Spoofing attacks explained: What they are and how they work: Header image
Safer Web 10 min read

Spoofing explained: The definition, the meaning, and how it works

Published:Jul 10, 2026

Cybercriminals are masters at developing clever ways to deceive, harass, and steal from the public. One of these techniques is called spoofing. It’s been around for a long time but continues to be a standard attack procedure. 

Keep reading this guide to learn what spoofing is, how it works, and how threat actors use it to gain unlawful access to your most personal information or steal your money.

What is spoofing? The definition, meaning, and examples

Spoofing attacks are some of the most common and widespread cyberthreats today. In 2024, the FBI logged more than 193,000 phishing and spoofing complaints, while global phishing losses were estimated at $25 billion annually.

Got a suspicious email that’s urging you to click?

Check the message with Scam Detector to determine whether it’s legitimate or a scam.
TRY 7 DAYS FREE

A spoofing attack is when someone pretends to be someone else in order to gain access to secure servers, bank information, digital assets, or accounts. The intent is usually to steal money or information for identity theft or to install malware on your device. One common example is a hacker emailing a company employee while posing as a high-ranking executive and requesting a password or wire transfer.

If the recipient doesn’t catch this type of threat in time, they may end up losing money or causing irreversible damage to their machine.

A screenshot of a spoofed job email.

What does the spoofer want?

While spoofing refers to a method used by criminals, the motives behind it can vary greatly, ranging from monetary to ideological. Most spoofers are after money, impersonating high-ranking executives in companies to trick employees into making large wire transfers in what’s known as whaling. Others are after personal data, as stolen credentials can be sold on the dark web or used to break into other accounts, like social media or banking.

Spoofing can also be a stepping-stone attack, allowing a hacker to install malware or ransomware on your device via malicious email attachments, links, or QR codes (in attacks known as quishing). You can protect your device from malicious files by using Moonlock’s built-in real-time protection. Try out a 7-day free trial of Moonlock to monitor and scan your Mac for threats.

Screenshot of Moonlock, a Mac security app: The Dashboard screen.

How does spoofing work?

It’s best to think about spoofing as operating in 2 layers: technical and social.

In the technical spoof, the attacker falsifies identifying information, like the sender’s address, phone number, or IP address, in order to appear legitimate to the receiver. In the social engineering layer, the attacker crafts a compelling message designed to trigger an action, usually utilizing tactics like urgency or fear.

One example is an email that claims to be from your bank, warning you of suspicious activity. Upon checking the sender’s email, you’ll find that it matches the bank’s real address, making the email seem more legitimate, even though it’s not.

Spoofing vs. phishing: What’s the difference?

Spoofing and phishing often go hand-in-hand. However, while spoofing is the impersonation of a person or entity, phishing is the scam that the spoofed communication enables. Not all phishing attacks rely on spoofing to seem legitimate, and not all spoofing involves phishing.

Is spoofing illegal?

Yes, but with a catch — in the US it’s only illegal if you’re doing it to defraud, harm, or scam someone out of something. That’s under the FCC’s Truth in Caller ID Act, not CAN-SPAM (that law’s actually about deceptive emails, not phone numbers). Get caught, and you could be looking at fines up to $10,000 per call.

How to spot a spoofing attempt

Spoofing uses social engineering to trick unsuspecting victims. The bad actor typically uses some legitimate information to make the user think it’s real. They use urgency to try to get people to act quickly without thinking to ensure that their attacks are successful.

Below are some ways to recognize a spoofing attack and prevent potential damage. 

Analyze suspicious emails for scams and fraud

Moonlock’s Scam Detector looks at the text of the suspicious email itself, looking for any telltale social engineering language often used by scammers.

Screenshot of Moonlock, Moonlock Scam Detector message

Here’s how to put it to work:

  • Sign up for a 7-day free trial of Moonlock and install the app.
  • Head to the Scam Detector.
  • Copy the full text of the email that caught your eye.
  • Paste it in and hit Check.
  • Moonlock will do the rest.

If it’s a likely scam, Moonlock’s Security Advisor will help you with the next steps.

