RevRing
Home
Predictive DialerPower DialerRevRing CRMLead Management & RoutingAI & AutomationAnalyticsCompliance & Security
InsuranceReal EstateLegalHealthcareLead GenerationCustomer ServiceMore Industries
CRMAPI & Developers
Pricing
BlogCompare CRMs & DialersCase StudiesLead MarketplacePublishers
About UsContact UsInvestor Relations
Link Hub
Sign In
RevRing

Revenue Acceleration Platform

Link Hub
Florida, USA

Product

  • Predictive Dialer
  • Power Dialer
  • RevRing CRM
  • Lead Management & Routing
  • AI & Automation
  • Analytics
  • Compliance & Security

Industries

  • Insurance
  • Real Estate
  • Legal
  • Healthcare
  • Lead Generation
  • Customer Service
  • More Industries

Integrations

  • CRM
  • Data Sources
  • Productivity
  • API

Learn More

  • Home
  • About Us
  • Pricing
  • Blog
  • Compare CRMs & Dialers
  • Best CRMs for Insurance
  • Best CRMs for Real Estate
  • Case Studies
  • Lead Marketplace
  • Publishers

Legal

  • Privacy Policy
  • Terms & Conditions
  • Contact Us

© 2026 RevRing. All rights reserved.

support@revring.com
← All articles

U.S. Neighbor Spoofing Laws: FTC Rule Updates and How to Report

Woman checking a suspicious incoming phone call

Neighbor spoofing is illegal under federal law when the caller intends to defraud, cause harm, or wrongfully obtain something of value, and the Truth in Caller ID Act, is the primary statute that makes it so. The FCC, FTC, and DOJ all share enforcement duties. If you get one of these calls: hang up, never send money or codes, and report it through official channels.


TL;DR:

  • A false caller ID violates federal law only when the caller intends fraud, harm, or wrongful gain; legitimate business callback numbers can be lawful.
  • Regulators increasingly pursue VoIP providers and platforms carrying spoofed traffic, rather than focusing only on individual callers, to disrupt the revenue behind mass campaigns.
  • STIR/SHAKEN signatures can disappear on older networks or between carriers, and even the highest attestation does not verify the speaker’s identity.
  • Hang up, never send money or share security codes, report the call to the FTC and FCC, and contact your bank if you already paid.

Revring
Bring Compliance Into Your Workflows
RevRing brings communication tools, CRM, AI automation, and compliance functionalities together in tailored workflows for teams managing customer outreach.
Explore RevRing

Table of Contents

  • 1. What the law says about caller ID spoofing
  • 2. How enforcement and penalties actually work
  • 3. Why STIR/SHAKEN doesn’t stop every spoofed call
  • 4. What to do if you get a spoofed call
  • 5. Recent rule changes and enforcement trends
  • Why communications compliance matters for businesses
  • FAQ
  • Sources

1. What the law says about caller ID spoofing

The Truth in Caller ID Act, codified at 47 U.S.C. § 227(e), is the backbone of federal spoofing law. In plain terms, the FCC’s implementing rules make it illegal to transmit misleading or inaccurate caller ID information with intent to defraud, cause harm, or wrongfully obtain anything of value. Intent is the hinge. A call that displays a false number but carries no fraudulent purpose does not automatically violate the statute.

That distinction matters because plenty of spoofing is lawful. Common legitimate uses include:

  • A business displaying a central callback number instead of an employee’s direct extension
  • A doctor’s office or clinic routing outbound calls through a main line for patient callbacks
  • A company using a toll-free or branded number across multiple call centers for consistency

Congress later passed the RAY BAUM’S Act, which widened the statute’s reach. The updated rules extended coverage to calls and text messages originating from outside the United States when they target U.S. recipients, and they folded in alternative voice services beyond traditional telephone lines. That closed a loophole that let overseas callers and VoIP-based robocallers dodge liability simply by routing traffic through foreign carriers.

2. How enforcement and penalties actually work

Three federal agencies divide the work. The FCC enforces the Truth in Caller ID Act directly and can issue forfeiture orders, civil penalties assessed per violation. The FTC pursues civil enforcement under its Impersonation Rule, often securing consumer redress rather than just penalties. The DOJ steps in to file suit when forfeitures go unpaid or when criminal conduct warrants prosecution.

In practice, enforcement tends to follow this pattern:

  1. A carrier or consumer complaint triggers a traceback investigation
  2. The FCC or FTC identifies the responsible party and issues a citation or proposed forfeiture
  3. If the target ignores the penalty, the Department of Justice files suit to recover the debt through the courts

Penalties can run into the hundreds of thousands of dollars per violation range in serious cases, and the DOJ has pursued recovery actions against individuals for illegal spoofed robocall campaigns. More recent enforcement has shifted upstream. Regulators increasingly target VoIP providers and platform operators that carry spoofed traffic at scale, not just the individual who dialed the number, because choking off the revenue chain does more to stop mass campaigns than chasing one caller at a time.

