Caller ID Optimization

What STIR/SHAKEN Actually Does for Your Outbound Calls

STIR/SHAKEN is a caller ID authentication framework: a set of technical standards that lets phone providers cryptographically verify that the number transmitted with a call belongs to the caller placing it. It proves your number isn’t spoofed — and that’s all it proves. It does not decide whether your calls show up as “Potential Spam” on Verizon or “Scam Likely” on T-Mobile; those labels come from analytics engines that treat attestation as one input among many. If you searched “stir shaken” hoping it’s the switch that clears spam labels, this page will save you weeks of chasing the wrong fix.

How STIR/SHAKEN Works — and Its One Big Limitation

Mechanically, STIR/SHAKEN is a signature check between two phone companies. When you place a call, your originating provider creates a SIP Identity header containing the calling and called numbers, a timestamp, and an attestation level, then signs it with its private key. The provider on the receiving end retrieves the originating provider’s certificate and verifies the signature and certificate chain. If everything checks out, the receiving network knows which provider vouched for the call — and how strongly.

The framework is mandatory in the US. Implementing the TRACED Act, the FCC required originating and terminating providers to deploy STIR/SHAKEN in the IP portions of their networks by June 30, 2021, with staggered deadlines for smaller, gateway, and intermediate providers running through the end of 2023.

The limitation hides in that phrase “IP portions.” STIR/SHAKEN works only on IP networks. If any leg of the call path crosses older non-IP (TDM) equipment, the authentication is stripped and the call arrives unsigned — through no fault of the caller. Keep that in mind when you read the coverage numbers below.

The Three Attestation Levels: A, B, and C

Every signed call carries one of three attestation levels, which describe how much the originating provider is willing to vouch for:

  • Attestation A (Full). The provider authenticated the calling party and verified they’re authorized to use the calling number — the textbook case is a customer whose numbers live on the provider’s own switch.
  • Attestation B (Partial). The provider authenticated where the call originated but can’t verify the caller is authorized to use that specific number — the classic example is a number behind an enterprise PBX.
  • Attestation C (Gateway). The provider can only say where it received the call from — for example, traffic entering through an international gateway. It knows the door the call came through, not who’s calling.

How much each level counts downstream is proprietary to each analytics engine. The industry-consensus description: A-level reads as a positive trust signal, B roughly neutral, and C or unsigned carries negative weight that makes flagging more likely.

Where STIR/SHAKEN Stands in 2026

Adoption is less complete than most people assume. In TransNexus’s March 2026 measurements (published April 8, 2026), 42.7% of calls arrived at termination with a signature — 27.8% attested A, 3.5% B, and 7.5% C, measured against all calls reaching the terminating network that month. TransNexus noted coverage has been drifting down, likely because calls routed over non-IP segments lose their authentication along the way.

The regulatory machinery keeps tightening, though:

  • Robocall Mitigation Database (RMD). Every voice provider must certify its STIR/SHAKEN implementation and robocall-mitigation practices in the FCC’s RMD, and since September 2021 providers may not accept traffic directly from a provider that isn’t listed. It’s now an annual obligation — the first March 1, 2026 recertification deadline has passed — and enforcement is real: the FCC removed over 1,200 providers’ certifications in August 2025, which effectively disconnects a provider from the US phone network.
  • The non-IP gap (FCC 25-76). In April 2025 the FCC proposed requiring providers with non-IP networks to either complete their IP transition or implement ATIS non-IP authentication frameworks within two years. As of July 2026 this is still a proposal, not a final rule — so treat any “non-IP compliance deadline” you hear about as not yet set.
  • Know Your Upstream Provider (FCC 26-32). In May 2026 the FCC proposed baseline vetting duties for the upstream providers a carrier accepts traffic from, plus tighter vetting of the certificate infrastructure behind SHAKEN signatures. Also still at the comment stage.

The direction of travel is clear: more of the network signing calls, and more accountability for who signs what.

Attestation Authenticates the Number — Analytics Decide the Label

Here’s the distinction that trips up most outbound teams. STIR/SHAKEN authenticates the number. Spam labels are decided by analytics engines — First Orion, Hiya, and TNS, the three companies that score calls for the major US carriers — based mostly on behavior: call volume and its consistency, the share of short-duration calls, user complaints and block reports, and, yes, attestation level as one input.

Numeracle, which works on number reputation for enterprises, puts it plainly: a STIR/SHAKEN-verified call may still be an unwanted or spam call, attestation level is “just another piece of data factored into the equation,” and carriers are not blocking calls simply because they lack A-level attestation.

