Over the past decade, the voice industry has faced one of its greatest challenges: an unrelenting rise in spoofed calls, impersonation scams and fraudulent call origination. Consumers are overwhelmed. Businesses are alarmed. Regulators are imposing stricter rules than ever.

And, above all, the trust that once defined the public telephone network is rapidly eroding.

STIR/SHAKEN has helped, but it has not prevented fraudsters from exploiting a deeper vulnerability: spoofing numbers that should never originate calls.

What Exactly Is Do-Not-Originate (DNO)?

At its core, DNO is simple: if a number should never be used to initiate an outbound call, carriers must block any attempt to originate a call from it. This includes:

-> Government and agency helplines -> Inbound-only numbers for financial institutions -> Corporate customer support lines -> Numbers reserved for routing, testing or internal use -> Unassigned, unused or invalid numbers -> Numbers whose legitimate subscriber explicitly requests blocking

Fraudsters favor these numbers because they instantly create credibility. If you spoof a bank’s fraud department number, the victim is more likely to answer. If you impersonate a government agency, people comply out of fear.

DNO prevents these attacks at the network edge, before illegitimate calls enter the ecosystem.

Why DNO Matters More Than Ever

Voice fraud is no longer random; it is industrialized. Organized groups use automation, bots and large-scale spoofing to impersonate trusted institutions and exploit vulnerable populations.

Here’s why DNO is now essential:

1. Caller ID spoofing is the #1 fraud method Most high-impact scams start with spoofing: IRS, CRA, banks, utilities, insurance companies, hospitals, etc.

2. STIR/SHAKEN doesn’t solve the “number legitimacy” problem STIR verifies the signer’s identity, not whether a number is authorized to originate calls. Fraudsters often use real, valid numbers that were never intended to make calls.

3. Consumers have lost trust in voice Unwanted calls have conditioned consumers to ignore unknown numbers, even legitimate ones.

4. Upstream carriers are tightening filters

If your outbound traffic contains suspicious caller IDs, you risk being: -> Blocked -> Rate limited -> Flagged for remediation

5. Businesses expect protection

Large enterprises want carriers to ensure that their inbound-only numbers are never exploited by criminals. DNO is the only scalable way to keep this promise.

The FCC’s response: new mandatory DNO rules

To strengthen the national call authentication framework, the FCC expanded its robocall mitigation program under the Eighth Report & Order, creating a new explicit requirement for all voice providers.

The mandate: by 15 December 2025, every provider must:

  • Maintain and enforce a “reasonable” DNO list
  • Block calls originating from numbers that should not originate calls
  • Apply DNO enforcement at the origination, transit, and termination stages
  • Support subscriber-requested DNO blocking
  • Demonstrate ongoing list maintenance and compliance readiness

This applies to everyone in the call path: ITSPs, hosted PBX providers, CLECs, CPaaS platforms, UCaaS providers, wholesalers, and national networks.

What the FCC did not provide:

  • Centralized DNO dataset
  • Minimum list definition
  • Prebuilt integration framework

Providers must build or obtain their own solution, quickly.

The message is clear: DNO is no longer optional. It is a regulatory obligation.

Why DNO is difficult for ITSPs to implement in-house

Although DNO seems simple in theory, its implementation is complex:

1. No official list means you have to create one

Providers must aggregate and normalize multiple data sources: -> Invalid/unassigned numbers -> Reserved ranges -> Vacant NPA‑NXX blocks -> ITG DNO Registry -> Routing-only numbers -> Customer-specified DNO entries

Building this in-house can take months.

2. Lists must be updated constantly

DNO data changes daily. Failure to update it means: -> Fraudulent calls can get through -> Legitimate calls can be blocked by mistake -> You risk failing an FCC audit

3. Integration into call flows is technically involved

This requires: -> Query logic -> Routing variants -> Failover behavior -> Detailed logs for audits

4. Implementation timelines are long

Most ITSPs report 6–12 months to build DNO functionality themselves.

5. Errors are costly

A single high-profile spoofing incident originating from your network can destroy trust and trigger regulatory scrutiny.

This is exactly why many providers are turning to turnkey managed DNO services.

Introducing Sangoma’s turnkey DNO compliance service

To help carriers and ITSPs meet the FCC mandate with speed and simplicity, Sangoma has launched a fully managed Do‑Not‑Originate compliance Add‑On for providers already using our STIR/SHAKEN service (NSS v1/v2).

This service is specifically designed to eliminate the engineering and operational burden of DNO.

How Sangoma’s DNO service works

Your NSS v1/v2 server performs DNO screening during call processing, exactly like your current STIR/SHAKEN queries.

-> No new infrastructure -> No list server to maintain -> No code or routing changes -> No internal DNO dataset to build

We manage the intelligence. You stay compliant.

Powered by an enriched, daily updated DNO dataset

Sangoma collaborates with Sansay to provide a comprehensive, continuously updated DNO list that includes: -> Invalid NPAs -> Unallocated and reserved NPA‑NXX -> Vacant NPA‑NXX‑Y -> ITG DNO Registry data -> Routing-only number designations -> Proprietary anti-fraud intelligence enrichment

This ensures that you always use a “reasonable,” comprehensive, and current list as required by the FCC.

Why Sangoma’s DNO solution is the best path to compliance

Here’s what makes Sangoma unique for ITSPs, carriers, and CPaaS networks:

1. Shortest time to compliance: become fully compliant in days, not months. 2. No engineering effort: NSS already supports the workflow; simply activate the add-on. 3. No list maintenance: we aggregate, normalize and update all DNO data daily. 4. Better fraud prevention: enriched intelligence blocks more spoofing attempts and protects your brand. 5. Designed for carrier-grade environments: high volume, low latency, high accuracy. 6. Fully aligned with FCC requirements: everything you need for audit-ready compliance. 7. Reduces operational incidents: fewer customer complaints, fewer escalations, fewer fraud disputes.

If you already use Sangoma STIR/SHAKEN (NSS v1/v2), you’re one switch away from effortless DNO compliance.

To learn more or activate DNO, contact Sangoma Carrier Voice today.