoofing is not always illegal. There are legitimate, legal uses for spoofing, like when a doctor calls a patient from her personal mobile phone and displays the office number rather than the personal phone number or a business displays its toll-free call-back number.”
So there is no switch to turn off, and there was never going to be one. What the FCC is doing instead is at the network level: on the same page it states that, to combat neighbour spoofing, it is requiring the phone industry to adopt a robust caller ID authentication system. That is why some calls now arrive labelled, and the FCC describes the labelling honestly — “If a telephone number is blocked or labeled as a ‘potential scam’ or ‘spam’ on your caller ID, it is possible the number has been spoofed” — which is a probability, not a verdict. An unlabelled call is not thereby a safe one.
These are United States rules and they bind United States carriers. Elsewhere the same behaviour is regulated under other names by other regulators, and quoting one country’s rule as though it were universal would be worse than saying nothing.
If it is your number that other people are seeing
This is the second reason people arrive here, and it deserves an answer of its own because the fear attached to it is misplaced.
Nothing of yours has been broken into. Somebody typed your number into the field that sets what the caller ID displays. That requires nothing from your phone, your SIM, your accounts or your passwords, and there is no infection to find and nothing to reset. It is closer to somebody writing your address on the back of an envelope than to anything technical.
The FCC’s advice for it is practical and slightly bleak: “If you get calls from people saying your number is showing up on their caller ID, it’s likely that your number has been spoofed. We suggest first that you do not answer any calls from unknown numbers, but if you do, explain that your telephone number is being spoofed and that you did not actually make any calls. You can also place a message on your voicemail letting callers know that your number is being spoofed.”
And then the part that is genuinely reassuring: “Usually, scammers switch numbers frequently. It is likely that within hours they will no longer be using your number.” There is nothing to do except wait it out, and waiting is not resignation — it is the accurate response to a thing that is not happening to your equipment.
Where these get reported
Two different places, for two different things, and it is worth knowing which is which.
A call. The FCC takes complaints about spoofed calls directly, through its consumer complaint centre, and it is the agency that enforces the Truth in Caller ID Act. Its own page puts it simply: if you think you have been the victim of a spoofing scam, you can file a complaint with the FCC.
A text. The FTC gives three routes for an unwanted message, and the first is the least visible of them: “Copy the message and forward it to 7726 (SPAM). This helps your wireless provider spot and block similar messages in the future.” The other two are reporting it inside the messaging app, and reporting it to the FTC at ReportFraud.ftc.gov.
Neither of these gets your evening back, and neither stops the next call. What they do is feed the two systems that decide which calls get labelled and which numbers get blocked before they reach anybody — which is the only lever that operates at the scale the problem has.
If money has already left an account, none of this is the priority: the deadlines start immediately and they are on a different page.
The rule, decided in advance
All of this is free, and none of it requires you to judge whether a call is real.
The call that sounds like somebody you know. Spoofing changes the number; a different technique changes the voice, and the two arrive together often enough that people conflate them. What to do about a voice you recognise asking for money urgently is on the voice scams page, where the defence is a word agreed in advance rather than anything you can hear.
Where this sits. A faked number is one door among several in phishing and scam calls. If the same trick reached you by message rather than by ringing, reducing spam texts is the nearer page, and a code arriving out of nowhere has its own explanation on the verification code page. If somebody already has enough about you to be convincing, that material usually came from somewhere public: your digital footprint. And if the number itself stopped working rather than being displayed elsewhere, that is a SIM swap.
The name for this, and its two siblings. A scam delivered by telephone is called vishing and one delivered by text is smishing, and the reason the words are worth anything is practical: a call leaves nothing behind to forward, while a text does. The text version you are most likely to receive claims to be about a parcel, and the usual advice about it is false.
Where to start
Four ways into this page.
- “My bank’s number is calling me. Is it them?”
- What the screen proves — what it is
- “Why is it always a local number?”
- Neighbour spoofing, and the money — neighbour
- “What do I actually do when it rings?”
- One rule, decided in advance — what to do
- “People say I called them. I did not.”
