Mastodon Mastodon Mastodon Mastodon

Spoofing

Updated: · CyberSecureFox Editorial Team

Spoofing is a type of attack in which an attacker falsifies identifying information – a sender address, phone number, IP address or website – to pose as a trusted source.

Types of spoofing

  • Email spoofing – a forged “From” address makes a message look as if it comes from a bank, a colleague or the CEO. It is the basis of most phishing and business email compromise scams.
  • Caller ID and SMS spoofing – fake numbers or sender names in calls and text messages, used in vishing and smishing.
  • Website and domain spoofing – copies of real sites on lookalike domains, often registered through typosquatting.
  • IP spoofing – forged source addresses in network packets, used to hide the origin of traffic and in reflection DDoS attacks.
  • DNS and ARP spoofing – false answers that redirect victims to attacker-controlled servers inside a network, enabling man-in-the-middle attacks. The 2008 Kaminsky bug showed how DNS caches could be poisoned at scale.
  • GPS spoofing – fake satellite signals that mislead ships, aircraft or drones.

Why spoofing works

Many core internet protocols were designed without authentication. Classic email (SMTP) does not check whether the sender is real, and IP packets carry whatever source address their creator writes into them. Spoofing exploits this trust and human habits: people believe a familiar name or number.

How to defend

  • Publish SPF, DKIM and a DMARC policy set to “quarantine” or “reject” for your domains.
  • Verify unusual payment or data requests through a second, known channel.
  • Use network filtering against forged source addresses (BCP 38), DNSSEC and dynamic ARP inspection.
  • Train employees to check real sender addresses and URLs.
Synonyms:
spoofing attack