What is spoofing?
Spoofing is when a fraudster forges their sender identity, so a message appears to come from someone you trust. It could be an email from the bank, a call showing a familiar Danish number on the display, or a website that is a faithful copy of the real one. Spoofing is rarely the goal in itself: the forgery is the door opener that gets the recipient to lower their guard before the actual fraud begins. The Danish Centre for Cyber Security regularly warns about spoofing waves targeting Danes, typically peaking in the fraud season leading up to Christmas.
Types of spoofing: email, phone and web
Email spoofing: The sender address of an email is forged, so the mail appears to come from a colleague, a supplier or your own domain. It is the foundation of most phishing attacks and CEO fraud. The technical protection is called DMARC, together with SPF and DKIM.
Caller ID spoofing: The caller ID is forged, so the phone shows a number you know, for example the bank's or the police's. The fraudster often poses as support or a fraud department and pushes for quick decisions.
Web spoofing: A fake website mimics a genuine one, often with a domain name that differs by only a single character. It is typically combined with links in fake emails or text messages.
How to spot spoofing
- Check the full sender address, not just the display name.
- Be sceptical of urgency, threats and unusual payment requests.
- Call back on a number you look up yourself, never the number from the call or the email.
- Check the address bar in the browser before logging in or paying.
- Remember: the bank, the police and the Danish Tax Agency never ask for MitID (Denmark's national digital ID), codes or transfers over the phone.
My number is being spoofed, what do I do?
If you find that your own number is being used as a fake sender of calls you never made, your phone is not necessarily hacked: the fraudster has simply forged the caller ID. Do three things. Report the spoofing to the police via politi.dk, contact your telecoms provider, who can advise and in some cases filter the traffic, and warn your contacts so they do not call the fraudster back.
If your company's domain is being misused for email spoofing, the solution is technical: a correctly configured DMARC policy makes recipients' mail servers reject the forged emails automatically.
Spoofing vs. phishing: what is the difference?
In short, spoofing is the method and phishing is the goal. Spoofing forges the identity, while phishing is the actual attempt to trick information, money or access out of the victim. The two almost always go hand in hand: a phishing email becomes far more convincing when the sender looks genuine. That is why the defence must cover both: technical protection of the domain and alert employees.
How MI Support IT can help
We protect your domain against email spoofing with correctly configured SPF, DKIM and DMARC as part of our IT security solutions, and we train your employees to recognise forged emails and calls with security awareness training. Contact us for a no-obligation conversation about how exposed you are today.