Spoofing

Spoofing is masking the origin of a communication so it appears to come from someone you trust. An attacker can forge the caller ID on a phone call, the 'from' name and address on an email, or a website's look, making what you see line up with a legitimate brand. Spoofing is the disguise that makes phishing and impersonation scams believable.

Check a suspicious message now

The check runs in your browser. What you paste stays on your device. It is not sent to our servers or anyone else, and nothing is stored.

The image is read on your device. It is never sent or stored.

Please don't paste other people's personal data.

Or try a real one:

Get it free

Or check it on Telegram

Example

Your phone rings and the caller ID shows your bank's real name and number, but the call is actually placed by a scammer who faked that ID to convince you the fraud warning they're about to deliver is genuine.

How to recognize it

  • A caller ID or sender name that looks right but the request feels off
  • An email display name matching a brand while the real address doesn't
  • A website that looks identical to a trusted one on a slightly different domain
  • Replies bouncing or going to an address you don't recognize

How Hunch flags it

Hunch focuses on signal categories that survive the disguise, the actual domain behind a display name, lookalike addresses, and whether a message pairs a trusted appearance with an urgent credential or payment ask.

FAQ

What is spoofing?

Faking the source of a call, email, or website so it appears to come from a trusted person or organization.

Can scammers really fake a real phone number?

Yes. Caller ID is easy to forge, so a familiar name or number on your screen is not proof that the call is genuine.

How do I tell if an email is spoofed?

Look past the display name at the actual sending address and the real link destinations; a spoofed message usually reveals a mismatched domain there.

Related