I find it's very useful to think of the problem not as governed by technical possibility, but rather by costs.
Good spoofing detection does not prevent fraud, it increases its costs to fraudsters (hoping to render fraud uneconomical).
Bad spoofing detection harms legitimate users and is inefficient against capable actors.
All of this gets much more interesting and complex when we consider privacy (and privacy compliance) to be part of the puzzle - now fraud prevention incurs a cost to the defender as well.
Finally, it's important to consider asymmetric risk/benefit counts. Are you defending against a single major heist, or against billions of tiny events (click fraud)? The trade-off will look different.