AVATALK

How to Spot a Deepfake (and Protect Yourself From Voice-Clone Scams)

Deepfakes are getting harder to catch by eye. Here are the visual and audio clues to look for, the context checks that matter more, and a simple plan for suspicious calls.

By the AVATALK Team · Updated · 9 min read

How to spot a deepfake: look for visual glitches like odd hands, teeth, eyes, shadows or jewelry, listen for flat or unnatural speech, and, most importantly, check the context. Ask who shared it, whether trusted sources confirm it, and whether it's pushing you to act fast. For calls asking for money, hang up and verify on a number you know.

Deepfakes are AI-generated or AI-altered videos, images and audio that make it look or sound like a real person said or did something they didn't. Some are harmless jokes. Others are used to spread false information, harass people, or steal money by imitating someone you trust.

The tools that make deepfakes keep improving, so spotting them by eye and ear alone is getting harder. This guide covers the clues that still help, the context checks that matter even more, the red flags of voice-clone scams according to the FBI and the FTC, and exactly what to do when something feels off.

Can you still spot a deepfake?

Sometimes. Lower-quality fakes still have visible flaws, and it's worth knowing what they look like. But many convincing fakes don't, especially short clips, still images and audio. In a 2022 study published in the journal PNAS, researchers Sophie Nightingale and Hany Farid found that people could not reliably tell AI-generated faces from photos of real people. Other studies have found that people tend to overestimate how well they can spot deepfakes.

That's why the best approach has two parts:

  1. Look and listen for clues, which can catch many fakes.
  2. Check the context and verify, which works even when a fake looks perfect.

Visual clues in deepfake videos and photos

In a December 2024 public service announcement on criminals using generative AI for fraud, the FBI advised people to look for subtle imperfections in images and videos. The signs it listed include:

  • Distorted hands or feet, such as extra or merged fingers.
  • Unrealistic teeth or eyes, like teeth that blur together or eyes that don't reflect light naturally.
  • Indistinct or irregular faces, especially around the edges of the face, hairline and ears.
  • Unrealistic accessories, such as glasses or jewelry that warp, melt or change between frames.
  • Inaccurate shadows and lighting that doesn't match the scene.
  • Watermarks left by the tool that made the image.
  • Lag time and voice mismatch, where lip movements don't line up with the words.
  • Unrealistic movements, like stiff heads, jerky motion or bodies that move unnaturally.

A few more things to check: skin that looks too smooth or waxy, background text that turns into gibberish, and odd blinking or a strangely still face. In a live video call, you can ask the person to turn their head fully to the side or pass a hand in front of their face, which some real-time face-swapping tools struggle with. Treat these as hints, not proof.

How to tell if a voice is AI

Voice clones are often harder to catch than video fakes, because phone audio is already low quality and an emotional caller can explain away anything that sounds a little off. The FBI suggests listening closely to tone and word choice to tell a real call from a loved one apart from a cloned voice.

  • Flat or oddly placed emotion, like panic that sounds performed, or crying without natural breathing.
  • Words they wouldn't use. Different nicknames, formal phrasing, or missing the little expressions they always say.
  • Unnatural pacing, with strange pauses, no "ums," or responses that come a beat too late.
  • Short, scripted answers. The caller avoids back-and-forth or changes the subject when you ask questions.
  • A reason they can't talk long, such as being in custody, in a hospital or on a bad connection.

Remember that scammers only need a short clip of someone's voice, which they can often find in public videos or social media posts. Our AI voice cloning guide explains how the technology works.

Check the context, not just the pixels

Context checks are your most reliable tool, because they work no matter how good the fake is. Before you believe or share something surprising, ask:

  • Where did it come from? An unknown account, a forwarded message or a brand-new profile is a reason for caution.
  • Are trusted news outlets or official sources reporting it? A real, shocking video of a public figure will usually be covered quickly by reliable sources.
  • Does it push an emotion or action? Outrage, fear and urgency are the fuel of misinformation and scams.
  • Has it appeared before? A reverse image search tool such as Google Lens or TinEye can show whether an image or video frame was taken from somewhere else or altered.
  • Does it have Content Credentials? Some cameras, apps and websites now attach Content Credentials, based on the C2PA open standard, showing how a file was made or edited. You can check a file with the Content Authenticity Initiative's free tool at contentcredentials.org/verify.

Content Credentials are helpful when they're there, but a file without them isn't necessarily fake. Many real photos don't have them, and metadata can be stripped when files are shared.

