STIR/SHAKEN attestation for outbound calling,
explained without the vendor spin

Written for teams running US outbound: what attestation actually proves, who applies the spam labels, where the UK landed, and what genuinely improves answer rates.

Does STIR/SHAKEN attestation stop outbound calls being labeled Spam Likely?

No. STIR/SHAKEN authenticates that a caller is entitled to use the number displayed, nothing more. Spam labels come from carrier analytics engines, which weigh attestation as one signal among many alongside traffic patterns and complaint data. Full A attestation reduces suspicion but does not switch labeling off; analytics engines can and do label A-attested numbers.

What gets authenticated, and what does not

The framework verifies number entitlement. Everything else is out of scope.

STIR/SHAKEN answers one narrow question: is the caller entitled to use the number showing on the recipient's screen? The FCC's own description is precise. The framework digitally validates the handoff of calls between networks so the terminating phone company can verify that a call really is from the number displayed on caller ID. In the rule text, authentication is the process by which a provider "attests to the accuracy of caller identification information" for calls it originates (47 CFR 64.6300). That is the whole job.

Mechanically, it works like signed email. When your call leaves the originating carrier, that carrier attaches a cryptographically signed Identity header to the SIP invite: calling number, called number, a timestamp, an attestation level and an origination identifier. The terminating carrier fetches the signer's certificate, checks the signature, and now knows two things: which carrier put the call on the network, and how confident that carrier is about the number being presented. US voice providers have been required to do this in the IP portions of their networks since June 30, 2021.

Notice everything that is not in that header. Nothing about call content, consent, calling hours, or whether the recipient wants to hear from you. A predictive campaign with immaculate A attestation can still be breaking abandonment rules, and a fully opted-in campaign can be signed B purely because of how its numbers were procured. The framework authenticates ownership, not virtue.

It also, and this is the part most vendor material buries, does not decide what appears on the handset. Spam labels are applied by a different system entirely, owned by different companies. We will get to that layer shortly, because it is where most outbound teams are actually bleeding.

A, B and C, and what decides yours

Your level is a statement about procurement and paperwork, not conduct.

Every signed call carries one of three attestation levels, set by the originating carrier at the moment of signing. The level reflects exactly two facts: whether the carrier has verified who you are, and whether it can verify your right to the specific number you are presenting. Nothing else enters the decision.

LevelWhat the signing carrier is assertingTypical outbound scenario
A (full)We know this customer, and they are authorized to use this number.Trunks and numbers bought from the same carrier, with know-your-customer checks completed.
B (partial)We know this customer, but we cannot verify their right to this number.Presenting numbers the carrier did not issue: unverified ported numbers, CLIs bought from another provider, numbers behind an enterprise PBX.
C (gateway)We know where this call entered our network, and nothing else.International gateway traffic and long resale chains.

The definitions come from the ATIS SHAKEN standard, and TransNexus publishes a readable technical walkthrough if you want the header-level detail. The practical reading for an outbound operation is blunt: A attestation describes your procurement, not your behavior. If your dialer presents CLIs your originating carrier cannot verify, you will be signed B indefinitely, however clean your calling is.

Two developments worth tracking. Under a 2025 amendment (90 FR 40255), a provider that outsources signing to a third-party service must still make the attestation-level decisions itself; the duty now sits explicitly in 47 CFR 64.6301(b). And in May 2026 the FCC adopted an order and further notice, FCC 26-32, pushing attestation decisions toward the provider with the direct customer relationship, resellers included, alongside know-your-upstream-provider obligations; parts of that package are still at the proposal stage. The direction of travel is consistent: responsibility keeps moving closer to whoever actually knows the caller. Good news for operators who own their numbers, less good for anonymous minute-brokers.

Find out what your outbound is actually being signed with

Our free Five9 Health Check runs 17 questions across dialing, caller ID and deliverability, and shows you where the setup is leaking answer rate before you spend money on the wrong fix.

Take the Five9 Health Check

The Robocall Mitigation Database

A public register with commercial teeth, and your first due-diligence stop.

Alongside the signing framework sits a public register. Every voice service provider, gateway provider and intermediate provider carrying US traffic must file in the FCC's Robocall Mitigation Database: a certification of how far it has implemented STIR/SHAKEN, plus a robocall mitigation plan describing the specific steps it takes to keep illegal traffic off its network.

The register bites. Since September 28, 2021, other providers may not accept traffic directly from a voice service provider that is not listed. Removal from the database is commercial death for a carrier, which is why the FCC uses delisting as an enforcement tool.

The filings are more revealing than most people expect. Under 47 CFR 64.6305, a provider must describe how it knows its customers, name the analytics systems and third-party vendors it uses to spot illegal traffic, commit to answering traceback requests within 24 hours, disclose its robocall-related enforcement history, and update its filing within 10 business days of any change. The obligations have been tightened more than once, most recently in a final rule published in January 2026 requiring more timely updates and raising penalties for non-compliance.

