Compliance · STIR/SHAKEN

STIR/SHAKEN: the operator's guide from a carrier that signs its own calls.

Most STIR/SHAKEN content online is written by consultants, resellers, or CPaaS platforms that don't hold their own certificate. SIPNEX is the actual licensed carrier signing your calls with its own SP-KI keys. Every section below is implementation, not theory.

01 · The standard

What STIR/SHAKEN actually is.

DEFINITION

STIR/SHAKEN — also written SHAKEN/STIR or STIR SHAKEN — is a caller ID authentication framework. It lets the originating carrier cryptographically sign each outbound call, so the terminating carrier can verify the caller is authorized to use the number displayed.

STIR — Secure Telephone Identity Revisited — is the IETF framework for cryptographically signing caller ID information. The framework is specified in RFC 8224, RFC 8225, and RFC 8226.

SHAKEN — Signature-based Handling of Asserted information using toKENs — is the ATIS/SIP Forum implementation that actually delivers STIR over SIP trunks. When people say "STIR/SHAKEN" they usually mean the SHAKEN profile running on production carrier networks, which is what the Federal Communications Commission (FCC) has mandated for US carriers since June 2021. The tortured acronym is deliberate, by the way — a nod to James Bond's "shaken, not stirred."

The goal is narrow: verify that the phone number shown on an outbound call belongs to a caller who has the right to use it. It is the industry's direct counter to caller ID spoofing. The originating carrier authenticates the calling party, then signs the call with a private key tied to its Service Provider certificate — a standard X.509 digital certificate issued by one of the approved STI certificate authorities, not something a carrier can mint for itself.

On the receiving side, the roles flip to verify the calling identity. The terminating carrier retrieves the certificate's public key, validates the signature, and reads the attestation level the originator claimed. The signed token carries additional information beyond the number itself — including a unique origination identifier that supports industry traceback of bad traffic. The phone then displays — or blocks — accordingly.

What STIR/SHAKEN is not: it's not a consent mechanism, not a do-not-call replacement, not TCPA compliance, not a magic box that makes answer rates go up regardless of who you're calling. It's one layer of a multi-layer trust system. Treating it as anything more is a mistake.

Where STIR/SHAKEN stops.

  • IP networks only — Calls that cross legacy TDM or other non-IP segments lose the signature. The FCC requires those providers to upgrade or develop alternatives, but the gap is real today.
  • Authority, not legality — Attestation verifies number authority. It says nothing about the legality or content of the call itself.
  • Display varies — Treatment differs by terminating carrier and handset. A-level attestation is necessary for good display, not sufficient.
  • International traffic — Calls entering the US through gateways typically arrive at C-level, whoever originated them.

One extension is coming next: Rich Call Data (RCD). It extends the STIR/SHAKEN PASSporT to carry a display name, a logo, and a call reason alongside the attestation. The industry is still rolling it out, and handset support varies by carrier. Treat it as direction, not a feature anyone can fully deliver today.

So the fix is real, but it is not the whole fix. The right way to read the rest of this page: the standard sets the floor, and your carrier sets what you get from it.

02 · Attestation

A, B, C: the three levels nobody explains clearly.

Every signed call carries an attestation level. Your answer rate depends on it. Here's what each level actually means — and which one SIPNEX delivers.

The grade is not about how good your leads are or how clean your script is. It is about what the carrier that signs the call can prove.

A

Full attestation

WHAT SIPNEX DELIVERS
WHEN IT'S GIVEN

Originating carrier has direct customer relationship AND verified the caller has authority to use the phone number.

WHAT HAPPENS ON THE PHONE

Terminating carriers display 'Verified Caller' with a checkmark. Highest answer rates.

B

Partial attestation

WHEN IT'S GIVEN

Originating carrier has direct customer relationship but cannot verify phone number authority.

WHAT HAPPENS ON THE PHONE

Neutral or unverified display. Measurable answer-rate drop vs A.

C

Gateway attestation

WHEN IT'S GIVEN

Originating carrier received the call from another network. Cannot attest to origin at all.

WHAT HAPPENS ON THE PHONE

Frequently displayed as 'Scam Likely' or 'Potential Spam.' Significant answer-rate penalty.

The same three levels, side by side:

LEVEL NAME WHEN IT'S GIVEN WHAT THE PHONE SHOWS ANSWER-RATE IMPACT
A Full attestation Originating carrier has direct customer relationship AND verified the caller has authority to use the phone number. 'Verified Caller' with a checkmark Highest answer rates
B Partial attestation Originating carrier has direct customer relationship but cannot verify phone number authority. Neutral or unverified label Measurable drop vs A-level
C Gateway attestation Originating carrier received the call from another network. Cannot attest to origin at all. 'Scam Likely' or 'Potential Spam' overlays Significant answer-rate penalty

Here is the short version. An A means the carrier knows you and knows your number. A B means it knows you, but not your number. A C means it just passed the call along. The phone at the far end reads that grade and picks what to show. That choice drives how many of your calls get picked up.

