The STIR/SHAKEN framework was mandated by the FCC with a clear goal: stop caller ID spoofing. Carriers were required to implement it. Deadlines were set. Compliance was enforced. The promise was that caller ID would finally mean something — that when your phone showed a number, you could trust that the call actually came from that number.
It is 2026. The US received over 29 billion unwanted robocalls last year. The number barely budged from the year before. Your phone still rings with spoofed numbers. The "Scam Likely" label appears on legitimate business calls. And caller ID still cannot be trusted.
STIR/SHAKEN is not a failure of technology. It is a failure of expectations. Understanding what it actually does — and what it does not do — explains the gap.
What STIR/SHAKEN actually does
STIR (Secure Telephone Identity Revisited) and SHAKEN (Signature-based Handling of Asserted information using toKENs) form a framework for cryptographically signing caller ID information. When a call is placed:
- The originating carrier examines the call and assigns an attestation level
- The carrier signs the caller ID information with a digital certificate
- The signature travels with the call through the network
- The terminating carrier verifies the signature and uses the attestation level to inform call handling
The three attestation levels:
A — Full Attestation. The carrier knows the customer and confirms the customer has the right to use the calling number. This is the highest level of trust. Your carrier knows your business, knows the phone numbers assigned to your account, and is willing to vouch that you are who you claim to be.
B — Partial Attestation. The carrier knows the customer but cannot verify the right to use the specific calling number. This might apply when a business uses a SIP trunk that passes through caller ID set by the customer's PBX. The carrier knows the trunk customer but does not control which number the PBX puts in the From header.
C — Gateway Attestation. The carrier received the call from another network (often an international gateway) and cannot verify anything about the caller or the number. The carrier is just passing it along.
This is a verification framework, not a blocking framework. It tells the receiving carrier what level of confidence the originating carrier has in the caller's identity. What the receiving carrier does with that information is up to them.
Why it has not stopped robocalls
Problem 1: Attestation does not mean legitimacy
A-level attestation means the carrier vouches for the caller's right to use the number. It does not mean the caller is not a spammer. A business can legitimately own a phone number, have full attestation on their calls, and use that number to robocall thousands of people in violation of the TCPA. The signature is valid. The call is still illegal.
STIR/SHAKEN verifies identity. It does not verify intent.
Problem 2: Gateway calls bypass the system
The majority of robocall traffic enters the US through international gateways. These calls receive C-level attestation at best — the US carrier that accepts the call from the international network cannot verify the caller or the number. Many of these calls carry no STIR/SHAKEN signature at all because the originating country does not participate in the framework.
The spammers know this. Moving call origination offshore puts them outside the STIR/SHAKEN system entirely. The framework works best for domestic, carrier-to-carrier calls — exactly the calls that were least likely to be spoofed in the first place.
Problem 3: SIM farms and legitimate numbers
The latest evolution in robocalling uses SIM farms — racks of physical SIM cards from legitimate mobile carriers. Each SIM is a real phone number with a real carrier account. Calls from these SIMs receive A-level attestation because the carrier genuinely assigned the number. The spammer burns through SIMs: use a number for a day of robocalling, discard it, activate a new one.
STIR/SHAKEN cannot distinguish between a legitimate mobile user and a SIM farm. The attestation is technically correct.
Problem 4: Analytics overcompensate
Because STIR/SHAKEN alone does not block spam, carriers layer analytics engines on top. These systems use call patterns, volume, duration, answer rates, and other signals to flag suspected spam. The problem is that legitimate businesses — particularly those with high outbound call volumes like medical offices, delivery services, and appointment reminders — trigger the same patterns.
The result: "Scam Likely" labels on legitimate calls. Customers who do not answer because their phone flagged the call. Businesses whose caller reputation is damaged by overzealous spam algorithms. The cure introduces its own disease.
What businesses can actually do
You cannot fix the framework, but you can protect your outbound caller reputation and manage the reality of inbound spam.
