SMS spoofing is the practice of falsifying the sender information on a text message so it appears to come from a trusted person, brand, or agency rather than from the actual sender. It is the text messaging equivalent of forging the return address on an envelope, and it is the enabling technique behind many of the most damaging text scams: fake bank fraud alerts, fake delivery notices, fake government warnings, and messages that appear mid-thread from a company you genuinely do business with.
Understanding spoofing matters for two audiences at once. Consumers need it to judge whether a sender name can be trusted (short answer: not by itself). And organizations that text their communities need it to understand why sender registration, vetting, and consistent numbers are not bureaucratic hurdles but the actual anti-impersonation infrastructure of the US messaging ecosystem.
This glossary article defines SMS spoofing, explains how it works technically, covers the FCC rules and 10DLC registration system built to counter it, and lays out defenses for both individuals and senders.
SMS Spoofing Definition
SMS spoofing: manipulating the originating address (sender ID) of a text message, whether a phone number or an alphanumeric name, so the message displays as coming from someone other than its true source.
Not all sender substitution is malicious. Legitimate uses exist, such as a business sending from a provisioned brand number through an authorized messaging platform. The term "spoofing" as commonly used, and as regulated, refers to deceptive falsification: transmitting misleading or inaccurate sender information with intent to defraud, cause harm, or wrongly obtain something of value. US law treats that intent as the dividing line. The Truth in Caller ID Act, which the FCC's implementing rules extend to text messages following the RAY BAUM'S Act, prohibits exactly this kind of harmful, deceptive sender falsification.
How SMS Spoofing Works
A text message carries an originating address field set when the message enters the network. Several routes let that field display something other than the sender's real identity:
- Alphanumeric sender IDs. In many countries outside the United States, messages can display a name like "YourBank" instead of a number. Where networks accept these IDs without verifying who is entitled to the name, an attacker can simply claim it. This is the classic spoofing vector internationally. Critically, US carriers do not support alphanumeric sender IDs for standard A2P (application-to-person) messaging: commercial texts to US phones come from real numeric senders, which is itself an anti-spoofing measure. A text displaying a name instead of a number in the US should raise, not lower, your suspicion.
- Unvetted routes into the network. Attackers exploit loosely policed international gateways or gray routes to inject messages with falsified originating numbers.
- Thread hijacking through number reuse. If a scammer transmits using the same number a brand legitimately texts from, phones may group the fake message into the existing conversation thread, inheriting all its trust. This is why spoofed bank alert scams are so effective.
- Adjacent techniques. SIM swapping (taking over the victim's number itself) and smishing (phishing content regardless of sender) are different attacks, but they combine with spoofing constantly. Our explainer on what smishing is and how SMS phishing works covers how the content side of these scams operates once the sender field has done its deceptive work.
For a deeper technical breakdown of what the sender field is and the forms it can take (long codes, short codes, toll-free numbers, alphanumeric IDs), see our guide to how SMS sender IDs work.
Spoofing vs. Related Attacks
| Attack | What is falsified | Typical goal |
|---|---|---|
| SMS spoofing | The sender ID on a message | Make a fraudulent message look trusted |
| Smishing | The content and links in a message | Steal credentials or payments via SMS |
| Caller ID spoofing | The number shown on a phone call | Impersonate banks, agencies, or neighbors by voice |
| SIM swapping | Control of the victim's actual number | Intercept calls, texts, and security codes |
| Email spoofing | The From address on an email | Phishing and business email compromise |
These attacks are frequently chained: a spoofed sender delivers a smishing link, and the harvested codes enable account takeover.
What US Rules and Infrastructure Do About Spoofing
The United States has built a layered defense around sender identity, and it is worth understanding because it explains what a legitimate commercial text looks like.
Legal prohibitions. The Truth in Caller ID Act (47 U.S.C. 227(e)) prohibits transmitting misleading or inaccurate caller ID information with intent to defraud, cause harm, or wrongfully obtain anything of value, and following the RAY BAUM'S Act the FCC's rules apply this prohibition to text messages. Separately, the TCPA (47 U.S.C. 227) and the FCC's rules at 47 CFR 64.1200 govern consent for automated texts, and the FCC's robotext orders require mobile carriers to block texts that are highly likely to be illegal, including messages from invalid, unallocated, or unused numbers and from numbers on a reasonable Do-Not-Originate list. Consumers can file complaints about spoofed or scam texts at fcc.gov/complaints.
10DLC registration and vetting. For A2P messaging over standard 10-digit long codes, US carriers require businesses to register their brand and campaigns through the 10DLC system. Registration ties every sending number to a verified business identity and a declared use case before commercial traffic flows. That vetting is anti-spoofing infrastructure in the most practical sense: it means the number texting you about your appointment is contractually and technically bound to a known, verified organization. Short codes undergo their own approval process, and toll-free numbers require verification as well.
