Google Rolls Out RCS Call Authentication to Block Fake Voice Scams on Android

Google has rolled out a new Android feature that automatically detects and filters fake RCS calls by verifying GSMA authentication standards, displaying warnings for suspicious ones. The device-level system minimizes battery use and false positives while enhancing protection against sophisticated voice scams. Early user feedback is positive.
Google Rolls Out RCS Call Authentication to Block Fake Voice Scams on Android
Written by Lucas Greene

Google has begun rolling out a new feature for Android phones that can automatically detect and filter out fake calls made through Rich Communication Services, or RCS. The capability, which started appearing in beta form for select users in early June 2026, marks a significant step forward in protecting people from increasingly sophisticated voice scams that abuse modern messaging protocols.

The feature works by examining the technical signals that accompany an incoming RCS call. When a call arrives, the system checks whether the connection follows proper authentication standards established by the GSMA, the industry group that oversees mobile communications. Calls that fail these checks or show signs of spoofing get flagged immediately. Users see a clear warning on their screen before they answer, giving them the chance to decline the connection or proceed with caution.

This development arrives at a time when scammers have adapted quickly to the shift away from traditional SMS toward richer messaging formats. RCS offers higher quality voice calls, read receipts, and typing indicators, but it also opens new avenues for abuse if carriers and device makers do not implement strong verification. Criminal groups have learned to mimic legitimate RCS traffic, making their calls appear to come from trusted contacts or official organizations. The new Android detection system aims to close that gap by adding an extra layer of scrutiny at the device level.

According to reporting from Slashdot, the rollout began quietly through server-side updates rather than a full software release. Early testers noticed the option appearing in their Phone app settings under spam protection controls. When enabled, the system runs in the background and requires no additional configuration from the user beyond granting basic permissions. Google designed the process to minimize battery impact and avoid false positives that might block legitimate calls from friends or businesses.

The technology builds on years of work Google has done to combat robocalls and SMS spam. Previous efforts focused mainly on caller ID matching and community-reported block lists. With RCS adoption growing rapidly, especially after major carriers made the service default on newer Android devices, the company recognized the need to extend those protections to the richer protocol. RCS calls can carry more metadata than older voice calls, which gives the detection algorithm more data points to analyze. This includes details about the sender’s carrier registration, the encryption status of the connection, and whether the call route matches expected patterns for that geographic region.

Privacy remains a central concern in any call-screening system. Google states that the detection process happens locally on the device whenever possible. Suspicious patterns get evaluated without sending call logs to remote servers unless the user explicitly opts into broader spam reporting. Even then, the system strips out personal identifiers before transmitting data. This approach aligns with Google’s broader privacy commitments while still allowing the creation of an aggregated database of known scam techniques.

Experts who have followed the rise of RCS-based fraud welcome the move but caution that it represents only one piece of a larger solution. Many scams now combine multiple channels, starting with an RCS call that spoofs a bank or government agency, then following up with text messages or links that direct victims to fake websites. Blocking the initial call helps, but users still need education about how to verify the identity of anyone requesting sensitive information. The new feature includes educational prompts that explain why a call was flagged, which may help users recognize similar attempts in the future.

Carriers play an essential role in making this protection effective. The GSMA has published detailed guidelines for RCS authentication that require network operators to verify the origin of each call before it reaches the recipient’s phone. However, implementation varies widely between countries and even between different carriers in the same market. Google’s decision to add device-level checking compensates for gaps in carrier adoption. When both the network and the device perform verification, the chances of a successful spoof drop dramatically.

The timing of this rollout coincides with a noticeable increase in reported RCS scams across several regions. In Europe and parts of Asia, authorities have documented cases where fraudsters used RCS to impersonate delivery services, tax offices, and technical support teams. These calls often display the correct company name and logo on the recipient’s screen, making them especially convincing. By catching calls that do not match official authentication certificates, Android phones can now interrupt many of these attempts before any conversation begins.

Users who receive the update will find the new controls grouped with existing spam protection settings. A simple toggle labeled something like “Verify RCS call authenticity” activates the feature. Additional options let users decide how aggressively the system should act. They can choose to silence suspicious calls automatically, send them straight to voicemail, or simply display a warning while still allowing the call to ring. This flexibility accommodates different user preferences and risk tolerances.