Screenshot of Moonlock, Moonlock Security advisor

Spoof emails

There are many signs that an email is not legitimate. Here are just a few:

  • For starters, the recipient’s address. If you hold your mouse over it, you may find that it comes from a very different source than what is shown in the “name” field.
  • Another sign that an email may be spoofed is that the language may contain errors. Many cybercriminals operate out of non-English speaking countries, so the grammar and punctuation may be messy.
  • Look for a sense of urgency or a dire alert. If the email says that your account has been hacked and you must call or click a link immediately, be wary. These are tactics used by spoofers.
  • It is also probably fake if the email asks you to pay money or provide personal information such as account login information, your Social Security number, or your ID.
  • Be wary of links to login pages. Legitimate services rarely ask you to log in via an email link. When in doubt, go directly to the site by typing the address into your browser.
  • If your organization supports it, check email headers by inspecting the raw email to verify that the sending server matches the claimed domain.
  • Enable 2-factor authentication (2FA) on all accounts to limit the risk of account takeover even if your credentials get stolen or leaked.

Never click a link in an email from any source that you do not trust completely. You could infect your device with malware or a virus. 

Also, never give out personal information to anyone online or over the phone unless you initiate the conversation. Do not share logins or passwords with anyone.

Spoof websites

  • Check the address bar. Chances are the URL will be slightly “off” from the original. Stay away if the site doesn’t start with “https” (meaning it is secure). 
  • Look for blurry images, logos, or graphics, along with broken English and poor grammar. Be careful of logging into any website that doesn’t seem legitimate. 
  • Don’t click a link to visit the site. Go to your browser and type it in manually so you are sure you’re going to the right place.
  • Use a reputable password manager, as those won’t autofill your credentials on spoofed websites. They’ll be able to tell when a URL or webpage is slightly off.

Spoof calling

Spoof calling is one of the oldest types of trickery. Callers pretend to be from a charitable organization and elicit donations from people. Sometimes, spoofers pretend to call from the IRS demanding payment. Rest assured, the IRS doesn’t make threatening phone calls and can’t put you in jail without a lengthy court process.

If anyone calls you with a threat or something that feels “off,” don’t provide any payment information over the phone, and don’t provide access to any of your accounts. Some hackers ask for access to your computer, then take it over and install malware. Just hang up.

In general, a good practice is to just not answer a call when you don’t recognize the caller ID. Let your voicemail pick up. Spoofers rarely leave messages.

Types of spoofing

Fraudsters use many different types of spoofing to trick users and obtain what they want. These techniques utilize various forms of communication, such as phone, email, SMS/messaging, and website access.

Caller ID or phone spoofing

Caller ID revolutionized the phone industry, allowing recipients to see who was calling before they picked up. Spoof calling is when a threat actor fools your caller ID by pretending to be someone else. This is made possible by Voice over Internet Protocol (VoIP) technology, which anyone can use to cheaply place calls over the internet with a falsified number.  

When you see a town or state name on the caller ID, a spoofer may be trying to get you to pick up the phone. This tactic is known as neighbor spoofing. Because, while international or out-of-state area codes might seem suspicious, using your local area code can make the number seem more familiar, and thus more trustworthy.

Criminals have found that victims are more likely to pick up an unrecognized number if they see that the call originates from their local area code. Occasionally, the scammer will even use your own number so that it appears that the call is coming from you. They’ll try anything to get you to pick up the phone so they can continue the ruse.

To protect yourself from caller ID spoofing attacks, always let unknown numbers go to voicemail, as spoofers rarely leave a message. And, if possible, check if your carrier offers a free filtering service, like AT&T’s ActiveArmor, Verizon’s Call Filter, or T-Mobile’s Scam Shield. You can also take proactive measures yourself by using third-party apps like Hiya and Nomorobo. 

Remember that, as a rule of thumb, government organizations like the IRS and the Social Security Administration will never demand immediate payment over the phone, no matter how legitimate a call may sound.

Email spoofing

Email spoofing is very common. You probably get dozens of spam emails every day. They are used for phishing attacks to get people to take action without thinking.

An email spoofing attack is when a hacker sends you an email that appears to be from a reputable source. They manipulate the “from” name so that it appears legitimate. They may even insert logos, colors, and fonts from the actual company to make you trust it. 

