Support · Legal
Verified RCS · SMS · MMS

Can RCS be spoofed?

Compliance & Security

Reviewed by , VP of Global Operations, Signalmash · Last reviewed · Editorial standards

Quick answer

RCS business messaging is far harder to spoof than SMS, by design. Every legitimate business RCS message is sent from a verified RCS agent, a sender identity that carriers and Google have vetted and that displays the brand’s name, logo, and a verification checkmark. Because that identity can’t simply be faked the way a sender ID or phone number can be on SMS, impersonating a verified brand over RCS is much more difficult. That verified-sender model is one of RCS’s biggest security advantages over legacy texting.

See this on your own phone in about 30 seconds: get a free sender ID test →

SMS is notoriously easy to spoof: scammers routinely fake sender IDs and short codes, which is why text phishing (“smishing”) is rampant. RCS raises the bar by tying every business message to a vetted, branded identity, so the verification badge becomes a trust signal consumers can look for.

No system is perfectly immune, attackers may still try to abuse unverified channels or fall back to SMS, which is exactly why the verified-sender badge matters: it gives consumers a reliable way to tell a real brand message from an imposter.

Knowing where the residual risk actually sits is more useful than the reassurance, and there are three places it does not go away. The first is the fallback leg: a message that falls back is an ordinary SMS with no verified identity, so a programme that depends on customers trusting a badge has to account for the sends where no badge appears. The second is lookalike registration, where an attacker registers a plausible but different brand rather than forging yours, which verification makes harder and slower but does not make impossible. The third is the ordinary phishing link, which does not require impersonating anyone: a legitimate-looking thread still carries URLs, and a customer trained to tap buttons is not automatically good at judging destinations.

That last one is the reason to be careful how you train your own customers. If your genuine messages routinely ask people to tap through to a page and sign in, you are teaching exactly the behaviour an attacker needs, and the verified badge on your messages does not protect them on someone else's. The stronger pattern is to keep the action inside the thread where you can, use suggested replies for confirmations rather than links, and where a link is unavoidable, send it to a page on your primary domain rather than a redirect or a shortener.

What to tell customers is short and worth putting in your help content: a genuine business message shows the brand name, logo and checkmark, we will never ask for a password, a full card number or a one-time code in a chat, and anything asking for those is fraudulent regardless of how it looks. Give them a way to report a suspicious message, and make sure the reply path in your own thread is monitored so a worried customer can ask rather than guess.

Key facts
  • Verified RCS agents are vetted by carriers/Google; the brand identity isn’t trivially forgeable like an SMS sender ID.
  • CTIA guidance explicitly says message-number spoofing should be avoided and must comply with applicable law.
  • The verification checkmark is the consumer’s anti-spoofing signal.
  • Residual risk sits in the SMS fallback leg, lookalike brand registration, and ordinary phishing links inside plausible threads.
  • Avoid training customers to tap through and sign in, since the badge does not protect them on another sender's message.
  • Publish a short "what a real message from us looks like" note and monitor the reply path so customers can check.
How verification, consent, and STOP handling actually work on SimplyRCS. Read the trust page →

← All RCS questions