03 · Why most providers can't give you A

The reseller ceiling is B-level, and nobody tells you.

Most "VoIP providers" you can buy a SIP trunk from are not carriers. They're resellers or CPaaS platforms sitting on top of an actual carrier. The call path looks like this:

Your dialer → Reseller platformUpstream carrier (signs here) → PSTN

The problem is that the upstream carrier signing the call has a relationship with the reseller — not with you. It doesn't know your business. It doesn't know which numbers you're authorized to use. It can't verify number authority on your behalf. So it signs at B-level — "I know my reseller customer, but I can't attest to their customer's phone number authority."

B-level is the ceiling for calls originated through a reseller. You can have perfect TCPA compliance, clean DNC scrubbing, legitimate consent — it doesn't matter. The signature will still say B because the carrier holding the pen doesn't have the information needed to sign A.

This is why most dialer operators report a mysterious answer-rate drift as their volume scales. It's not mysterious. It's the attestation ceiling catching up with their call patterns.

There is a quick way to test this. Ask your provider one question: who signs my calls? If the answer is "our upstream does," you have found your ceiling. The pen is not in their hand. No plan tier, no add-on, no support ticket can change that.

04 · SIPNEX implementation

We hold the certificate. We sign your calls ourselves.

SIPNEX is the licensed carrier in the call path. Not a reseller wrapper. Not a CPaaS abstraction over someone else's trunk. Our name is on the FCC filing. Our private key is on the signature. The company holding both is operator-owned SIPNEX Telecom.

That means three things your current provider probably can't offer:

  • Direct A-level attestation — Because the direct customer relationship is with you (not with a middleman), we can attest to your authority over the phone numbers you dial from.
  • Direct RMD filing — We're in the Robocall Mitigation Database as a primary filer, not under an umbrella.
  • Signature reputation we own — Our SP-KI reputation is ours to protect. We actively manage it. Bad actors don't last on our network because the reputational cost is on our company, not some distant upstream.
YOUR CALL PATH ON SIPNEX
STEP 1
Your VICIdial instance places outbound call
STEP 2 · SIGNED HERE
SIPNEX signs with our SP-KI certificate at A-level
STEP 3
PSTN validates signature · recipient phone displays "Verified Caller"

How a call gets signed, in seven steps.

Here is the full path a call takes on our network, from the first packet to the screen:

  1. Your dialer sends the SIP INVITE to SIPNEX.
  2. We check the caller ID number against your verified number authority.
  3. We create a PASSporT — a signed JSON web token carrying the attestation level, origin number, destination, and timestamp.
  4. The PASSporT goes into the call's SIP Identity header, signed with our SP-KI private key.
  5. The call routes to the terminating carrier.
  6. That carrier fetches our public certificate and validates the signature chain back to an approved STI-CA.
  7. The handset displays "Verified Caller," a neutral label, or a spam warning based on the attestation.

The signature only counts because of the chain of authorities behind it. Three bodies govern who gets to sign:

  • STI-GA — the governance authority. It sets the rules for who may obtain a signing certificate.
  • STI-PA — the policy administrator. It issues the tokens carriers use to request certificates.
  • STI-CA — the approved certificate authorities. They issue the SP certificates carriers sign with.

Resellers rent a place in this chain. SIPNEX holds its own SP-KI certificate inside it.

Why should you care about the chain? Because trust flows down it. A signed call is a claim, and the chain is what makes the claim worth something. When we sign your call, our name is on the line — not a vendor two hops up. That is the whole pitch, and it is easy to check.

How caller ID authentication became law.

None of this was optional. Congress passed a law, and the FCC turned it into hard dates:

  • DEC 2019 — TRACED Act signed, directing the FCC to mandate call authentication.
  • MAR 31, 2020 — FCC adopts rules requiring STIR/SHAKEN caller ID authentication.
  • JUN 30, 2021 — Implementation deadline for large US carriers.
  • 2022–2023 — FCC extends obligations to gateway and intermediate providers.
05 · Robocall mitigation

FCC Robocall Mitigation Database.

Every US carrier is required to be listed in the FCC's Robocall Mitigation Database with a filed robocall mitigation plan. SIPNEX is a direct filer. Our plan covers number authority verification, suspicious traffic detection, customer vetting, and incident response.

Read our mitigation approach →
06 · TCPA interaction

STIR/SHAKEN is not TCPA.

