Skip to content
Adrythm
Phones and the AI receptionist

STIR/SHAKEN

call authentication / caller ID authentication / attestation / robocall mitigation database

In short

STIR/SHAKEN is how phone carriers sign outbound calls so the receiving network can tell the caller ID was not faked. The signature is your provider attesting to the accuracy of the number it is sending. Congress required it on internet protocol networks and asked only for reasonable measures elsewhere.

The name is an acronym stack. The statute spells it out: the framework means the secure telephone identity revisited and signature-based handling of asserted information using tokens standards proposed by the information and communications technology industry. The regulation defines the act itself in one clause worth keeping. To authenticate caller identification information is the process by which a voice service provider attests to the accuracy of caller identification information transmitted with a call it originates. So the statement belongs to the carrier, about a call it sent. It says nothing about your business.

One asymmetry explains why some calls carry no signature. Congress told the Commission to require a provider of voice service to implement the STIR/SHAKEN authentication framework in the internet protocol networks of the provider of voice service. For everything else it asked less. Providers must take reasonable measures to implement an effective call authentication framework in the non-internet protocol networks. Older equipment got the softer duty, so a call can travel a path where nothing is signed.

Underneath the signature sit duties your provider carries. Each voice service provider shall implement an appropriate robocall mitigation program. That program shall include reasonable steps to avoid originating illegal robocall traffic and shall include a commitment to respond within 24 hours to all traceback requests from the Commission, law enforcement, and the industry traceback consortium. Providers then file a certification in the Robocall Mitigation Database, which the rule describes as a database accessible via the Commission's website that lists all entities that make filings.

What that certification says is the part to read. A provider certifies either that it has fully implemented the STIR/SHAKEN authentication framework across its entire network, or to one of the partial alternatives the rule allows. That is a public statement about your supplier, not about you. It is also the piece of your outbound calling you can change by changing who you buy from.

In practice

None of this is something you configure. Most people reach this word after a stretch of outbound calls going unanswered, and the framework settles a narrower question: whether the number shown was authenticated by the provider that sent the call. Knowing it is a supplier property, and a publicly filed one, turns a complaint you cannot act on into a procurement question you can.

Not the same as

Caller ID spoofing
Spoofing is sending a number other than the line you are calling from, and the prohibition turns on intent. Authentication is the originating carrier signing what it sends, whether anyone meant harm or not.
The rules about placing calls
Consent rules govern which calls you may make. This governs how a call is signed on the way out. Separate question, separate owner.

Why it matters to you

If outbound calling is part of how the business gets paid, part of how your number is treated is decided by a company you contract with and can replace. That reframes the problem. It is not a mystery about the phone network. It is diligence on a supplier, and the supplier filed its own answer where anyone can read it.

What to ask or check

  1. 01Is our provider in the Robocall Mitigation Database, and what does its certification claim?
  2. 02Does it sign our calls with its own certificate, or through a third party acting for it?
  3. 03Does any of our traffic travel a non-internet-protocol path where no signature survives?

What people get wrong

That the signature says something about your business. The rule describes a provider attesting to the accuracy of the caller identification information on a call it originates, so the subject of the statement is the provider.

Red flags

  • A phone supplier that cannot say what its own certification claims.
  • An outbound calling plan with no discussion of who originates the traffic.
  • A provider unable to describe the robocall mitigation program the rule requires it to have.

Who owns it

The voice service provider that originates the call. The rules address providers throughout, which is why changing the outcome usually means changing supplier rather than changing a setting.

Where you will see it

Not on the handset. It lives in your provider's filing and in the signaling between networks.

Caller ID spoofing

Caller ID spoofing is sending a number other than the line you are calling from. The federal prohibition is not about the technique. It applies to transmitting misleading or inaccurate caller identification information with the intent to defraud, cause harm, or wrongfully obtain anything of value.

Robocall

A robocall is an outbound call that plays a recorded message. The Telemarketing Sales Rule prohibits placing one to sell something unless the person gave express agreement in writing beforehand. The rule covers calls you place. A system that answers calls coming in to you is a different thing.

Call tracking

Call tracking replaces the phone number shown to a visitor with a substitute number that routes to your real one. Only calls dialed through that substitute are measured. Google assigns a forwarding number when call reporting is on, and Microsoft requires an ad group to have reached 10 clicks and 10 dollars of spend in 30 days.

Telemarketing Sales Rule

The Telemarketing Sales Rule is the FTC rule governing sales calls. Beyond the do not call list, it sets what a caller must say and when they may call: residential calls only between 8am and 9pm local time, and a prompt disclosure that the purpose of the call is to sell something.

AI voice calls

An AI voice call uses a synthesized or cloned voice to speak to the person who answers. In February 2024 the FCC confirmed those voices fall under the existing rules on artificial or prerecorded voice, so the same consent requirements apply. The message must also identify your business and offer an automated way to opt out.

National Do Not Call Registry

The National Do Not Call Registry is the federal list of numbers telemarketers may not call. Sellers subscribe by area code, and FTC guidance says call lists must be scrubbed against it at least every 31 days. Business to business calls are largely outside the rule, with narrow exceptions.

Want this explained against your own numbers?

Twenty minutes, a straight answer, and no follow-up sequence if you decide not to work with us.