Trust & compliance

Caller ID spoofing

Caller ID spoofing means the number shown to the called party is not the true originating line identity. Some substitution is ordinary telephony. Spoofing with intent to defraud, cause harm, or wrongfully obtain value is unlawful in the United States.

Updated August 27, 2026

Caller ID (and the ANI used in the network) can be rewritten at a PBX, a CPaaS API, or a gateway. That rewrite is how a sales floor shows one main DID instead of 40 extensions. The same mechanism is how scam robocalls display a local number or a bank's published line. The technology is not the legal test. Intent and the displayed identity are.

Lawful vs unlawful

"Neighbor spoofing" (displaying a nearby NANP number you do not use) is a common scam pattern. Whether a given call is unlawful depends on facts and intent, not on the phrase alone.
PracticeWhat is happeningTypical legal posture in U.S. federal law
Presenting a number you are authorized to useOutbound from a branch shows the published company number. The originating provider may attest it under STIR/SHAKEN if it has a verified association.Ordinary CLI / caller-ID substitution. Still subject to TCPA (telemarketing must transmit caller ID) and provider contracts.
Blocking caller ID (*67 or line-level restrict)The network is told not to deliver calling-number display. The call still has a billing identity in the carrier network.The Truth in Caller ID Act expressly does not restrict blocking caller ID. Telemarketers are separately required to transmit caller ID under FCC telemarketing rules.
Unlawful spoofingKnowingly transmitting misleading or inaccurate caller ID with intent to defraud, cause harm, or wrongfully obtain anything of value (voice or text).Prohibited by 47 U.S.C. § 227(e) (Truth in Caller ID Act of 2009, as amended). FCC and DOJ enforcement. Not the same statute as the TCPA autodialer rules.

Truth in Caller ID Act

Codified at 47 U.S.C. § 227(e), the Act makes it unlawful for a person in the United States (or a person abroad if the recipient is in the United States) to cause a caller identification service to knowingly transmit misleading or inaccurate caller ID, in connection with voice or text, with the intent to defraud, cause harm, or wrongfully obtain anything of value, unless an FCC exemption applies. Law-enforcement and court-authorized exemptions exist in the FCC's implementing rules.

The Act's blocking clause matters: hiding your number is not the same as putting someone else's number on the call. *67 is a CLASS code that requests calling-number delivery restriction for that call. It is privacy, not impersonation.

*67 vs spoofing vs CNAM

*67
Per-call caller ID blocking on many NANP lines. The called party's phone may show "Private," "Blocked," or "Unknown." This is not a forged number.
Spoofed number
A displayed or signaled number that is not the true originating identity. May still pass through some networks if unsigned or if a gateway signs C-level.
CNAM
The name database lookup from the number. Spoofing the number can cause the wrong name to appear if CNAM is queried on the fake number. STIR/SHAKEN does not fill CNAM.

Spoofed robocalls

Illegal robocall campaigns often spoof local local numbers so the call looks like a neighbor, or spoof a trusted brand. STIR/SHAKEN makes it easier for terminating networks to treat unsigned or gateway-signed spoofing as risky. It does not make spoofing impossible on TDM hops. Analytics blocking, traceback, and the FCC robocall mitigation database are the rest of the industry response. For businesses, the practical control is: only send calling numbers your originating provider will attest, and do not present numbers you cannot document a right to use.

What the called party actually sees

  • Network number (ANI / SIP From / P-Asserted-Identity) may differ from the number shown on a handset.
  • Some carriers display a verification mark or "spam likely" from analytics, not from spoofing detection alone.
  • A correct STIR/SHAKEN A attestation can still appear next to a call the recipient did not want. Authentication is not consent. See TCPA.

Operational checks

  1. Inventory which numbers you present on outbound voice and on A2P text.
  2. Confirm the originating provider's attestation for each number (A vs B vs unsigned).
  3. Do not use random NANP numbers to raise answer rates. That pattern is how neighbor spoofing is described in enforcement actions.
  4. Keep a callback path: the displayed number should accept return calls.