In recent kernels, the spoofing check is controllable on a per-interface basis via ip link parameter (spoofchk). This is already documented on the vf_offload page: https://doc.dpdk.org/dts/test_plans/vf_offload_test_plan.html