STIR/SHAKEN
call authentication / caller ID authentication / attestation / robocall mitigation database
STIR/SHAKEN is how phone carriers sign outbound calls so the receiving network can tell the caller ID was not faked. The signature is your provider attesting to the accuracy of the number it is sending. Congress required it on internet protocol networks and asked only for reasonable measures elsewhere.
The name is an acronym stack. The statute spells it out: the framework means the secure telephone identity revisited and signature-based handling of asserted information using tokens standards proposed by the information and communications technology industry. The regulation defines the act itself in one clause worth keeping. To authenticate caller identification information is the process by which a voice service provider attests to the accuracy of caller identification information transmitted with a call it originates. So the statement belongs to the carrier, about a call it sent. It says nothing about your business.
One asymmetry explains why some calls carry no signature. Congress told the Commission to require a provider of voice service to implement the STIR/SHAKEN authentication framework in the internet protocol networks of the provider of voice service. For everything else it asked less. Providers must take reasonable measures to implement an effective call authentication framework in the non-internet protocol networks. Older equipment got the softer duty, so a call can travel a path where nothing is signed.
Underneath the signature sit duties your provider carries. Each voice service provider shall implement an appropriate robocall mitigation program. That program shall include reasonable steps to avoid originating illegal robocall traffic and shall include a commitment to respond within 24 hours to all traceback requests from the Commission, law enforcement, and the industry traceback consortium. Providers then file a certification in the Robocall Mitigation Database, which the rule describes as a database accessible via the Commission's website that lists all entities that make filings.
What that certification says is the part to read. A provider certifies either that it has fully implemented the STIR/SHAKEN authentication framework across its entire network, or to one of the partial alternatives the rule allows. That is a public statement about your supplier, not about you. It is also the piece of your outbound calling you can change by changing who you buy from.
In practice
None of this is something you configure. Most people reach this word after a stretch of outbound calls going unanswered, and the framework settles a narrower question: whether the number shown was authenticated by the provider that sent the call. Knowing it is a supplier property, and a publicly filed one, turns a complaint you cannot act on into a procurement question you can.
Not the same as
- Caller ID spoofing
- Spoofing is sending a number other than the line you are calling from, and the prohibition turns on intent. Authentication is the originating carrier signing what it sends, whether anyone meant harm or not.
- The rules about placing calls
- Consent rules govern which calls you may make. This governs how a call is signed on the way out. Separate question, separate owner.
Why it matters to you
If outbound calling is part of how the business gets paid, part of how your number is treated is decided by a company you contract with and can replace. That reframes the problem. It is not a mystery about the phone network. It is diligence on a supplier, and the supplier filed its own answer where anyone can read it.
What to ask or check
- 01Is our provider in the Robocall Mitigation Database, and what does its certification claim?
- 02Does it sign our calls with its own certificate, or through a third party acting for it?
- 03Does any of our traffic travel a non-internet-protocol path where no signature survives?
What people get wrong
That the signature says something about your business. The rule describes a provider attesting to the accuracy of the caller identification information on a call it originates, so the subject of the statement is the provider.
Red flags
- A phone supplier that cannot say what its own certification claims.
- An outbound calling plan with no discussion of who originates the traffic.
- A provider unable to describe the robocall mitigation program the rule requires it to have.
Who owns it
The voice service provider that originates the call. The rules address providers throughout, which is why changing the outcome usually means changing supplier rather than changing a setting.
Where you will see it
Not on the handset. It lives in your provider's filing and in the signaling between networks.