KuberEva Book a call

Home/Documentation/STIR/SHAKEN

STIR/SHAKEN & robocall mitigation

SS7 was trustworthy because only carriers could reach it. Once signaling moved to IP that assumption collapsed, and caller ID spoofing became trivial. STIR/SHAKEN is the replacement for trust-by-perimeter.

What the two names mean

The mechanism is straightforward in outline. The originating provider signs the call with a certificate, asserting something about how well it knows the caller. The terminating provider verifies that signature and can act on the result — display a verified indicator, label the call, or apply analytics.

Attestation levels: the part that affects you

The signature carries an attestation level, and it is the single most consequential detail for any organization making outbound calls.

Fig. 1 — attestation decides how you're treated A · B · C
You place a call Originating carrier signs it What the customer sees Carrier owns your number records in place A full Verified — rings normally answer rate protected Number owned elsewhere multi-carrier or CCaaS B partial Analytics get suspicious may be labeled Unknown origin entered at a gateway C gateway "Spam Likely" — or blocked campaign quietly fails The fix for B is paperwork, not engineering: give the originating provider the records to grant you A.
This is why legitimate outbound campaigns underperform. Not list quality, not timing — attestation. If you display numbers your outbound carrier cannot verify you own, you are shipping B or C on every call.
LevelNameThe provider is asserting
A Full attestation It knows the customer and confirms they are authorized to use the calling number.
B Partial attestation It knows the customer, but cannot confirm the right to use that specific number.
C Gateway attestation It only knows where the call entered its network. Essentially: "this arrived from somewhere."
Why your legitimate calls get labeled "Spam Likely" Terminating carriers and analytics engines weight attestation heavily. If your contact center presents a calling number that your outbound carrier cannot verify you own — very common when an organization uses one carrier for outbound and displays numbers owned by another, or when a CCaaS platform originates on your behalf — you get B or C attestation. That materially increases the chance your calls are labeled or blocked. The fix is administrative: ensure the originating provider has the records to grant full attestation for every number you present.

This is worth auditing specifically. Organizations frequently discover that outbound campaigns are underperforming not because of list quality or timing, but because half their calling numbers attract B attestation.

Who has to implement it

Most providers — voice service providers, gateway providers, and intermediate providers that receive unauthenticated calls directly from originating providers — are required to use STIR/SHAKEN to authenticate caller ID information.

Most enterprises are not themselves voice service providers, and reach these obligations through their carrier. But the boundary is less obvious than it looks. Organizations that resell voice, operate as an intermediate in a call path, or originate on behalf of third parties can fall within scope. If there is any doubt about your classification, it is worth confirming rather than assuming.

The Robocall Mitigation Database

The FCC launched the Robocall Mitigation Database in April 2021. Providers file certifications describing the status of their STIR/SHAKEN implementation and their robocall mitigation efforts.

The critical point: all providers in the call chain must file and maintain an RMD certification and plan, regardless of their STIR/SHAKEN implementation status. Having fully deployed STIR/SHAKEN does not exempt you from filing, and not having deployed it does not exempt you either.

Key dates

DateRequirement
Apr 2021Robocall Mitigation Database launched
30 Jun 2021Service providers required to complete RMD registration
28 Sep 2021Carriers directed to block calls — including internationally originated traffic — from providers not registered in the RMD
18 Sep 2025New third-party authentication rules took effect
1 Mar 2026Annual RMD recertification deadline

The September 2021 date is the one with teeth. Other providers may decline to accept call traffic directly from a voice service provider that is not listed in the database. Failing to file also exposes a provider to FCC fines.

Note the annual recertification. This is not a one-time filing — an entry that lapses can lead to traffic being refused, and the failure mode is abrupt rather than gradual.

What an enterprise should actually do

  1. Inventory every number you present as calling party, and identify which carrier owns each. Multi-carrier and CCaaS arrangements are where mismatches hide.
  2. Confirm the attestation level your calls receive, per number range, with your outbound provider. Ask directly; do not assume A.
  3. Fix the records that cause B attestation. This is usually paperwork — establishing with the originating provider that you are authorized to use the numbers — rather than an engineering change.
  4. Establish whether you are a provider under the rules. If you resell, originate on behalf of others, or sit in a call path as an intermediate, get that determined properly.
  5. If you file in the RMD, calendar the annual recertification and give it a named owner. Lapses are avoidable and expensive.
  6. Monitor how your calls are labeled. Answer rates by number range will tell you something is wrong before anyone reports it.

What STIR/SHAKEN does not do

It authenticates the calling number. It does not establish that the caller is honest, that the call is wanted, or that the content is legitimate. A fraudster calling from a number they genuinely own receives full attestation.

It is an identity mechanism, not a fraud filter — which is why robocall mitigation plans are a separate requirement alongside it, and why analytics engines still apply their own judgement on top.

Related reading

Underperforming outbound campaigns are often an attestation problem, not a list problem.

Book a call