TransNexus’s data makes the same point from both directions. In its July 2021 analysis, 0.84% of full-A-attested calls were robocalls, versus 7.33% of B-attested and 3.16% of unsigned calls — so A-attestation genuinely correlates with legitimacy. But in its March 2026 data, providers that sign traffic for prolific robocallers attested 89.8% of those calls at A-level. Bad actors get A-signatures too, which is precisely why terminating carriers lean on analytics scoring rather than trusting the signature alone.

The takeaway: full attestation is table stakes and a real positive input — but it is not label immunity. If your calling patterns look like spam, an A-attested call can still ring through with a warning like AT&T ActiveArmor’s “Spam Risk” label. That’s why day-to-day caller ID reputation management matters more than any one-time authentication checkbox.

What an Outbound Team Can Actually Control

You can’t sign your own calls — your provider does that. Three things are in your hands:

  1. Work with a provider that has a direct relationship with you. TransNexus’s best-practices guidance is that an originating provider should sign with full A-attestation only when it can confidently attest you’re authorized to use each calling number. That takes a real vendor relationship: the provider knows who you are and provisioned your numbers. Traffic resold through layers of intermediaries tends to arrive at B, C, or unsigned.
  2. Keep number ownership clean. Numbers provisioned in your name, through your provider, with consistent registration are the ones a provider can vouch for at the A level — and the ones analytics engines can connect to a legitimate business.
  3. Behave like a business people want to hear from. Attestation is one input; behavior is the bulk of the score. Consistent daily volume, real conversations instead of rapid-fire hang-ups, honoring do-not-call requests, and spreading volume across a managed pool with a caller ID rotation system do more for your labels than any signature will.

Enzo provisions and manages every caller ID through its carrier — 35 numbers per seat on Starter, 100 on Standard, monitored and swapped when reputation dips, included in the published pricing — so ownership and provisioning are handled upstream of your campaigns.

The Bottom Line

STIR/SHAKEN is worth understanding, but it isn’t a lever you pull to clear labels. As of July 2026 it covers fewer than half of terminating calls, its non-IP extension is still a proposed rule, and by design it answers only one question: is this number really yours? The signature vouches for your number; your calling behavior earns the label. Get full attestation through a provider that actually knows you — then spend your energy on the behavior and reputation work the analytics engines actually score.

See how Enzo manages caller ID health end to end — book a free discovery call.

Company names are trademarks of their owners; details as of July 2026 — verify with each provider.

FAQ

Common questions.

Does A-level attestation prevent spam labels?

No. A-level attestation tells the receiving network your number isn't spoofed, and analytics engines treat it as one positive input in their scoring. Labels are decided by reputation analytics that weigh calling behavior — volume patterns, short-duration calls, complaint reports — alongside attestation. In TransNexus's March 2026 data, providers that sign traffic for prolific robocallers attested 89.8% of those calls at A-level, which is exactly why carriers rely on analytics scoring rather than the signature alone.

Is STIR/SHAKEN required by law?

Yes, on IP networks. Implementing the TRACED Act, the FCC required originating and terminating providers to deploy STIR/SHAKEN in the IP portions of their networks by June 30, 2021, with staggered deadlines for smaller, gateway, and intermediate providers running through the end of 2023. Providers must also certify in the FCC's Robocall Mitigation Database and, as of 2026, recertify every March 1. Rules for non-IP networks were still at the proposal stage (FCC 25-76) as of July 2026.

Why do some calls still arrive unsigned in 2026?

Because STIR/SHAKEN only survives on IP networks — when a call crosses a non-IP (TDM) segment, the authentication information is stripped. In TransNexus's March 2026 measurements, 42.7% of calls arrived at termination with a signature: 27.8% attested A, 3.5% B, and 7.5% C, measured against all calls reaching the terminating network that month. TransNexus noted coverage has been drifting down, likely due to calls routed over non-IP segments.

How do I find out what attestation level my calls get?

Ask your originating provider — attestation is assigned when the provider signs the call, and it should be able to tell you whether your numbers receive full A-level attestation and why. You can't see it on a normal handset. Some paid reputation-monitoring platforms also test attestation as part of real-device carrier testing. If your provider can't confirm the direct relationship that supports A-level signing, that's the first thing to fix.

Ready to have more conversations per hour?

Schedule Discovery Call
Schedule Discovery Call