These spoofing emails are often designed to get you to click a link to steal credentials or install malware on your device.

A screenshot of a spoof email.

SMS spoofing

We live in an age of text messages, and cybercriminals have taken advantage of this opportunity for spoofing. They may send you fake messages urging you to click a link to check a breached account or review a non-existent invoice for something you didn’t buy. They are designed to incite fear so you act quickly without thinking.

In other cases, someone may contact you through a text message pretending to be a famous or notable person to get you to install an app or take an unsafe action that could result in theft. 

IP spoofing

In the case of IP spoofing, attackers will falsify their IP address to conceal their location during distributed denial of service (DDoS) attacks and other nefarious activities. 

DNS spoofing

DNS spoofing is particularly damaging. This occurs when hackers alter DNS records on servers to redirect web traffic to malicious websites that mimic the original. The fake website may look very realistic, so victims are unaware as they enter personal information and passwords. 

ARP spoofing

ARP spoofing targets local networks. This is where the attacker sends fake Address Resolution Protocol (ARP) messages to try to link their device to a legitimate IP address, allowing them to intercept traffic between 2 parties and steal data and session cookies or inject malware.

GPS spoofing

To spoof a GPS location, an attack may broadcast fake satellite signals to override a device’s real location. This can misdirect your personal GPS in your phone or vehicle, showing incorrect positions in your navigation app.

AI voice spoofing (deepfake calls)

With only a few seconds of audio, criminals can use AI to clone anyone’s voice, then use synthetic recreations to impersonate family members or executives in real-time calls to extract money or sensitive information. 

Tracking pixels

Tiny, invisible images (pixel-sized) can be embedded in emails to ping a remote server when opened, revealing the receiver’s IP address, device, and location. To reduce the risk of pixel tracking, disable automatic image loading in your email client and use email providers with built-in tracker blocking, like Apple Mail or Proton Mail.

How to protect yourself from spoofing attacks

You can use security tools and built-in filters to help prevent spoofing attacks, but your best line of defense remains your personal knowledge and awareness of such schemes.

Screenshot of Moonlock's Scam Detector tool.

Here’s what you need to keep in mind:

  • Keep an eye out for scam patterns: Use Scam Detector to check emails and messages for any of the phrasing typically used by scammers. Just copy and paste the text into the scanner, and it’ll flag anything suspicious for you.
  • Slow down before you act: Spoofing, like phishing, relies on urgency and lack of attention to detail. If an email, text message, or phone call pressures you to act immediately, treat it as a red flag and verify the correspondence through official channels.
  • Use a password manager: Password managers will autofill your credentials only on legitimate domains. Even if a fake site is practically indistinguishable from the real one, your password manager can often still tell the difference.
  • Enable two-factor authentication (2FA): With 2FA enabled, even if a spoofer manages to steal your password, they won’t be able to access your account. This is particularly important for your main email and banking accounts.
  • Verify unexpected requests independently: If your bank or your boss contacts you with an unusual request, contact them via an alternative official channel. Never use the contact details provided in the suspicious message.
  • Keep software and apps updated: Spoofing attacks typically exploit outdated browser extensions, apps, and operating systems. Regularly update the tools you use to patch vulnerabilities before attackers can use them against you.
  • Check links before clicking: Hover over a URL to preview its real destination. Mismatched, misspelled, or slightly altered domains are usually a sign of spoofing.
  • Run a malware scan: If you’ve clicked on any malicious link or email attachment, you can use the antivirus to scan your Mac for malware that was installed through drive-by downloads on malicious sites or packaged with other software.
Screenshot of Moonlock, a Mac security app: The Malware Scanner screen.

Hackers can trap you in many ways. However, if you are vigilant and remain alert, you can stay safe from all these different types of spoofing attacks. Protect your personal information and account credentials diligently, and follow all cybersecurity best practices. 

MoonLock Banner
Dawna Roberts

Dawna Roberts

Dawna has spent her entire career in web dev, cybersecurity, and IT. Her work has been featured on Forbes, Adobe, Airtable, Backblaze, Cyberleaf, Lifewire, and other online publications for the past ten years.