If you run a contact center, you almost certainly do not file; your carriers do. The database matters to you as due diligence. Search it for your originating carrier and every reseller in your chain before you sign a contract, because your traffic inherits the weakest certification in that chain. One caution: the rules here have moved every year since 2020 and enforcement practice moves faster than the documents, so check anything load-bearing against the current rule text and take qualified advice where the downside is real.

Attestation does not write the labels

Analytics engines are a separate system with different owners and different data.

Here is the distinction that saves you money on snake oil. Attestation is applied at origination and verified at termination. Spam labels are generated by analytics engines working for the terminating carriers; First Orion, Hiya and TNS are the three firms behind the industry's shared registration portal. Their models score every inbound call using traffic patterns, complaint reports, number history and, yes, attestation. The label on the handset is their output, not the framework's.

The FCC's blocking rules make the relationship explicit. Terminating providers may block calls "based on the use of reasonable analytics designed to identify unwanted calls", and those analytics need only "include consideration of caller ID authentication information where available" (47 CFR 64.1200(k)(3)). Attestation is one input among several. A signal, not a verdict.

Current data shows why the engines cannot simply trust the signature. In TransNexus's June 2026 measurements, 48.8 percent of calls arriving at termination were signed at all. Among signed traffic, 1.9 percent of A-attested calls were robocalls, against 6.4 percent for B and 8.4 percent for C. Read that both ways. A-attested traffic really is cleaner, so attestation genuinely earns credit with the models. And nearly one in fifty A-attested calls was still a robocall, so no engine will whitelist a number for its signature alone. Full A attestation does not stop Spam Likely on its own, and anyone selling attestation as a labeling fix is selling you the wrong layer.

What the blocking rules did bring is formal redress. A terminating provider that blocks calls or uses authentication information in delivery decisions must offer a free, published single point of contact, give a status update within 24 hours of a dispute, and on request supply a list of your calls it blocked in the previous 28 days (47 CFR 64.1200(k)(8) and (k)(10)). The setups we audit almost never use these rights; mislabeled numbers just quietly rot in the dialer. If a number matters, dispute it, and work through the remediation sequence properly.

What actually improves outcomes

Attestation is the foundation layer. The wins come from the signals stacked on top of it.

The honest answer to "does STIR/SHAKEN affect answer rates" is: barely on its own, and substantially through what it feeds. Handsets mostly do not surface attestation to the person deciding whether to answer. Labels and blocking decide that, and attestation is one of the stronger inputs to the systems applying them. So the work that pays is the work that improves every signal the analytics engines see.

Direct number ownership comes first. Buy your CLIs from the carrier that signs your calls wherever the routing allows it, and where you must port numbers in, complete the letter-of-authorization and verification steps so the carrier can attest A rather than B. Every number your carrier cannot vouch for is a number you are asking the analytics layer to judge on behavior alone.

Carrier KYC done properly is the unglamorous second step. The onboarding forms asking about your business, traffic profile and consent basis are not decoration; they are the evidence base your carrier signs against, and the attestation decision is now explicitly the signing provider's regulatory responsibility. Vague answers get conservative attestation. We fill these in with clients line by line, because the difference between A and B is often just a form nobody finished.

Then traffic consistency, which is where dialing operations win or lose. The engines score per-number behavior: attempt volumes, time-of-day spread, call durations, answer rates, complaint marks. A stable pool of DIDs with honest pacing and conversations that last longer than eight seconds builds history in your favor. Five hundred numbers rotated daily reads as snowshoeing to every model in the market, whatever it is signed with. This is dialer configuration as much as telecom procurement, and on Five9 floors we treat campaign pacing and DID strategy as one system, because the analytics engines certainly do.

Finally, tell the engines who you are and watch what they say about you. The Free Caller Registry submits your numbers and business identity to First Orion, Hiya and TNS in one free pass. After that, monitor labels per DID on the major networks weekly, from real handsets or a monitoring service, and watch carrier logs for SIP 603+ rejections, the response code blocking providers are required to return. If your answer rate has already dropped, that monitoring is where the diagnosis starts.

The UK chose a different route

No attestation, no database: CLI guidance and network-level blocking instead.

Ofcom looked hard at importing the US model and declined. After consulting on CLI authentication in 2023, it concluded in a February 2024 assessment that "CLI authentication on its own is unlikely to sufficiently hinder scam calls that originate overseas, and it'd be complex, costly and time-consuming to implement". The UK's migration to all-IP networks did the rest of the arguing. So there is no UK attestation, no UK equivalent of the mitigation database, and none currently scheduled.

What the UK has instead is CLI guidance with progressively sharper edges. Since January 29, 2025, providers are expected to identify and block calls arriving from abroad that present a UK number, outside a short list of legitimate cases such as roaming. On July 15, 2026 Ofcom went further: under revised guidance applying from July 15, 2027, calls from abroad presenting UK mobile numbers from the +447 range will have the presentation number treated as withheld, on the logic that no UK provider can verify them. Alongside all this sits the Do Not Originate list, protecting inbound-only numbers such as bank fraud lines.