3. Why STIR/SHAKEN doesn’t stop every spoofed call

STIR/SHAKEN is the industry framework carriers use to authenticate caller ID on IP-based networks. Each call carries a signed digital certificate called a PASSporT, and the originating carrier assigns an attestation level: A means full attestation (the carrier knows the caller and the number), B means partial, and C means gateway attestation, where the carrier can vouch for the call’s entry point but not the actual source.

That attestation system has real limits:

  • Calls that pass through non-IP networks, like older copper or TDM lines, often can’t carry STIR/SHAKEN signatures at all
  • Some call paths “wash” attestation as calls cross between networks, stripping or downgrading the signal before it reaches your phone
  • An A-level attestation confirms the originating provider’s claim, not that the person speaking is who they say they are

An A-level attestation gives carriers the highest confidence that a number was properly assigned, according to the FCC’s STIR/SHAKEN framework, but it still does not verify the identity of whoever is actually talking to you.

The FCC has proposed fixes to close these gaps, including call branding (showing verified business names on screen) and expanding authentication to non-IP networks. Both proposals aim to extend the trust STIR/SHAKEN already builds on modern IP calls to the older infrastructure that still carries a meaningful share of U.S. traffic.

4. What to do if you get a spoofed call

Neighbor spoofing calls almost always follow a script designed to create urgency. The response that limits damage is the same every time.

  1. Hang up immediately. Don’t engage, don’t answer security questions, don’t confirm your name.
  2. Never send money, gift card codes, cryptocurrency, or bank transfers based on a call alone.
  3. Report the call to ReportFraud.ftc.gov and file a complaint with the FCC.
  4. If the caller claimed to be police or another government agency, contact your local law enforcement directly using a number you look up independently.
  5. Save evidence: screenshot the caller ID, note the time and date, and keep any voicemail or text message the caller left.

Pro Tip: If you’ve already shared payment information or sent money, contact your bank or payment app immediately. Many can freeze or reverse a transaction within a limited time, but that opportunity may close quickly.

Scammers impersonating local police are a recurring pattern the FTC has flagged, often demanding payment through gift cards or payment apps while posing as officers collecting a fine or bail. Documentation matters here. A clear record of what was said, when, and from what number gives investigators something to work with and gives you a paper trail if you need to dispute a charge with your bank.

Call documentation branching to investigators and bank

5. Recent rule changes and enforcement trends

The regulatory landscape around spoofing has moved quickly. The FTC finalized its Impersonation Rule in 2024 and has used it to bring enforcement actions that delivered more than $70 million in consumer redress, with cases active through 2025 and 2026. The same reporting shows people lost $3.5 billion to imposter scams in 2025, a scale that explains why agencies keep expanding their tools.

Current developments worth tracking:

  • The FCC has opened rulemaking on non-IP caller ID authentication, aiming to extend verification to calls that STIR/SHAKEN can’t currently cover
  • A parallel call branding proposal would let verified businesses display their name on screen, reducing reliance on caller ID numbers alone
  • Enforcement priorities continue shifting toward the revenue chain: VoIP providers, lead generation platforms, and payment processors that enable spoofing campaigns at volume

That upstream focus reflects a practical reality. Shutting down one spoofed number does little when a platform can generate thousands more within hours. Targeting the infrastructure behind the calls produces a bigger drop in overall volume than chasing individual violators ever could.

Why communications compliance matters for businesses

Following FCC and FTC guidance on caller ID isn’t just a legal formality; using phone append data and intent signals helps verify contact numbers before calling to reduce TCPA exposure. It protects the consumers you’re calling and it protects your business from the same forfeitures and civil penalties aimed at bad actors. We build compliance playbooks and features directly into our platform because we’ve seen how fast a single complaint can turn into regulatory exposure. Any business making outbound calls should treat agency guidance as the floor, not the ceiling.

— Marc

FAQ

How do I block neighbor spoofing calls?

Most major carriers offer free call blocking and labeling tools that flag suspected spoofed calls before you answer, and your phone’s settings may let you silence unknown numbers automatically. The FCC recommends checking with your carrier directly, since available tools vary by provider.

Can a spoofed call be traced?

Yes. Carriers and a private-sector consortium run coordinated traceback investigations that follow a call through each network it passed, and these tracebacks are the standard first step before the FCC or FTC issues a penalty. Cooperation with traceback requests is a legal obligation for providers, not optional.

What happens if you’ve been targeted by a spoofed call?

If you haven’t sent money or shared sensitive information, the best move is reporting the call to ReportFraud.ftc.gov and the FCC complaint portal. If you did send payment, contact your bank or payment app immediately and file a police report if the caller impersonated law enforcement.

Does *57 still work to trace a spoofed call?

The call trace service only works on landlines through participating carriers, and it traces the actual originating line, not a spoofed display number, so it’s largely ineffective against neighbor spoofing. Modern spoofed calls typically route through VoIP services that call trace was not designed to track.

Sources

  • Caller ID spoofing | Federal Communications Commission
  • Truth-in-Caller-ID rules (Federal Register)
  • Scammers are impersonating local law enforcement | Consumer Advice
  • FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025 | Federal Trade Commission