STIR/SHAKEN is an FCC-mandated call authentication framework that digitally signs outbound calls so receiving networks can verify that caller ID has not been spoofed. STIR means Secure Telephony Identity Revisited; SHAKEN means Signature-Based Handling of Asserted information using toKENs. Together, they function as a technical standard and governance framework for signing and verifying calls across IP networks.

The impetus was simple: U.S. consumers received nearly 60 billion robocalls in 2019, eroding trust in voice communications to the point that people stopped answering unknown numbers. Congress passed the TRACED Act in response, and the FCC required all voice providers to implement STIR/SHAKEN.

For businesses, the stakes are direct. When your outbound calls are not properly signed, terminating carriers such as Verizon, AT&T, and T-Mobile apply their own analytics to signature verification and may flag or block your calls before they reach the recipient. This affects answer rates, customer trust, and revenue, especially for businesses that depend on outbound calls for appointment reminders, order confirmations, and patient follow-ups. STIR/SHAKEN determines whether your calls get through.

How STIR/SHAKEN Works

When your business places an outbound call, your voice provider digitally signs it before it leaves its network. Downstream networks verify this signature before delivering the call to the recipient. Three roles make this possible. Your voice carrier, the originating provider, verifies the call’s source and signs it with a digital certificate issued by a certification authority. The signed call travels through the network until it reaches the terminating provider, the recipient’s carrier. The terminating provider verifies the signature and decides whether to deliver, label, or block the call.

One thing to remember: all of this happens at the carrier level. Your phone system is not involved in signing or verification. The quality of this step depends almost entirely on your provider.

Understanding Attestation Levels

Attestation is the most important concept for understanding why calls are flagged. Every signed call carries one of three levels, and the level assigned by your provider determines the trust granted by the terminating carrier.

A (Full Attestation) means the provider has authenticated the caller and verified that they own the displayed number. This is the highest trust level and the least likely to be flagged by downstream networks.

B (Partial Attestation) means the provider has authenticated the caller but cannot confirm ownership of the displayed number. The terminating carrier still treats B-attested calls with reduced trust, and flagging remains common.

C (Gateway Attestation) means the provider received the call from another network and cannot guarantee the caller or the number. Calls at this level are frequently blocked immediately.

Two providers can claim to be STIR/SHAKEN-compliant while signing at different levels. If one signs at A and the other at B, their customers will see measurably different answer rates. Compliance is a threshold; the attestation level is the real performance driver.

The two ways STIR/SHAKEN affects your business

STIR/SHAKEN influences both sides of your phone traffic: whether your outbound calls reach customers and whether your team’s incoming lines are protected against fraudulent calls. How your provider implements the framework determines both outcomes.

Outbound: why your calls are flagged as spam

The most common reasons legitimate business calls are flagged, even when signed:

  • The originating provider signs at attestation B or C instead of A, resulting in reduced trust by default.
  • Outbound call volume or the dialing pattern from a single number resembles robocaller behavior, triggering analytics signals regardless of attestation level.
  • Recipients have already reported the number as spam, creating a reputation score that persists even after signing.
  • Numbers recently assigned from a carrier pool may carry the poor reputation of the previous holder.

The consequences are concrete. Pharmacy appointment reminders displayed as “Likely Spam” mean patients miss their appointments. Unanswered booking confirmations from a restaurant group result in no-shows. Blocked delivery alerts from a retailer increase customer service volume. In every case, the problem is traceable to the provider’s implementation, not the business’s intent.

Inbound: how STIR/SHAKEN protects your team

On the inbound side, your carrier verifies the STIR/SHAKEN signature on calls arriving at your network. Unsigned calls or calls signed at low attestation levels can be labeled as suspected spam before your phones even ring.

This filtering has practical value beyond convenience. Employees no longer pursue every unknown number, reducing interruptions and allowing them to focus on actual customer calls. More importantly, it raises the barrier against attacks: vishing attempts, CEO impersonation calls, and spoofed-number scams become harder to execute when they cannot pass attestation checks.

Why your calls are still flagged even with STIR/SHAKEN

Being “STIR/SHAKEN-compliant” does not mean your calls will stop being flagged. Compliance is binary: you sign or you do not. What actually determines your answer rates is implementation quality, and several reasons explain why flagging persists even after compliance.

