Phishing is the con itself, tricking someone into giving up passwords or card details through a fake message or page, while spoofing is the disguise that makes the trick believable, such as faking a sender address or location. Spoofing is often the tool that makes phishing work, but the two are not the same thing.
The core difference
Phishing is the attempt to steal information; spoofing is the act of faking identity to disguise the attempt.
- phishing — sending fake emails, texts or web pages that imitate a trusted organisation to steal information: the email claiming to be from her bank was phishing.
- spoofing — falsifying identity or other identifying details, such as a sender address or location, to deceive or gain access: criminals are phishing for login details using fake delivery notices, the sender address spoofed to look genuine.
How to tell them apart
One way to keep the two apart is to think of phishing as the scam and spoofing as the disguise worn to pull it off. A phishing email asks you to click a link and enter your password; the spoofing is what makes that email's sender field say it comes from your bank rather than the actual scammer. Spoofing can also apply outside phishing entirely, such as faking a location or a program appearing to work normally while it has secretly been altered.
The confusion tends to surface in security training, where the words get used almost interchangeably even though phishing describes the goal and method of the con, while spoofing describes only the act of faking identifying information. A message can be spoofed without being phishing, if nothing in it asks for information, and a phishing attempt does not strictly require spoofing if it simply relies on a convincing story instead of a faked identity.