- Your number, not your phone — your own number
The other things that arrive by phone
The faked number is the wrapper. What comes through it is one of a small number of scripts, and each has its own page.
If the call worked
These are the pages for after somebody has been convincing, rather than before.
Questions people also ask
What is an example of caller ID spoofing?
A call that displays your own bank’s real number, or a number with your area code and prefix. The FCC describes both: scammers “spoof a number from a company or a government agency that you may already know and trust”, and use neighbour spoofing to show a number similar to your own so that you answer.
Is caller ID spoofing illegal?
Only with a particular intent. The FCC: under the Truth in Caller ID Act its rules “prohibit anyone from transmitting misleading or inaccurate caller ID information with the intent to defraud, cause harm or wrongly obtain anything of value”, with penalties of up to $10,000 per violation. The same page notes legitimate uses, such as a doctor showing the office number.
Can you stop caller ID spoofing?
Not at your end, because nothing at your end is involved. The FCC’s approach is at the network level: it states that to combat neighbour spoofing it is requiring the phone industry to adopt a robust caller ID authentication system. What you can change is your own rule about calling back on a number you chose yourself.
Someone is using my phone number to make calls. Have I been hacked?
No. Somebody entered your number into the field that sets what the caller ID shows; nothing on your phone or in your accounts was involved. The FCC adds the reassuring part: “Usually, scammers switch numbers frequently. It is likely that within hours they will no longer be using your number.”
Why do I get so many of these calls even though nobody falls for them?
Because the caller is paid for placing the call. “They get paid based on the number of calls they make per day,” said Stacy Harrell of the Mississippi Public Service Commission. “All they have to do is place the call. They don’t have to make a sale or talk to anyone.”
Does a call labelled “Scam Likely” mean the rest are safe?
No. The FCC describes the label as a probability produced by analytics: if a number is labelled, “it is possible the number has been spoofed”. An unlabelled call has simply not been flagged, which is not the same as having been checked.
Not covered here. It does not publish a list of numbers to block. Numbers are spoofed and rotated constantly, such a list is out of date the day it is written, and treating an absent number as a safe one is exactly the mistake this page exists to prevent.
It does not explain how to falsify a caller ID, and it will not. The sections above are written from the regulator’s published material, at the level the regulator publishes it.
And it does not sell a blocking service. The habits described here are free, the reporting routes are free, and there is no affiliate link on the page. What holds instead is simple: the definition, the law, the penalty and the advice are quoted from the FCC’s own consumer guide with the date it was last reviewed, the economics are quoted from a named state commission official, no list of numbers is published, and nothing is sold.
Sources
- Federal Communications Commission — Caller ID Spoofing (last reviewed 13 November 2024): the definition of spoofing as deliberately falsifying the information transmitted to a caller ID display, the description of neighbour spoofing and the requirement placed on the industry to adopt caller ID authentication, the Truth in Caller ID Act prohibition and the penalty of up to $10,000 per violation, the legitimate uses, the advice not to answer unknown numbers and never to press a button to stop calls, the voicemail password warning, and what to do when your own number is the one being displayed — www.fcc.gov, read 10 September 2026.
- Mississippi State University Extension Service — Take steps to avoid caller ID spoofing scams (22 April 2022): Stacy Harrell of the Mississippi Public Service Commission on why spoofed numbers share the first six digits of the number being called, and on the economics — that callers are paid for calls placed rather than for sales made, which is why the volume does not fall when nobody is deceived — techoutreach.extension.msstate.edu, read 10 September 2026.
- Federal Trade Commission — What’s a verification code and why would someone ask me for it? (March 2024): the instruction to reach a bank only on a number you already trust, and never on a number supplied by the caller — consumer.ftc.gov, read 10 September 2026.
- Federal Trade Commission — How To Recognize and Report Spam Text Messages: the three reporting routes for an unwanted message, including forwarding a copy to 7726 so that the wireless provider can spot and block similar messages — consumer.ftc.gov, read 10 September 2026.
Written by Alberto Gulotta
Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.
Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.
Written on 10 September 2026.
Independence and limits
No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.
This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.