The weekly report from the office firewall has two hundred lines that say "IP spoof dropped". The same week, a news story describes a website knocked offline by traffic that seemed to come from thousands of ordinary servers, none of which had been hacked. Both involve the same trick: a packet that lies about where it came from.
This post explains what IP spoofing is, why a forged address can flood a server but cannot open a web page, the main attack types, what that log line means and how networks block forged packets. It also explains why a proxy or a VPN is not IP spoofing. There is no how-to here, only how to recognize and prevent it.
What is IP spoofing?
Everything sent over the internet travels in packets, and every packet starts with a header that holds two addresses: the destination and the source. What Is an IP Address? explains who hands them out. The computer that builds a packet writes both itself.
IP spoofing means putting an address in the source field that does not belong to the sender. The Internet Protocol has no built-in check for this. Routers forward a packet by reading its destination; the source is taken on trust unless a network along the way verifies it. "Spoof" simply means fake, as in a spoofed email, but here the fake is the address of the machine itself.
How does IP spoofing work?
A spoofed packet crosses the internet in five steps:
- The sender writes the header by hand. Normal programs let the operating system fill in the source; forging it needs full control of the machine, so spoofed traffic mostly comes from servers or infected devices.
- The first network decides. Only the sender's own provider knows which addresses belong to that customer. If it checks sources, the packet dies here.
- Routers pass it on, reading only the destination.
- The target accepts it as a normal packet from the forged address.
- The reply goes to the real owner of the forged address, not to the sender.
Step 5 shapes everything else: a spoofer can send but cannot receive.
Why can't a spoofed IP address open a website?
Web pages, logins and downloads run over TCP, and TCP opens every connection with a three-way handshake, described in TCP vs. UDP:
- The client sends a SYN ("I want to connect") with a starting sequence number.
- The server replies with a SYN-ACK carrying its own starting number, chosen at random.
- The client sends an ACK that repeats the server's number plus one. Only then can data flow.
With a forged source, the SYN-ACK goes to the real owner of that address. The spoofer never sees the server's number, cannot write a valid step 3, and the connection never opens. No request is sent, no page comes back.
Older systems sometimes used predictable sequence numbers, which let an attacker guess the answer blindly and fake a connection from a trusted address. RFC 6528 traces that attack to a 1985 paper by Robert Morris and requires numbers an outsider cannot predict.
UDP has no handshake: one request gets one reply. That makes it the natural carrier for spoofed traffic.
Types of IP spoofing attacks
The column that matters most is whether the attack needs to see replies.
| Attack | What is forged | Who is hurt | Needs replies? | Main defense |
|---|---|---|---|---|
| SYN flood | Random sources on connection requests | The server's connection table | No | SYN cookies, filtering (RFC 4987) |
| Reflection and amplification | The victim's address, on UDP requests to public servers | The victim | No | Provider filtering, no open UDP services |
| Blind injection or reset | Both ends of a TCP connection | The two parties | No, it guesses | Random sequence numbers, encryption |
| Trust abuse | An address a system trusts | Services that trust IPs alone | Yes, so it mostly fails | Real authentication |
| ARP spoofing | The IP-to-MAC link on a local network | People on the same Wi-Fi | Yes, it sits on the path | Switch protection, HTTPS, VPN |
ARP spoofing is a relative of IP spoofing. On a local network, ARP matches IP addresses to hardware addresses (What Is a MAC Address?). A device on the same Wi-Fi can claim the router's address and pull other people's traffic through itself, so it is used for eavesdropping. Business switches block it with features such as Dynamic ARP Inspection; on shared Wi-Fi, HTTPS and a VPN protect your traffic, as Is Public Wi-Fi Safe? explains.
How does IP spoofing power DDoS attacks?
A distributed denial-of-service (DDoS) attack tries to make a service unreachable by sending it more traffic than it can handle. Spoofing helps in two ways.
SYN floods target memory. Each SYN makes the server reserve a slot and wait for step 3, which never comes. The slots fill and real visitors are turned away; since the source changes with every packet, blocking addresses achieves nothing.
