Skip to content
Skip to main content
IP Addresses & Networks Ordinary Explanatory

Can a source IP address be spoofed?

Yes. A sender can place a false source address in an individual IP packet. This is called source IP spoofing.

Whether that explains the activity in your case depends mainly on whether the sender needed to receive a reply.

The basic problem for the sender

A reply is sent to the source address written in the packet. If that address is false, the reply normally goes somewhere else.

This makes spoofing useful for some one-way traffic but much less useful for activity that needs a continuing two-way conversation.

UDP and one-way traffic

UDP can send traffic without first setting up a connection. A sender may not need the reply, or may deliberately direct it elsewhere.

Reflection and amplification attacks use this technique:

  1. The attacker sends requests with the victim’s IP address as the source.
  2. Internet services send their replies to the victim.
  3. The victim receives traffic they did not request.

A record of a single UDP packet may therefore contain a spoofed source address.

TCP and completed sessions

TCP normally begins with a three-way handshake. The receiving system replies to the source address, and the sender must respond correctly before the connection is established.

Simple spoofing will not usually support a completed TCP session because the real sender does not receive the reply. A successful website login, upload or other two-way exchange is therefore unlikely to be explained by someone merely writing a false source address into a packet.

Spoofing is different from an intermediary

A VPN, proxy or NAT service creates or forwards a real connection. The online service sees the intermediary or shared public address because that is where the connection reached it from. The address has not simply been forged in the packet received by the service.

Apply it to the record

Ask:

  • Is this one packet, an attempted connection or a completed session?
  • Is the traffic TCP, UDP or another protocol?
  • Did the activity require replies from the service?
  • Do surrounding records show a continuing exchange?

The point to remember

A source address can be spoofed in a packet. A completed two-way session makes simple source spoofing a much less likely explanation.

Explore related guidance
Reference: IP-020IP Addresses & Networks