Can Remote ID be spoofed or faked?
Remote ID is an open, unencrypted broadcast — which is what makes it publicly readable, and also what makes it spoofable in principle. That's not a reason to ignore it; it's a reason to understand what spoofing looks like and how a good receiver flags it.
Can Remote ID be spoofed?
Yes, in principle. Because most Remote ID is broadcast without cryptographic signing, someone could transmit fabricated Remote ID — inventing a drone, cloning a serial, or replaying a captured broadcast. It requires deliberate effort and is generally unlawful, but it is technically possible.
What does a spoofed broadcast look like?
Often, subtly wrong. Tell-tales include a drone that teleports impossibly between positions, multiple aircraft sharing one identity, a position that doesn't match signal strength, values that are physically implausible, or a broadcast that appears and vanishes without a natural flight path. Individually weak, together suspicious.
What is the Authentication message for?
The ASTM F3411 Authentication message exists to let a broadcast carry data that verifies its integrity — the mechanism intended to make spoofing detectable. In practice many drones don't populate it yet, so receivers also rely on behavioural checks in the meantime.
How does a receiver flag spoofing?
By watching for the physical impossibilities a real drone can't produce: teleport-sized jumps, duplicate identities, mismatched signal-vs-distance, and impossible speeds. A receiver that applies these consistency checks can raise a warning on a suspicious track rather than presenting it as gospel.
This is built into D.A.R.S.: its companion app includes spoofing detection that flags broadcasts failing plausibility checks — so a fabricated or replayed Remote ID is marked as suspect instead of silently trusted. You still see it; you just see that something is off.
Does spoofing make Remote ID useless?
No. The overwhelming majority of Remote ID you'll receive is genuine, because there's rarely a reason to fake it. Spoofing is an edge case to be aware of and flag, not a reason to dismiss a system that reliably identifies the real, compliant drones flying around you.
Perspective. A determined bad actor who spoofs Remote ID is also likely to just fly a non-broadcasting drone — a problem for RF and radar, not Remote ID. Remote ID's job is to identify the cooperative majority, and flag the obvious fakes.
Frequently asked questions
Is Remote ID encrypted or signed?
Generally not — it is designed to be publicly readable, so most broadcasts are unencrypted. The Authentication message can carry integrity data, but it isn't universally populated yet.
Can you tell a spoofed drone from a real one?
Often, yes, through behaviour: impossible jumps, duplicate IDs, and signal that doesn't match the claimed position are strong indicators. A receiver with spoofing detection flags these automatically.
Is spoofing Remote ID legal?
Broadcasting fabricated Remote ID over real airspace is generally unlawful and can breach aviation and radio rules. This article is about recognising it, not doing it.
Detection that flags the fakes
D.A.R.S. receives Remote ID over WiFi and Bluetooth and its app flags broadcasts that fail plausibility checks — so spoofed tracks stand out. One-time €34, per device.
See D.A.R.S. →