  • Signing at attestation B instead of A exposes calls to carrier analytics that treat partial attestation as a reduced-trust signal.
  • The number’s poor historical reputation persists because past call data is not reset when a signature is added.
  • High outbound call volume from a single number can trigger analytics signals regardless of attestation level.
  • Terminating carriers apply their own proprietary scoring on top of STIR/SHAKEN, which means a clean signature does not remove a low reputation score.

There is also a gap in the framework that STIR/SHAKEN was never designed to address. Fraudsters can spoof numbers that should never make outbound calls: your inbound-only support line, your appointment desk, the numbers used for internal routing. When scammers use these numbers to place fraudulent calls, recipients report them as spam, and that poor reputation attaches to your number. Your company did not make those calls, but you bear the consequences.

The FCC closed this gap by mandating Do Not Originate (DNO) enforcement starting December 15, 2025, requiring all voice providers to block origination attempts from numbers that should never make outbound calls. If your provider does not enforce DNO, your numbers remain available for spoofing, and every spoofed call erodes a reputation you will have to rebuild yourself.

STIR/SHAKEN is necessary infrastructure. What your provider does around it — attestation level, DNO enforcement, reputation monitoring — is what actually moves your answer rates. This shift, where compliance determines whether calls connect rather than simply whether regulations are met, is reshaping how the entire telecom stack works.

What your provider should do (and what is your responsibility)

Understanding where responsibility lies helps you evaluate your current provider honestly.

Your business communications provider is responsible for signing all your outbound calls at full A attestation, managing SPC tokens, certificates, and renewals without requiring your involvement, verifying inbound calls against STIR/SHAKEN signatures, monitoring your number’s reputation and handling remediation when a report occurs, and enforcing DNO rules on your inbound-only numbers so fraudsters cannot spoof them. Providers must also stay current with FCC rules — the framework is still evolving, with active rules on non-IP authentication and Rich Call Data.

Your company’s responsibility is narrower: register branded caller ID with your carrier if offered, maintain good calling practices by contacting only opt-in recipients and honoring do-not-call lists, promptly report flagged numbers to your provider, and consolidate outbound calls under a single carrier that signs at A attestation instead of splitting traffic among providers with inconsistent practices.

How to tell whether your current phone provider is really doing the work

Here are the questions to ask any provider, whether current or prospective.

  • Do you sign all my outbound calls at full A attestation? A provider signing at B will often say “we are STIR/SHAKEN compliant” without specifying the level. Ask for a direct answer.
  • Do you own the infrastructure that signs my calls, or do you use a third-party signer? Under the FCC’s report and eighth order, providers must now sign calls with their own certificates. Third-party signing arrangements are no longer sufficient for compliance.
  • Do you offer caller ID reputation monitoring and remediation? Signing at A reduces the risk of being flagged; it does not eliminate it. A provider without reputation monitoring has no early warning system or remediation path.
  • Do you manage SPC token and certificate renewals, or does my team need to get involved?
  • Do you enforce DNO on my inbound-only numbers?
  • What happens to voice service during an internet outage? Do outbound calls continue to be signed and routed through failover?

Weak answers about attestation level, certificate ownership, or reputation remediation are direct indicators of reduced answer rates. A provider that cannot explain its DNO enforcement exposes your inbound-only numbers.

How to remediate numbers that have already been flagged

If numbers have already been flagged, remediation follows one of two paths depending on your volume and available resources.

For businesses that handle it in-house: start by checking which numbers are flagged using free reputation lookup tools provided by major analytics providers. Submit disputes to the carriers and call-blocking apps flagging your numbers, and sign up for the free call registry services available. Review your outbound dialing patterns. A high volume from a single number or calling unverified contacts accelerates flagging. Avoid rotating numbers reactively; short-term numbers signal suspicious behavior to carrier analytics and are flagged more quickly than numbers with a stable history. Sangoma’s wholesale knowledge base includes a detailed guide to mitigating Spam Likely labels for SIP trunk customers.

For high-volume businesses or those with many numbers, manual remediation is not enough. A managed service continuously monitors reputation across carriers and call-blocking apps, detects flagging before it appears in your answer rates, and handles disputes directly. The difference between the two approaches is the difference between reacting to complaints and fixing the problem before customers notice it. Sangoma’s Caller ID Reputation (CIDR) service provides ongoing monitoring and remediation for businesses that need it.