A-level attestation doesn't make your campaign TCPA-compliant, and TCPA compliance doesn't give you A-level attestation. They operate at different layers. You need both: the right carrier signing your calls, and your own policy for consent, DNC, and calling hours.

TCPA compliance guide →
Frequently asked

About STIR/SHAKEN implementation.

Short answers to the things buyers ask us most. Each one is the real rule, not the sales gloss.

What is STIR/SHAKEN?
STIR/SHAKEN is a pair of industry standards that use cryptographic signing to verify caller ID authenticity on outbound phone calls. STIR (Secure Telephone Identity Revisited) is the underlying IETF framework defined in RFCs 8224, 8225, and 8226. SHAKEN (Signature-based Handling of Asserted information using toKENs) is the ATIS/SIP Forum implementation that delivers STIR over SIP trunks. Together they let originating carriers attest that the caller is authorized to use the number they're calling from. Terminating carriers then validate that attestation before the call rings.
What does 'attestation level' mean?
Attestation is the originating carrier's statement about how confident it is that the caller is using a phone number they have the right to use. There are three levels: A (full), B (partial), and C (gateway). The level is baked into the cryptographic signature and travels with the call. Terminating carriers and handsets read the attestation to decide whether to display 'Verified Caller,' show a neutral label, or flag the call as potentially spoofed.
What's the difference between A, B, and C level attestation?
A-level means the originating carrier has a direct customer relationship with the caller AND has verified the caller has authority to use the phone number on the call. B-level means the carrier has the customer relationship but can't verify the number authority. C-level means the call came in through a gateway from another network — the carrier is just passing it along and can't attest to origin. A-level calls get 'Verified Caller' display treatment on major carriers; B and C don't.
Why does attestation level matter for my answer rate?
Terminating carriers increasingly use attestation level to decide whether to display caller ID honestly, show a spam warning, or silently block. An A-level call can show up as 'Verified Caller' with a green checkmark. A B-level call often shows neutral. C-level calls frequently get 'Scam Likely' or 'Potential Spam' overlays. The difference in answer rate between A and C can be 30% or more on identical dialing patterns.
Does SIPNEX provide A-level attestation?
Yes, directly. SIPNEX holds its own STIR/SHAKEN Service Provider certificate (SP-KI), is a direct filer in the FCC Robocall Mitigation Database, and signs every outbound call we originate using our own keys. There is no upstream carrier in the signing path.
Do I need to file anything with the FCC as a SIPNEX customer?
As a customer purchasing SIP trunk service from SIPNEX, you don't personally file with the FCC — SIPNEX, as the licensed carrier, handles the 499 contribution and the Robocall Mitigation Database filing. If you are yourself operating as a carrier or reseller, your FCC obligations depend on your specific status; we can walk through that on a call.
How does STIR/SHAKEN interact with TCPA compliance?
STIR/SHAKEN is a carrier-layer cryptographic attestation. TCPA is a federal consumer protection law covering consent, do-not-call lists, calling hours, and caller ID accuracy obligations. They overlap but don't substitute: A-level attestation doesn't mean your campaign is TCPA compliant. You need both. Get STIR/SHAKEN from a carrier that signs directly, and keep your own TCPA policy at the campaign level.
What happens if I try to spoof caller ID on your network?
If you present a phone number on outbound that you haven't verified authority to use with us, we'll sign the call at B-level instead of A. Worse, if the pattern looks like illegal spoofing, we'll flag it and can suspend service. Our incentive as a carrier is to keep our SP-KI reputation clean.
What does a STIR/SHAKEN PASSporT contain?
A PASSporT (Personal Assertion Token) is the signed JSON web token at the heart of STIR/SHAKEN. It carries the attestation level, the originating number, the destination, and a timestamp. The originating carrier signs it and places it in the call's SIP Identity header. The terminating carrier then validates it against the signer's public certificate.
Does STIR/SHAKEN work on landlines and non-IP networks?
No. STIR/SHAKEN signatures only survive IP call paths. When a call crosses a legacy TDM or other non-IP segment, the SIP Identity header carrying the signature is dropped. The FCC requires providers on non-IP networks to upgrade or pursue alternative authentication. Until that happens, some legitimate calls still arrive unverified.
Who issues STIR/SHAKEN certificates?
Approved certificate authorities called STI-CAs issue the Service Provider certificates carriers sign with. The ecosystem is overseen by the STI-GA (Secure Telephone Identity Governance Authority), which sets the rules for who may participate. The STI-PA (Policy Administrator) issues the tokens carriers use to request certificates. SIPNEX holds its own SP-KI certificate inside this chain — resellers don't.

Stop accepting B-level as the ceiling.

If your current answer rate feels capped and you can't figure out why, the answer is usually in the attestation your carrier can give you. Move to a carrier that holds its own certificate. Move to SIPNEX.