A call displays a relative's name and the voice sounds like them. Android now wants to verify that the call actually comes from their phone. Google's new fake call detection relies on an encrypted signal exchanged between devices using Phone by Google and RCS. If confirmation is missing and the real phone says it is not calling, the recipient sees a warning to hang up.

The system addresses an increasingly accessible combination: caller-ID spoofing and AI voice cloning. It does not merely decide whether a voice sounds artificial. It first tries to authenticate the originating device, a stronger approach that also depends on several compatibility requirements.

The short answer

QuestionAnswer
Does Android listen to the voice to decide?Google's design mainly verifies a device signal rather than judging acoustic authenticity.
Which phones are compatible?Android 12+ with Phone by Google, Contacts, Google Messages and RCS.
Do both people need compatible devices?Yes. The legitimate caller and recipient must use Phone by Google.
Is it enabled automatically?Google says it is on by default and can be disabled in settings.
Does no warning guarantee authenticity?No. Out-of-scope calls and compromised devices remain possible.

A digital handshake instead of a voice detector

When a contact calls, their device silently sends confirmation to the recipient's phone. Google compares it to a digital handshake. The signal uses end-to-end encrypted RCS.

When a criminal spoofs the number, that initial confirmation is absent. The recipient's phone then checks with the contact's real device. If it says no call is taking place, a warning appears. The system is looking for a mismatch between the telephone network and the expected devices.

This avoids promising perfect detection of synthetic voices, where models change rapidly. It can catch fraud even when the vocal imitation is excellent. The tradeoff is that both ends need the required ecosystem.

Compatibility has several conditions

Google is rolling the feature out globally to Android 12 and newer, starting with Pixel devices. Phone by Google must be the dialer, Google Messages needs RCS capability and Contacts is required. The legitimate contact must also use Phone by Google.

An iPhone, differently managed business handset, device without RCS or unsupported market therefore falls outside the check. No warning does not mean a call was certified; it may simply mean verification was unavailable.

The interface needs to distinguish three states: verified, suspected impersonation and verification unavailable. Without that nuance, people may place too much trust in calls showing no alert.

What the protection cannot cover

If an attacker actually controls the relative's phone or account, confirmation may appear legitimate. Calls from a bank or public authority may not be personal contacts either; Google operates a separate verified-financial-call system.

The feature does not protect against a cloned voice note, manipulated video or urgent request sent by text. The defensive habit remains the same: end the exchange and call back through a known channel without using a number supplied during the suspicious conversation.

A family passphrase or private question can help, provided the answer is not visible on social media. For money requests, a few minutes of verification are worth more than reacting to urgency created by the caller.

Privacy: verification should not become surveillance

Google says the handshake uses end-to-end encrypted RCS. The system needs to establish that two devices match expected contacts, but it does not need to upload call audio to verify that relationship.

Users can disable the feature. Organizations will still want clarity on exchanged metadata, retention and roaming behavior. Building on an open standard such as RCS may allow other manufacturers to adopt it, as long as implementations remain interoperable.

A useful safety net, not absolute proof

The protection is sensible because it does not try to win an endless race against every voice generator. It verifies the expected source instead. Real effectiveness will depend on device coverage and clear warnings.

Families should enable RCS, keep applications updated and teach the call-back habit to vulnerable relatives. Technology can flag an inconsistency; it cannot stop someone from voluntarily sharing a code or approving a transfer.

Android's warning adds technical evidence to a caller name that had stopped being evidence. That is meaningful progress, as long as users remember that an unflagged call is not automatically authentic.