The underlying machine learning models that power the detection have been trained on millions of call records, including both legitimate and fraudulent examples. Google updates these models regularly through Play Services, which means protection improves over time without requiring a full operating system upgrade. The company has also started collaborating with select carriers to share anonymized threat intelligence, creating a feedback loop that benefits all Android users regardless of their service provider.

One notable limitation involves international calls. Because authentication standards differ across borders, the system may flag some legitimate calls from overseas as suspicious. Google acknowledges this challenge and has tuned the algorithms to be more lenient with calls from recognized international carriers. Users can also create allow lists for specific numbers or contacts that bypass verification entirely. These exceptions help reduce friction for people who regularly communicate with family members abroad or business partners in other countries.

Security researchers have pointed out that determined attackers will likely develop workarounds as the feature becomes more widespread. Some may attempt to compromise legitimate RCS infrastructure or find ways to obtain authentic certificates through social engineering. For this reason, Google emphasizes that the detection system forms part of a defense-in-depth strategy rather than a complete solution. Features like automatic call screening, transcription of unknown callers, and integration with third-party security apps all contribute to the overall protection picture.

The rollout follows a similar pattern to other Google security features. It begins with a small percentage of users, gathers feedback, and expands gradually to avoid overwhelming support channels. Beta testers have reported that the warnings are clear and not overly frequent. Most legitimate calls pass verification without issue, which suggests the false positive rate sits at an acceptable level. As more users receive the update, Google will monitor performance metrics and adjust thresholds accordingly.

This development also reflects broader changes in how mobile platforms handle communications. Traditional phone calls have lost ground to messaging apps, but voice communication remains important for urgent matters and official business. RCS represents an attempt by the mobile industry to modernize voice and text services within the native dialer rather than ceding that space entirely to third-party applications. By securing RCS properly, Google helps ensure that users can trust their built-in phone app again.

For individuals who have been targeted by sophisticated voice phishing attempts, the new capability offers tangible relief. Many victims describe the psychological pressure of receiving a call that appears to come from their bank or a family member in distress. The immediate warning provided by Android can break that momentum and give people time to think before responding. Over time, this may reduce the success rate of such scams and force criminals to invest more effort in each attempt, potentially making the activity less profitable.

The feature also sets a precedent for other mobile platforms. Apple’s iOS has its own call identification and spam blocking tools, though it has been slower to embrace RCS. As more carriers worldwide adopt the standard, pressure will grow for all major phone makers to implement similar verification checks. Cross-platform consistency would create a stronger barrier against international fraud rings that target users regardless of their device choice.

Google has not provided an exact timeline for when the fake call detection will reach all Android users. The gradual server-side deployment suggests the company wants to observe real-world performance before declaring the feature complete. In the meantime, users can take additional steps to protect themselves by keeping their Phone app updated, enabling all available spam filters, and remaining skeptical of unexpected calls that request personal information or immediate action.

The introduction of RCS fake call detection demonstrates how device makers can respond quickly when new technologies create new risks. Rather than waiting for carriers to solve every authentication problem, Google has added intelligence directly to the Android operating system. This approach gives users faster protection and creates market pressure for carriers to improve their own systems. As scam tactics continue to evolve, frequent updates and collaboration between platforms, carriers, and security researchers will remain essential to staying ahead of the threat.

Early feedback from users who have received the feature has been largely positive. Many appreciate the peace of mind that comes from knowing their phone is actively checking call authenticity in the background. Others have noted that the educational messages accompanying warnings help them understand the difference between legitimate and suspicious calls. These small touches may prove as valuable as the technical detection itself by building user awareness over time.

As adoption spreads, the collective database of scam patterns will grow more comprehensive. This shared knowledge benefits everyone in the Android community and may eventually extend to other areas of communication security. The quiet rollout that began in June 2026 could mark the beginning of a new standard for how mobile devices verify the calls we receive each day.

Subscribe for Updates

MobileDevPro Newsletter

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us