Spoofing
Spoofing is masking the origin of a communication so it appears to come from someone you trust. An attacker can forge the caller ID on a phone call, the 'from' name and address on an email, or a website's look, making what you see line up with a legitimate brand. Spoofing is the disguise that makes phishing and impersonation scams believable.
How we check this: Written and reviewed by the Hunch team; recognition signs reflect how the FTC/FBI describe this scam. · Last reviewed: 2026-08
Check a suspicious message now
Example
Your phone rings and the caller ID shows your bank's real name and number, but the call is actually placed by a scammer who faked that ID to convince you the fraud warning they're about to deliver is genuine.
How to recognize it
- A caller ID or sender name that looks right but the request feels off
- An email display name matching a brand while the real address doesn't
- A website that looks identical to a trusted one on a slightly different domain
- Replies bouncing or going to an address you don't recognize
How Hunch flags it
Hunch focuses on signal categories that survive the disguise, the actual domain behind a display name, lookalike addresses, and whether a message pairs a trusted appearance with an urgent credential or payment ask.
FAQ
What is spoofing?
Faking the source of a call, email, or website so it appears to come from a trusted person or organization.
Can scammers really fake a real phone number?
Yes. Caller ID is easy to forge, so a familiar name or number on your screen is not proof that the call is genuine.
How do I tell if an email is spoofed?
Look past the display name at the actual sending address and the real link destinations; a spoofed message usually reveals a mismatched domain there.