Red flags of a voice-clone scam

The US Federal Trade Commission has warned that scammers can use AI to clone a family member's voice for so-called family emergency scams. A typical call sounds like a panicked loved one, often a grandchild, saying they've been in a car accident or arrested and need money right away. Sometimes a second person joins, claiming to be a lawyer, police officer or doctor.

Scams aren't only aimed at families. In May 2025, the FBI warned that criminals were using AI-generated voice messages to impersonate senior US government officials, aiming to gain access to people's accounts. Businesses have also been targeted with fake calls or video meetings that appear to come from executives.

Whatever the story, the warning signs tend to be the same:

  • Urgency. You must act now, before you have time to think or check.
  • Secrecy. "Don't tell Mom and Dad" or "Keep this confidential."
  • Unusual payment. Wire transfers, gift cards, cryptocurrency or cash pickups, which the FTC notes are hard to get back.
  • A request to switch platforms, such as moving to a different messaging app.
  • Requests for codes or passwords, including two-factor authentication codes.

What to do in the moment: a simple plan

Agree on this plan with your family now, so no one has to think clearly in a panic later.

  1. Pause. Real emergencies can wait the two minutes it takes to verify.
  2. Hang up and call back. The FTC's advice is not to trust the voice, and instead to call the person on a phone number you know is theirs. If you can't reach them, contact another family member or friend.
  3. Use a family safe word. The FBI recommends creating a secret word or phrase with your family to verify identity. Ask for it. A scammer won't know it.
  4. Ask a personal question only the real person would know, and that isn't on social media.
  5. Never send money or codes under pressure, and never by gift card, wire or crypto to someone you haven't verified.
  6. Talk to someone. Tell a friend or relative what's happening. A calm second opinion breaks the spell of urgency.

Do deepfake detection tools work?

Deepfake detection tools can help, especially those used by newsrooms, platforms and security teams. But no tool is foolproof. Detectors can miss new kinds of fakes and sometimes flag real media as fake. Free online checkers vary widely in quality.

Use a detection tool as one signal among several, never as the final word. Combine it with the context checks above and, for anything involving money or personal information, direct verification with the real person.

If you've been targeted or fooled

Scammers are skilled, and anyone can be fooled. If it happens, act quickly and don't blame yourself.

  • Contact your bank or payment provider right away if you sent money. The sooner you report it, the better the chance of stopping or reversing the payment.
  • Report it. In the US, report scams to the FTC at ReportFraud.ftc.gov and internet-enabled crimes to the FBI's Internet Crime Complaint Center at ic3.gov. In other countries, contact your national fraud reporting service or local police.
  • Secure your accounts if you shared passwords or codes. Change passwords and turn on two-factor authentication.
  • Report fake content to the platform where you saw it.
  • Warn your family and friends, since scammers sometimes target several people in the same circle.

If someone has made a deepfake of you, our guide to AI avatar privacy and safety explains steps for documenting and reporting misuse of your face or voice, and whether AI voice cloning is legal covers the laws involved. This is general information, not legal advice.

Frequently asked questions

What is the easiest way to spot a deepfake?

Check the context first. Ask where it came from, whether trusted sources confirm it, and whether it's pushing you to feel or do something quickly. Then look for visual clues like warped hands, odd teeth or eyes, mismatched shadows and lips out of sync. If money or personal information is involved, verify directly with the real person.

How can I tell if a phone call is an AI voice clone?

Listen for unusual word choices, flat or forced emotion, odd pauses and a caller who avoids back-and-forth conversation. But clones can be convincing, so don't rely on your ear. Hang up and call the person back on a number you know is theirs, or ask for a family safe word. Be wary of urgent requests for money.

What should a family safe word be?

Choose a word or short phrase that's easy to remember but impossible to guess, and that has never appeared online. Avoid pet names, birthdays, addresses or anything on social media. Share it only in person or on a trusted call, and agree that anyone asking for urgent help or money must say it.

Are deepfake detection apps reliable?

Not completely. Detection tools can help, but they can miss new types of fakes and sometimes wrongly flag real content. Treat their results as one signal, not proof. Combining a tool's result with context checks, reverse image searches, Content Credentials and direct verification gives you a much more reliable answer.

Where do I report a deepfake scam?

In the US, report scams to the Federal Trade Commission at ReportFraud.ftc.gov and internet-enabled crime to the FBI's Internet Crime Complaint Center at ic3.gov. If you sent money, contact your bank or payment provider immediately. Also report fake content to the platform where it appeared. Outside the US, contact your national fraud reporting agency or local police.