For operators this cashes out three ways. A UK domestic floor worries about CLI validity and the wider Ofcom dialler rules, not attestation levels. An offshore floor presenting UK CLIs needs routing and contractual arrangements that fit the permitted use cases, because from July 2027 a spoofed +447 presentation simply stops displaying. And a UK business dialing US consumers inherits STIR/SHAKEN in full the moment its calls terminate on a US network, which is exactly how a Manchester collections operation ends up caring about attestation policy written in Washington.

A working checklist

Six items, in the order we run them on a new floor.

Run this on any US-facing outbound operation, new or inherited. It takes about a week of elapsed time, and most of it is email.

  1. Get your attestation position in writing from every originating carrier: which level applies, per trunk and per number range, and precisely what would move any B-signed traffic to A.
  2. Search the Robocall Mitigation Database for your carrier and every reseller between you and the network. A missing, stale or vague filing is supplier risk; treat it like a failed credit check.
  3. Consolidate origination onto the fewest carriers your resilience plan allows, and buy or verify your numbers with the carrier that signs your calls.
  4. Register every outbound DID and your business identity through the Free Caller Registry, and keep the registration current as numbers change.
  5. Check labels weekly per DID on the major US networks, from real handsets or a monitoring service, and use the carriers' free redress contacts the day a number is wrongly labeled.
  6. Keep the traffic boring: stable DID pools, honest pacing, durations that look like conversations, and retire burned numbers properly instead of rotating around the problem.

None of this is glamorous, and that is rather the point. Attestation, database hygiene and consistent traffic are the plumbing of outbound deliverability. The operations that give caller identity an owner and a maintenance schedule keep their answer rates. The ones that treat it as a procurement afterthought are the ones we meet later, mid-incident.

Asked & Answered

What does STIR/SHAKEN actually verify on an outbound call?

It verifies that the caller ID transmitted with a call matches a number the caller is entitled to use, via a cryptographic signature applied by the originating carrier and checked by the terminating carrier. It says nothing about the content of the call, whether the recipient consented, or whether the call is wanted. A fully authenticated call can still be unlawful, and a spoof-free number can still be labeled spam by analytics engines.

What determines whether my calls get A, B or C attestation?

Your originating carrier decides at signing time based on two facts: whether it has verified who you are, and whether it can verify your right to the specific number you present. Its own numbers on its own trunks with completed KYC get A. Numbers it did not issue and cannot verify get B. Traffic entering from another network, typically an international gateway, gets C. Call quality and consent records play no part in the decision.

Does STIR/SHAKEN affect answer rates?

Not much directly. Handsets rarely display attestation results prominently, so consumers are not choosing to answer based on a signature. The effect is indirect: attestation feeds the carrier analytics engines that apply Spam Likely labels and blocking, and those labels move answer rates a great deal. In TransNexus's June 2026 data, A-attested traffic carried far fewer robocalls than B or C traffic, which is why the analytics engines treat attestation as a meaningful positive signal.

How do I find out what attestation level my calls are getting?

Ask your originating carrier or CCaaS voice provider directly, per trunk and per number range, and get the answer in writing. You can verify independently by test-calling numbers you control on the major US mobile networks and inspecting the SIP Identity header at the receiving end, or by using a call-testing service that decodes it. If any traffic comes back signed B, ask specifically what verification steps would move it to A.

What is the Robocall Mitigation Database and does my business need to file?

It is a public FCC database in which every voice service provider, gateway provider and intermediate provider certifies its STIR/SHAKEN implementation and describes its robocall mitigation program. Downstream providers may not accept traffic directly from a voice service provider that is not listed. A contact center buying service from a carrier does not file; its providers do. Search the database for every carrier and reseller in your chain before you sign a contract.

Does the UK use STIR/SHAKEN?

No. Ofcom assessed CLI authentication and decided in February 2024 not to mandate it, concluding it would be complex and costly and would not sufficiently hinder scam calls originating overseas. The UK relies instead on CLI guidance: since January 2025 providers are expected to block calls from abroad presenting UK numbers, and from July 2027 calls from abroad presenting UK mobile numbers will show as withheld. Calls from the UK into US networks still meet STIR/SHAKEN at the US end.

Will getting A attestation remove an existing Spam Likely label?

On its own, no. Labels are applied by analytics engines working for the terminating carriers, and attestation is only one input to their scoring alongside traffic patterns, complaint data and number history. A number that has already been flagged usually needs remediation: registration with the analytics providers, a redress request through the carrier's published contact point, and a genuine change in the dialing behavior that earned the label. Attestation helps the case; it does not close it.

Do offshore teams presenting UK numbers need to worry about Ofcom's rules?

Yes. Since January 29, 2025, UK providers are expected to block international calls presenting a UK number except in defined legitimate cases, such as a UK mobile user roaming abroad. From July 15, 2027, calls from abroad presenting UK mobile numbers will have the presentation number treated as withheld. An offshore floor dialing UK consumers needs routing and number arrangements that fit the permitted use cases, or its CLIs will stop displaying altogether.

References

Keep Reading

Talk to people who run this daily

We implement and operate Five9 outbound floors in the UK and US: carrier relationships, attestation, number strategy and the dialing behavior that keeps labels off. A dedicated pod, not a ticket queue.

Talk to us