Reflection and amplification target bandwidth. The attacker sends small UDP requests to thousands of public servers, such as DNS resolvers, with the victim's address as the source. Each server answers the victim, often with a much larger reply. CISA's alert on UDP-based amplification attacks lists the factors: 28 to 54 for DNS, 556.9 for NTP and 10,000 to 51,000 for an exposed memcached server. The victim sees only the addresses of innocent servers; the attacker's own address appears nowhere.
Not every DDoS attack uses spoofing. A botnet, a network of infected devices, can open real connections from real addresses; those floods are handled with rate limits and filtering services instead.
What does "IP spoof dropped" mean in a firewall log?
A firewall that logs this line has done its job: it saw a packet whose source address did not fit the network port it arrived on, and threw it away.
SonicWall's knowledge base article on IP spoof messages says the firewall "sees an IP address on one segment that it believes belongs on another segment". SonicWall reads that as a likely attack attempt, but lists harmless causes too: a bad route, a computer with an address outside the office range, an extra subnet, a cabling loop, a second network card or a Windows computer that gave itself a temporary 169.254.x.x address.
WatchGuard calls the same check Drop Spoofing Attacks, under Firewall > Default Packet Handling and on by default. FortiGate calls it reverse path forwarding, or anti-spoofing; Fortinet's technical note shows the drop as "reverse path check fail, drop".
Internet packets that claim your internal addresses are spoofed, and the drop is correct. Drops from inside your network usually mean a setup problem. Either way, keep the protection on.
How is IP spoofing prevented?
A forged packet is easiest to stop at the first hop, because only the sender's own network knows which addresses are really the sender's.
- Ingress filtering (BCP 38). RFC 2827, Best Current Practice 38 since 2000, urges every provider to accept a customer's traffic only if the source falls inside that customer's range. Forgery within that range stays possible, but it is confined to a known network.
- Reverse path checks (BCP 84). RFC 3704 covers customers with several providers. Strict mode accepts a packet only if it arrived on the interface the router would use to reach that source; loose mode only checks that a route exists. Routers call this uRPF.
- Egress filtering. Your own firewall should not let out packets whose source is not one of your addresses.
- Public commitment. The MANRS initiative lists anti-spoofing among its actions for network operators and points to CAIDA's Spoofer tool, which tests whether a network lets forged packets out.
- Hardened servers. SYN cookies let a server answer a SYN without reserving a slot. DNS, NTP and memcached should not answer the whole internet.
- Real authentication. TLS and SSH prove who is at the other end with keys, which a forged packet cannot do; an address alone proves nothing.
CISA's alert names BCP 38 and BCP 84 as the main defense against reflection.
Is using a proxy or a VPN IP spoofing?
No, and the handshake is why. Your device connects to the proxy and asks it to fetch a page. The proxy opens its own connection to the website from its own IP address, completes the handshake, receives the reply and relays it to you. Every packet carries a true source address. A VPN does the same for the whole device; Proxy vs. VPN compares the two.
| Spoofed packet | Proxy or VPN connection | |
|---|---|---|
| Source address | Forged | Real, the proxy's or VPN server's |
| Where replies go | To the address owner | Back to the proxy, then to you |
| TCP handshake | Cannot complete | Completes normally |
| Can load a web page | No | Yes |
When people talk about "spoofing their IP" to appear in another country, they mean using a different real address through a proxy or VPN. Some proxies even pass your original address to the site in a header; Transparent vs Anonymous vs Elite Proxies shows which. Our Residential Proxy and Datacenter Proxy services work this way: each request reaches the site over a connection the proxy opens from its own address, and the client never sets the source address of those packets.
Is X-Forwarded-For spoofing the same thing?
No, but site owners meet it far more often. Many apps read the visitor's address from the X-Forwarded-For header that reverse proxies add, and any client can send that header with any value. The TCP connection still comes from the client's real address, so this is header spoofing, fixed in the app. MDN's X-Forwarded-For reference states that rate limiting or IP-based access control must only use addresses added by a proxy you trust. Forward Proxy vs Reverse Proxy shows the Nginx setting.