How Sangoma prevents your calls from being flagged

Sangoma Carrier Voice (the carrier network underlying Sangoma’s unified communications platforms) signs outbound calls with full A attestation. Because Sangoma owns both the communications platform and the carrier infrastructure, there is no handoff to a third-party signer and no gap in the signing chain. Businesses using Sangoma cloud, hybrid or on-premises UC with Sangoma voice service benefit from A attestation signing without having to manage it separately.

On the inbound side, calls terminated on the Sangoma network are verified against STIR/SHAKEN signatures, so suspicious robocalls are labeled before reaching your team’s phones. Sangoma also enforces DNO compliance on its network, blocking origination attempts from numbers that should never place outbound calls, protecting your inbound-only numbers from exploitation by fraudsters and preventing the resulting poor reputation. You can consult Sangoma’s STIR/SHAKEN compliance page for details on certificate management and attestation infrastructure.

For number reputation, Sangoma’s Caller ID Reputation (CIDR) service monitors how your outbound numbers are labeled across carriers and call-blocking apps, highlights flagging before answer rates drop, and handles remediation directly. Customers using CIDR see answer-rate improvements of up to 30%. Sangoma owns the complete voice stack, from signing and SIP trunking to wholesale carrier services, eliminating third-party dependencies that create attestation gaps at other providers. Support for attestation and signing issues is available 24/7 through US-based teams as part of the standard support relationship. Local survivability with 4G/5G failover keeps voice running during internet outages, so call delivery reliability extends beyond signing infrastructure.

STIR/SHAKEN FAQ

What is STIR/SHAKEN?**

STIR/SHAKEN is the FCC-mandated call authentication framework that digitally signs outbound calls so receiving carriers can verify that the caller ID is accurate. STIR (Secure Telephony Identity Revisited) defines the technical standards; SHAKEN (Signature-Based Handling of Asserted information using toKENs) defines the governance framework providers follow to implement them. Together, they form the infrastructure that determines whether a call is delivered, labeled as spam, or blocked.

Do I need to do anything as a business to comply with STIR/SHAKEN?

For most businesses, no direct action is required; STIR/SHAKEN compliance is your provider’s responsibility. You can verify that your provider signs your calls with full A attestation, register a branded caller ID if your provider offers it, and maintain clean calling practices. The decisions that most affect your answer rates are made at the carrier level, not on your phone system.

Why are my business calls still being flagged as spam?

Several factors can lead to a flag even with STIR/SHAKEN: your provider may sign with B attestation instead of A, your numbers may have a poor historical reputation, a high volume of outbound calls from a single number may trigger analytics signals, and terminating carriers apply their own proprietary scoring on top of STIR/SHAKEN. Gaps in DNO enforcement can also expose your inbound-only numbers to spoofing-related reputation issues you did not cause.

What are the attestation levels, and which level does my provider use?

Attestation levels indicate the confidence a provider can guarantee for a given call. A (Full Attestation) means the provider authenticated the caller and confirmed ownership of the displayed number. B (Partial Attestation) means the caller was authenticated but ownership of the number was not confirmed. C (Gateway Attestation) means the call arrived from another network, and neither the caller nor the number can be verified. A attestation gives your calls the best chance of delivery; B and C expose them to carrier analytics that may flag or block them. Ask your provider directly which level it uses.

Does STIR/SHAKEN block all robocalls?

No. STIR/SHAKEN authenticates caller ID; it does not determine whether a call is fraudulent. Calls can pass signature verification and still be flagged by carrier analytics based on dialing patterns, reported complaints, or number reputation. Conversely, fraudsters can sign calls through complicit providers and deliver robocalls. STIR/SHAKEN reduces spoofing; it is one layer of a broader robocall mitigation approach that also includes DNO enforcement, reputation monitoring, and call analytics.

How can I tell if my provider signs with full A attestation?

Ask directly: “Do you sign all my outbound calls with full A attestation?” Many providers confirm STIR/SHAKEN compliance without specifying the level. A provider signing with A should be able to answer this question without qualification. If the answer includes phrases like “where possible” or “depending on the call path,” that usually means B is used for some of the traffic.

Can a number that has already been flagged be fixed?

Yes, but it requires active remediation. The flag is not permanent, but it does not resolve itself. The process involves identifying which carriers and call-blocking apps flagged the number, submitting disputes, and in some cases signing up for call registry services. For businesses with high call volumes or many numbers, a managed reputation service handles this continuously rather than reactively. See the remediation section above for both the DIY and managed paths.