Skip to main content

IT security

What is spoofing?

Spoofing is forging the sender of an email, phone call or website. Learn to recognise spoofing, and see what to do if your number is being misused.

In short

Spoofing is a technique where fraudsters forge a sender identity, so an email, a phone call or a website appears to come from someone you know and trust, for example your bank, your telecoms provider or your own boss.

The goal is typically to trick information, money or access out of the recipient, and spoofing is therefore often used as the first step in phishing attacks and CEO fraud against both individuals and Danish businesses. The most common forms are email spoofing with a forged sender address, caller ID spoofing where the phone's display shows a fake number, and web spoofing with fake copies of well-known websites.

Technical controls such as SPF, DKIM and DMARC can block forged emails from your domain, while staff training catches the attempts that slip through the filters. MI Support IT helps Danish businesses protect their domains against spoofing and train employees to recognise forged messages and calls.

Back to the glossary

What is spoofing?

Spoofing is when a fraudster forges their sender identity, so a message appears to come from someone you trust. It could be an email from the bank, a call showing a familiar Danish number on the display, or a website that is a faithful copy of the real one. Spoofing is rarely the goal in itself: the forgery is the door opener that gets the recipient to lower their guard before the actual fraud begins. The Danish Centre for Cyber Security regularly warns about spoofing waves targeting Danes, typically peaking in the fraud season leading up to Christmas.

Types of spoofing: email, phone and web

Email spoofing: The sender address of an email is forged, so the mail appears to come from a colleague, a supplier or your own domain. It is the foundation of most phishing attacks and CEO fraud. The technical protection is called DMARC, together with SPF and DKIM.

Caller ID spoofing: The caller ID is forged, so the phone shows a number you know, for example the bank's or the police's. The fraudster often poses as support or a fraud department and pushes for quick decisions.

Web spoofing: A fake website mimics a genuine one, often with a domain name that differs by only a single character. It is typically combined with links in fake emails or text messages.

How to spot spoofing

  • Check the full sender address, not just the display name.
  • Be sceptical of urgency, threats and unusual payment requests.
  • Call back on a number you look up yourself, never the number from the call or the email.
  • Check the address bar in the browser before logging in or paying.
  • Remember: the bank, the police and the Danish Tax Agency never ask for MitID (Denmark's national digital ID), codes or transfers over the phone.

My number is being spoofed, what do I do?

If you find that your own number is being used as a fake sender of calls you never made, your phone is not necessarily hacked: the fraudster has simply forged the caller ID. Do three things. Report the spoofing to the police via politi.dk, contact your telecoms provider, who can advise and in some cases filter the traffic, and warn your contacts so they do not call the fraudster back.

If your company's domain is being misused for email spoofing, the solution is technical: a correctly configured DMARC policy makes recipients' mail servers reject the forged emails automatically.

Spoofing vs. phishing: what is the difference?

In short, spoofing is the method and phishing is the goal. Spoofing forges the identity, while phishing is the actual attempt to trick information, money or access out of the victim. The two almost always go hand in hand: a phishing email becomes far more convincing when the sender looks genuine. That is why the defence must cover both: technical protection of the domain and alert employees.

How MI Support IT can help

We protect your domain against email spoofing with correctly configured SPF, DKIM and DMARC as part of our IT security solutions, and we train your employees to recognise forged emails and calls with security awareness training. Contact us for a no-obligation conversation about how exposed you are today.

Shall we talk about your business and your needs?

Real people talking to real people. We get back to you the same day.