How it works
Spoofing falsifies an apparent identity or source to make something seem to originate elsewhere. The term covers different contexts, including messages, caller identification and network information. A display name, sender label or logo is therefore not equivalent to verified authorization, even when it matches an organization you recognize.
A practical example
An email could display a familiar manager’s name while directing replies to an unrelated address. A call could show a known organization’s number without actually coming from it. Neither example necessarily means that the real organization’s account was compromised; imitation and takeover are distinct possibilities.
What to check
Check the actual destination and requested action, not only the visible name. Verify sensitive instructions through an independently known contact. Mail authentication information can help administrators investigate but needs correct interpretation. Preserve the original message or call details rather than forwarding only a screenshot that loses context.
Limits and safe use
A legitimate unfamiliar address is not automatically spoofing, and authenticating one communication channel does not authorize every payment instruction. Conversely, a message from a genuinely compromised account may pass technical checks. Treat identity, account integrity and authorization as separate questions, especially for changed bank details, account recovery or unexpected remote access.