STIR/SHAKEN Compliance Explained for Your Business

Your customers decide in two seconds whether to answer your call. Here is how caller ID authentication works, why legitimate numbers still get flagged as Spam Likely, and what you can actually do about it.

Call (336) 544-4000 Ask a Voice Engineer

Quick answer: STIR/SHAKEN is a caller ID authentication framework that United States phone carriers use to verify that the number shown on caller ID actually belongs to the caller. Your VoIP provider handles the technical compliance. Your job is to use only numbers your business owns, keep them organized, and work with a provider that signs your calls at the highest attestation level.

A customer sees your business number on their phone. They recognize it, they answer, and your team gets the chance to help. If that same number shows up as Spam Likely, the call never gets that chance. Nobody tells you it happened, either. The phone just does not ring on the other end the way you think it does.

That is the practical reason people search for STIR/SHAKEN compliance explained. It is not curiosity about telecom regulation. It is a dental office in High Point wondering why appointment confirmations stopped getting answered, or a contractor whose crews cannot reach homeowners the morning after a storm. I have taken both of those calls. This article covers what the framework actually does, what it cannot fix, and the specific questions worth asking your phone provider.

What does STIR/SHAKEN compliance mean?

STIR/SHAKEN is a pair of technical standards. STIR stands for Secure Telephone Identity Revisited, and SHAKEN stands for Signature-based Handling of Asserted information using toKENs. Nobody remembers that. What matters is the job: when your business places an outbound call through a compliant provider, that provider attaches a digital signature confirming it has the right to send calls from your number. The carrier on the receiving end checks the signature before the phone rings.

The framework exists because of caller ID spoofing, where scammers place calls that display a number they do not own. Your number, maybe. Spoofing got so bad that Congress passed the TRACED Act in 2019, and the FCC now requires voice service providers to implement STIR/SHAKEN caller ID authentication on their IP networks. Providers must also certify their implementation status in the FCC's public Robocall Mitigation Database. Carriers are not allowed to accept traffic from providers that have not filed.

Notice who carries the legal obligation there. The carrier does, not you. Your business does not file anything with the FCC to be STIR/SHAKEN compliant. But the way you manage your outbound numbers directly affects how confidently your provider can vouch for your calls, and that is where attestation comes in.

How do attestation levels A, B, and C work?

STIR/SHAKEN does not stamp calls as good or bad. It attaches one of three attestation levels, which is the provider's formal statement of how much it knows about the call it is signing.

Attestation Level What the Provider Is Saying Typical Business Situation
A (Full) We know this customer, and we know they are authorized to use this number. Calling from numbers your VoIP provider assigned to you, or numbers you properly ported in.
B (Partial) We know this customer, but we cannot fully confirm their right to this specific caller ID. Displaying a number your provider did not issue and cannot verify, such as a number left behind at an old carrier.
C (Gateway) We received this call from another network and cannot verify the original caller. Calls entering the US from international gateways or passing through multiple intermediate carriers.

Most people never see an A, B, or C on their screen. The receiving carrier uses the attestation level alongside other signals, like call volume patterns and consumer complaints, when its analytics engine decides whether a call looks normal, suspicious, or worth blocking outright. A-level attestation will not guarantee your call gets answered. B or C attestation, though, gives those filters one more reason to be skeptical of you.

Worth knowing: the FCC has proposed pairing A-level attestation with verified caller name display, so that phones would show a confirmed business name on authenticated calls. The details are still moving, but the direction is clear. Full attestation is becoming the ticket to looking legitimate on a customer's screen.

Smartphone showing an incoming call flagged with a red spam warning triangle next to a business VoIP desk phone, illustrating how STIR/SHAKEN caller ID authentication separates verified business calls from suspicious ones
One flagged number can silently cut off a business from its own customers. Caller ID authentication helps carriers tell verified calls from spoofed ones.

Key terms in plain English

STIR/SHAKEN
The caller ID authentication framework US carriers use to digitally sign outbound calls and verify the calling number was not spoofed.
Attestation
The confidence level (A, B, or C) a provider attaches to each signed call, based on how well it knows the caller and the number.
Caller ID spoofing
Placing a call that displays a number the caller does not own or control. Illegal when done with intent to defraud under the Truth in Caller ID Act. The FCC's spoofing consumer guide covers how it works.
Robocall Mitigation Database
The FCC's public registry where every voice provider must certify its STIR/SHAKEN implementation before other carriers may accept its traffic.
CNAM
The caller name display system, separate from STIR/SHAKEN. Authentication verifies the number; CNAM and newer branded calling services control the name shown.
Call labeling
Tags like Spam Likely or Scam Likely applied by carrier analytics engines. Labels are influenced by attestation but decided by call patterns, complaints, and reputation data.

Why is my business number showing as Spam Likely?

Here is the misunderstanding I run into most. An owner hears about STIR/SHAKEN, confirms their provider is compliant, and assumes the Spam Likely problem is solved. Then it happens again the next week.

Authentication confirms information about the calling number and the provider handling the call. It does not judge whether a customer wants the call, and it does not control the analytics engines that mobile carriers run on top of it. Those engines look at behavior. Unusually high call volume, lots of short calls, a burst of dials that nobody answers: all of it feeds a number's reputation score, and a legitimate business can trip those wires without doing anything wrong.

Think about what a normal week looks like around here. A roofing company in the Triad places sixty calls in one morning after a hailstorm. An insurance office calls every policyholder in a zip code after an ice event. A school district pushes out family notifications at 6 AM about a two-hour delay. Every one of those calls is wanted. To an algorithm watching raw call patterns, they can look like a robocall campaign.