Protect your outbound reputation
Verify your attestation level. Contact your SIP trunk provider and confirm that your outbound calls are signed with A-level attestation. If you are getting B-level because your provider cannot verify your numbers, work with them to register the numbers properly. B-level and C-level calls are more likely to be flagged by analytics engines.
Register your numbers. The Free Caller Registry and similar services let you register your business numbers so analytics engines know they are legitimate. This does not guarantee your calls will not be flagged, but it reduces the probability.
Monitor for spam flags. Periodically check whether your numbers have been flagged as spam. Call your own numbers from a mobile phone and see if the carrier labels the call. Some paid services provide ongoing monitoring.
Maintain consistent call patterns. Sudden spikes in outbound call volume from a number that normally makes 20 calls a day will trigger spam detection. If you are running a legitimate campaign, ramp up gradually and distribute calls across multiple numbers.
Do not share caller ID across services. If your main business line is also used for mass outbound calling, the calling pattern can get the number flagged. Use separate DIDs for high-volume outbound and your main business lines.
Use our carrier lookup tool to verify the carrier and line type information associated with your numbers. If a number has been ported or shows unexpected carrier information, that can affect attestation.
Manage inbound spam
Do not rely solely on carrier spam filtering. Carrier-level blocking is improving but imperfect. Consider a business phone system with its own call screening capabilities.
Train users on the gap. Employees need to understand that caller ID cannot be fully trusted, even with STIR/SHAKEN. A call showing a local number with no spam flag can still be spoofed.
Report spam calls. The FCC complaint process and carrier-specific spam reporting tools feed data back into the analytics engines. Reporting improves detection over time.
Where STIR/SHAKEN goes from here
The framework is not useless — it has made number spoofing harder for domestic callers and has given carriers a data point to feed into their analytics. The FCC continues to tighten requirements, including expanding the mandate to smaller carriers and increasing enforcement for gateway providers that pass through unsigned calls.
But the fundamental limitation remains: STIR/SHAKEN is an identity framework, not a blocking framework. It tells you who the carrier thinks is calling. It does not tell you whether you want to answer. Until caller intent can be verified as reliably as caller identity, the gap between the promise and the reality will persist.
For the MSP perspective on STIR/SHAKEN compliance, see STIR/SHAKEN: Why Your Clients' Calls Are Getting Flagged. For protecting client caller reputation, see Keeping Your Clients' Calling Reputation Clean.
Frequently Asked Questions
Why hasn't STIR/SHAKEN stopped robocalls?+
STIR/SHAKEN verifies the caller's right to use a number, but it does not block calls. A call with full attestation (A-level) can still be spam — the caller legitimately owns the number but is using it to robocall. Calls from international gateways receive C-level attestation or no attestation at all, and most robocall traffic now originates from these paths. The framework identifies, but does not prevent.
What do STIR/SHAKEN attestation levels A, B, and C mean?+
A (Full): The carrier knows the caller and confirms they have the right to use the calling number. B (Partial): The carrier knows the caller but cannot verify the specific number. C (Gateway): The carrier is just passing the call from another network and cannot verify anything about the caller. Most legitimate business calls should be A-level. C-level calls are not necessarily spam, but they have the least verification.
How do I check the STIR/SHAKEN attestation on my business numbers?+
Call your own number from another phone and check the call details on the receiving end. Some phones and carriers show verification status. You can also ask your SIP trunk provider what attestation level they assign to your outbound calls. Use our carrier lookup tool to verify the carrier and line type information associated with your numbers.
What can I do to protect my outbound caller reputation?+
Register your numbers with free caller registry services (like the Free Caller Registry). Monitor your numbers for spam flags using tools like caller reputation databases. Maintain consistent, moderate call volumes from each number. Ensure your SIP trunk provider signs your calls with A-level attestation. Avoid sudden spikes in outbound call volume, which trigger spam detection algorithms.
Share
Want to know when we publish new articles? Sign up for updates