What spoofing actually is
Caller ID spoofing is when a caller deliberately falsifies the number or name that shows up on your phone’s display to disguise who’s really calling (FCC). The number you see can be a stranger’s, a business’s, a government agency’s — or your own. In a harassment context, that means someone can call or text you from a rotating set of numbers that all look different, or spoof your number to third parties to make it look like you’re the one calling them.
Not all spoofing is illegal. The law draws the line at intent, not the act of falsifying a number itself.
The law: intent is what makes it illegal
Under the Truth in Caller ID Act, FCC rules prohibit anyone from transmitting misleading or inaccurate caller ID information “with the intent to defraud, cause harm or wrongly obtain anything of value” (FCC). Violating it can carry penalties of up to $10,000 per violation (FCC).
That “intent” clause matters because spoofing itself isn’t automatically against the rules. The FCC is explicit that there are legitimate, legal uses — its own example is a doctor calling a patient from her personal mobile phone while displaying the office number, or a business displaying its toll-free callback number instead of a direct line (FCC). A number that doesn’t match the account it’s coming from isn’t proof of a crime on its own — what turns it into a Truth in Caller ID Act violation is using that false display to defraud someone, cause harm, or wrongfully obtain something of value.
If someone is spoofing caller ID as part of a harassment or stalking pattern — to disguise who’s calling, to make you think a call is coming from someone else, or to scare you by having your own number show up on your screen — that can fall within “intent to cause harm” under the Act, though the FCC’s rules don’t spell out a scripted definition of every harassment scenario. Harassment and stalking are also addressed separately by state criminal statutes, which vary significantly from state to state — this article isn’t a substitute for checking your state’s specific harassment or stalking laws.
Why STIR/SHAKEN hasn’t made this go away
You may have heard that carriers rolled out new anti-spoofing technology and wondered why the harassing calls kept coming anyway. The technology is real, and it does help — but it has real limits worth understanding.
STIR/SHAKEN is the FCC’s name for a pair of interconnected technical standards — Secure Telephone Identity Revisited (STIR) and Signature-based Handling of Asserted information using toKENs (SHAKEN) — that let a call’s caller ID be “signed” as legitimate by the originating carrier and validated by other carriers before it reaches you (FCC). In 2020, the FCC adopted rules requiring voice service providers to implement STIR/SHAKEN on the IP portions of their networks by June 30, 2021, and has since worked to expand that obligation to more providers, including gateway and intermediate providers (FCC).
The limit built into the framework itself: STIR/SHAKEN only operates on IP networks. The FCC’s own page on the framework notes that because of this, its rules require providers still using older, non-IP network technology to either upgrade to IP or actively develop a caller ID authentication solution that works on non-IP infrastructure (FCC) — meaning authentication isn’t uniformly available across every network a call might cross. And authentication tells you whether a number was verified as legitimately originating from where it claims to — it doesn’t by itself block a call, silence a caller, or stop someone from spoofing in the first place. The FCC describes the benefit in terms of trust and reduced effectiveness, not elimination: caller ID authentication “enables subscribers to trust that callers are who they say they are, reducing the effectiveness of fraudulently spoofed calls” (FCC) — it gives carriers and call-blocking tools better information to work with, which is why blocking and labeling tools exist as a separate layer on top of it.
What actually helps: blocking, not engaging
Don’t answer unknown numbers, and don’t engage if you do. The FCC’s guidance is direct: don’t answer calls from unknown numbers, and if you do answer, hang up immediately rather than responding to questions — including ones that just want a “yes” — since that can confirm your number is active (FCC). A “local”-looking number is no guarantee of who’s actually calling. This is a trade-off, not a free action — the FCC notes that automatically enrolling in call-blocking services can be opted out of “if you are concerned about missing wanted calls” (FCC), so screening unknown numbers more aggressively can also mean a call you did want gets missed or delayed.
Use carrier and device-level blocking tools. The FCC maintains a list of tools by carrier: AT&T’s ActiveArmor app, T-Mobile’s ScamShield, Verizon’s Call Filter, and U.S. Cellular’s CallGuardian are among the carrier-side options; built-in phone features include Apple’s “Silence Unknown Callers” and Google Pixel’s “Call Screen,” along with Samsung’s Smart Call (FCC). Depending on your provider, a blocked call may go straight to voicemail, ring once before stopping, or simply never come through — check with your carrier about which behavior to expect (FCC). Third-party call-labeling and blocking apps (the FCC lists providers like Hiya, Nomorobo, and YouMail) are another layer, and many carriers now enroll customers automatically in some blocking services, with an opt-out if you’re worried about missing wanted calls (FCC).
If your own number is the one being spoofed — people call you back angry about calls they never made from your line — the FCC recommends not answering calls from unknown numbers, and if you do, explaining that your number is being spoofed and you didn’t place the call; you can also leave a note on your voicemail greeting saying the same (FCC).
File a complaint. The FCC accepts complaints about spoofed, blocked, or mislabeled calls at its consumer complaints portal — choose the phone form and “unwanted calls” issue category (FCC). A single complaint won’t stop a harasser by itself, but complaints feed the record the FCC uses for enforcement and policy.
Documenting the calls as evidence
If the spoofed calls are part of a harassment or stalking pattern rather than a one-off scam, treat them as evidence from the start rather than something to just block and forget. Screenshot caller ID displays, log dates and times, save voicemails and any text threads, and keep a simple running record rather than deleting things as you go. See documenting it and getting help for how to preserve this kind of evidence properly, including how law enforcement can request call records directly from a provider as part of an investigation.
Should you change your number?
Sometimes the harassment is coming in on your line rather than through spoofing of your number to others, and the honest answer is that a new number is a real fix but not a free one — it means updating everyone who legitimately needs to reach you, and it can complicate accounts and two-factor logins tied to the old number. If you’re weighing this because you’re leaving a monitored or shared household situation, a new phone, a clean start covers the account-side traps people hit when they try to start over, including how to actually get a line the other person can’t reach.
If this is part of a stalking pattern
Spoofed and harassing calls can be one channel in a broader pattern that also includes messages, social media, or in-person contact. If you recognize that pattern, read safety first: before you remove anything before you start blocking numbers, changing your voicemail greeting, or filing complaints — some of those actions can tip someone off that you’re building a response, and the sequencing matters more than the speed.
None of this requires figuring out who’s behind a spoofed number before you act. Blocking, documenting, and reporting all work whether or not the caller ID ever tells you the truth.