Industry standards. The CTIA Messaging Principles and Best Practices set ecosystem-wide expectations for consent, sender identification, and abuse prevention, and carriers enforce them through their messaging policies. Anyone can report spam and suspected spoofed texts by forwarding them to 7726 (SPAM), which feeds carrier blocking systems.
The upshot: in the US, legitimate organizations text from registered numeric senders with verified identities. Messages that fight this system, arriving from overseas numbers, email-to-text gateways, or unregistered numbers that change constantly, are announcing what they are.
How to Protect Yourself from Spoofed Texts
- Trust the request, not the sender field. Since the displayed sender can be falsified, judge every message by what it asks. Requests for codes, passwords, payments, or urgent link taps deserve independent verification no matter what the thread looks like.
- Verify out-of-band. If "your bank" texts about fraud, call the number on the back of your card, not any number in the text. If "a delivery service" flags a package, open its official app.
- Never share one-time passcodes. No legitimate organization asks you to read back a security code. A message mid-thread asking for one is an attack, even inside a real conversation history.
- Report and block. Forward suspicious texts to 7726, report scams to the FTC at ReportFraud.ftc.gov, file spoofing complaints at fcc.gov/complaints, and report losses to the FBI at ic3.gov.
- Be skeptical of name-only senders. In the US, a commercial message displaying an alphanumeric name rather than a number is unusual on its face and warrants extra caution.
What Organizations Should Do to Prevent Being Impersonated
If your nonprofit, health system, school, or agency texts the public, spoofing is a brand protection issue. You cannot stop criminals from trying to imitate you, but you can make imitation obvious:
- Register everything. Send only through properly registered 10DLC numbers, verified toll-free numbers, or approved short codes, with your brand vetted behind them.
- Use one consistent, published number per audience. When your community knows your number, an unfamiliar sender claiming to be you fails the first test. Publish the number on your website.
- Keep consent clean. Text only opted-in recipients under TCPA requirements, identify your organization in messages, and honor STOP instantly. Legitimate hygiene makes fraudulent traffic stand out.
- Never ask for what attackers ask for. Adopt and publish a policy that you never request passwords, one-time codes, or payment through text links.
- Give recipients a live verification channel. Two-way messaging with an AI Powered Helper means a suspicious recipient can reply "did you send this" and get an immediate, accurate answer instead of guessing, or instead of trusting the spoofer.
Frequently Asked Questions
Can someone spoof my personal phone number in a text?
Yes. Attackers who inject messages through weakly policed routes can falsify an originating number, including a personal one. If contacts report strange texts from your number, you likely have not been hacked; your number was forged as a return address. Deceptive spoofing with intent to defraud or harm is unlawful under 47 U.S.C. 227(e), and you can report it at fcc.gov/complaints.
Is SMS spoofing illegal in the United States?
Spoofing with intent to defraud, cause harm, or wrongfully obtain anything of value is prohibited under the Truth in Caller ID Act, and FCC rules extend this prohibition to text messaging. Sender substitution without harmful intent, such as an authorized platform sending from a business's provisioned number, is a normal part of legitimate messaging.
How can I tell if a text sender is spoofed?
Often you cannot tell from the sender field alone, which is the point of the attack. Evaluate the request instead: legitimate organizations do not ask for passwords, one-time codes, or urgent payments through text links. Verify through official channels you locate yourself, and treat mid-thread requests for security codes as attacks regardless of the conversation history.
Why don't US businesses text from names instead of numbers?
US carriers do not support alphanumeric sender IDs for standard A2P messaging. Businesses send from registered 10DLC numbers, verified toll-free numbers, or approved short codes, each tied to a vetted brand identity. This numeric, registered model makes it substantially harder to claim someone else's name than in markets where any sender can display any label.
Does 10DLC registration stop spoofing?
It does not make forgery impossible, but it changes the economics. Registration binds legitimate commercial traffic to verified business identities, gives carriers a basis for blocking unregistered and invalid-number traffic under the FCC's robotext rules, and lets recipients build trust in one known number. Impersonators are pushed to the unregistered margins, where their messages look and behave differently.
Text from a Sender Your Community Recognizes with FRANSiS
FRANSiS provisions registered, vetted sending numbers for nonprofits, healthcare organizations, schools, and agencies, and pairs them with two-way conversations powered by an AI Powered Helper so recipients can always verify it is really you. To build a texting presence impersonators cannot credibly fake, contact the FRANSiS team.