Who needs to care about IP spoofing?
- Home users. Nobody can browse "as you" by forging your address. Getting a new address for yourself is a different task; see How to Change Your IP Address.
- Site and app owners. An IP allowlist on a TCP service checks a completed connection, which blind spoofing cannot produce; shared addresses and forgotten entries are the real weak points. Proxy Authentication: User:Pass vs IP Whitelist weighs both methods.
- Network and security teams. Anti-spoofing and egress rules belong in the firewall review; Proxy vs Firewall shows where each device sits.
- QA teams. To see a site as visitors in other countries do, send real requests from real addresses there, as our app testing page describes.
Common mistakes
- "Someone spoofed my IP and got into my account." Spoofing cannot log in anywhere. Look for a stolen password or session; What Is Session Hijacking? covers the second.
- Treating every spoofing log line as an attack, or turning the check off to silence it.
- Calling a proxy or VPN "IP spoofing".
- Trusting X-Forwarded-For from anyone.
- Leaving DNS, NTP or memcached open to the internet.
- Using an IP allowlist as the only lock.
Decision guide
| Your situation | What to do |
|---|---|
| Spoofing drops from addresses inside your network | Check address ranges, subnets and VPN routes; keep the protection on |
| Drops of internet packets claiming internal addresses | Nothing to fix; the filter works |
| Your server is hit by a SYN flood | Turn on SYN cookies; ask your host to filter upstream |
| Floods of DNS or NTP replies you never requested | Reflection: contact your provider or DDoS service |
| You run a network with customers | Deploy BCP 38/84 filtering, test with CAIDA Spoofer, consider MANRS |
| Your app reads X-Forwarded-For | Trust only entries added by your own proxies |
| You need an address in another country for testing | Use a real proxy or VPN address |
Frequently asked questions
Can someone spoof my IP address?
They can write your address into their packets, but they get no replies, so they cannot browse, log in or download as you. At most, your address may appear in someone's logs as the apparent source of junk traffic.
Can IP spoofing be traced?
Only with cooperation. A packet carries no proof of origin, so investigators must follow it back network by network while the traffic is still flowing. Where providers apply BCP 38, a forged packet can only carry an address from the sender's own range, which points to the right network.
Is IP spoofing illegal?
Sending forged packets to flood a service or break into a system is a crime under computer misuse laws in most countries. Forging addresses in a closed lab on your own equipment is a different matter. Proxies and VPNs are not spoofing; their legal status is covered in Is Using a VPN or Proxy Legal?
Does HTTPS or a VPN protect me from IP spoofing?
They protect your data, not the network. HTTPS needs a completed connection and checks the server's certificate, so a blind spoofer cannot read or change the page; a VPN also defeats ARP spoofing on shared Wi-Fi. Neither stops a flood of forged packets aimed at a server.
What does IP spoofing mean in LoadRunner and other load testing tools?
Something harmless: giving the test machine many real IP addresses so the server sees virtual users coming from different addresses. OpenText's testing tool, formerly LoadRunner, calls its Multiple IP Address feature exactly that. The addresses are configured on the machine, so every connection is genuine.
Is IP spoofing the same as session hijacking?
No. Decades ago, attackers combined spoofing with sequence number guessing to take over TCP sessions; unpredictable sequence numbers made that impractical. Session hijacking today means stealing a login cookie or token, which needs no forged packets.
Summary
IP spoofing forges a packet's source address. It works because IP does not verify senders, and it is limited because replies go to the forged address, so a spoofer can never complete a TCP handshake or open a page. That makes it a tool for one-way attacks such as SYN floods and reflection DDoS. The fixes are mostly upstream: BCP 38 and BCP 84 filtering, egress rules, SYN cookies, no open UDP amplifiers and authentication that does not rest on an address. A proxy is the opposite of spoofing, a real endpoint with a real address; if that is what you need, see our proxy plans.