So compliance is the floor, not the fix. If your number picks up a spam label, the path back usually runs through three things: confirming your calls carry A-level attestation, registering your numbers with the carrier analytics services that manage reputation, and adjusting calling patterns where you can. A provider with real engineers can walk you through all three. A provider with a ticket queue will tell you to wait and see.

Is your number already flagged?

Call your own business line from a personal cell phone on a different carrier. If you see Spam Likely, your customers see it too. Carolina Digital Phone's engineers help local businesses trace and fix caller ID reputation problems.

Call (336) 544-4000

What is your business actually responsible for?

You do not need to become a telecom lawyer. You need a tidy house. In practice that means one short list, reviewed a couple of times a year.

None of that is complicated. Most of it fits on one page in a drawer. The businesses that get burned are almost always the ones where nobody owns the list.

What should you ask your VoIP provider?

The right provider answers these plainly, on the phone, without routing you through three departments.

  1. Do you sign my outbound calls with STIR/SHAKEN, and what attestation level do my numbers receive?
  2. Are you certified in the FCC's Robocall Mitigation Database?
  3. When I port numbers in or add a new location, how do you make sure those numbers keep full attestation?
  4. If my number gets labeled Spam Likely, will you help me investigate it, and what does that process look like?
  5. How do you handle caller ID for mobile apps and remote workers?
  6. What is your process for registering my numbers with carrier analytics and branded caller ID services?

One caution on scope. STIR/SHAKEN is not HIPAA compliance, it is not E911 compliance, and it is not a records policy. A medical practice still needs safeguards around voicemail and texting. Schools and agencies still need location-aware emergency calling across buildings. Those deserve their own conversations, and a provider who serves those industries should be ready to have them.

A note from 45 years in this industry

I started in this business when caller ID did not exist. When it arrived, people trusted it completely, and for a couple of decades that trust was mostly deserved. Spoofing broke it. What STIR/SHAKEN is really trying to do is rebuild something we used to get for free.

Here is my honest read after watching this roll out since 2021. The framework works, the carriers have largely implemented it, and the FCC keeps tightening the gaps. But I still talk with business owners every month who found out about a spam label from an annoyed customer rather than from their phone company. The technology is national. The fix is always local: somebody who knows your numbers, looks at your call patterns, and stays on it until the label comes off.

Pick a provider based on that second part. The compliance certificate is table stakes.

Nicky Smith, Founder, Carolina Digital Phone

How Carolina Digital Phone handles caller authentication

Carolina Digital Phone signs outbound calls with STIR/SHAKEN authentication and works to keep customer numbers at full A-level attestation, whether the numbers were issued by us or ported in from another carrier. We have been the trusted local source for telephone, business messaging, and AI Receptionist services in the Carolinas for more than 25 years, serving businesses, schools, and government agencies from our Greensboro headquarters with geo-redundant data centers in Greensboro, Research Triangle Park, and Dallas.

The part our customers actually notice is different, though. When a number picks up a spam label or calls stop completing to one mobile carrier, you call (336) 544-4000 and a North Carolina engineer picks up, checks the caller ID in use, reviews the call patterns, confirms number ownership, and works the problem upstream with the carriers involved. No provider can promise every mobile network will display every call identically. We can promise you will not be troubleshooting it alone.

Keep your number worth answering

Number porting, business caller ID setup, full-attestation call signing, and a local team that investigates delivery problems instead of closing tickets. That has been the job since 2000.

Request a Free Caller ID Review

Frequently Asked Questions

What is STIR/SHAKEN in simple terms?

STIR/SHAKEN is a caller ID authentication system US phone carriers use to verify that the number displayed on an incoming call actually belongs to the caller. It attaches a digital signature to each call so the receiving carrier can detect spoofed numbers.

Does my small business need to register for STIR/SHAKEN?

No. The FCC places the implementation obligation on voice service providers, not on individual businesses. Your responsibility is to use numbers you own through a provider that signs calls, keeps its Robocall Mitigation Database certification current, and gives your numbers full attestation.

Why does my business number show as Spam Likely even though my provider is compliant?

Spam labels come from carrier analytics engines that weigh call volume, call duration, answer rates, and complaint data alongside attestation. A compliant business with unusual calling patterns can still be flagged. Fixing it involves confirming A-level attestation, registering numbers with carrier reputation services, and adjusting call patterns.

What is the difference between attestation levels A, B, and C?

A means the provider knows the caller and confirms their right to the number. B means the provider knows the caller but cannot fully verify the specific caller ID. C means the call arrived from another network and the original caller could not be verified. Full A attestation gives your calls the strongest credibility signal.

Does STIR/SHAKEN control the name displayed on caller ID?

No. Caller name display comes from CNAM databases and newer branded calling services, which are separate from call authentication. STIR/SHAKEN verifies the number; the name a customer sees can still vary by carrier, device, and contact list.

Can I fix a Spam Likely label myself?

Partially. You can register your numbers with the free reputation portals run by carrier analytics companies and reduce suspicious calling patterns. A VoIP provider with engineering support can go further by confirming attestation, verifying number ownership, and escalating with upstream carriers.

Your Customers Should Never Wonder Who Is Calling

Carolina Digital Phone signs your calls, protects your number's reputation, and answers the phone when something looks wrong. Trusted by Carolina businesses, schools, and agencies for more than 25 years.

Call (336) 544-4000