ServicesHow It WorksIndustriesResultsInsightsBuild My Plan
Spam Call Prevention

What is STIR/SHAKEN caller ID and how does it work?

Back to InsightsWhat is STIR/SHAKEN caller ID and how does it work?

What is STIR/SHAKEN caller ID and how does it work?

Key Facts

  • In December 2025, 88.1% of calls signed by prolific robocallers carried A-level attestation, up 10.0% from November.
  • https://transnexus.com/blog/2026/shaken-statistics-december-2025/

The Robocall Problem Undermining Your Lead Response

Your phone rings. You don't recognize the number. You don't answer — and neither do your customers. That instinct, trained into all of us by years of scam calls, is quietly killing the response rates businesses work so hard to build.

Illegal robocalls and caller ID spoofing have eroded trust in the entire phone system. The FCC notes that caller ID authentication technology is critical to protecting the public because spoofing "erodes the ability of callers to illegally spoof a caller ID, which scammers use to trick the public into answering their phones when they shouldn't" (FCC guidance). When a scammer can display any number they choose, every incoming call becomes a gamble.

The scale of the problem is sobering. According to TransNexus network data drawn from more than 100 voice service providers, robocalls continued to tick upward in December 2025, and the most prolific robocall signers are adapting — with 88.1% of their signed calls carrying full A-level attestation, a strategic shift apparently designed to improve call completion rates and slip past blocking systems.

Why traditional caller ID fails here comes down to how modern calls travel:

  • Caller ID information is easily falsified as calls pass through the complex web of interconnected VoIP networks.
  • Traditional caller ID simply displays whatever number the originator claims — with no verification.
  • STIR/SHAKEN authentication only works in IP networks, so calls routed over older non-IP segments lose their verification data entirely (industry analysis).

That last point matters more than most businesses realize. In June 2025, only 40.4% of calls arrived at termination with authentication information intact, down from a peak of 49.3% in October 2024 — a level one analysis called "way too low for STIR/SHAKEN to be effective" (TransNexus). By December 2025, that figure had only recovered to 44.4% (updated data).

For businesses that depend on fast phone responses, this trust deficit has a real cost. When customers screen unknown numbers, a legitimate callback from your team — or from a service like CallMyLeads answering an inbound lead in seconds — gets lumped in with the scam traffic. And as Numeracle points out, even properly authenticated calls can still be mislabeled by third-party call analytics that judge reputation based on volume and consumer feedback, not identity. Spoofing prevention alone can't restore what robocalls broke: the reflex to pick up.

How STIR/SHAKEN Authenticates Caller ID to Restore Trust

Every time your phone rings, there's a silent cryptographic handshake happening behind the scenes — and it's the only thing standing between you and a spoofed caller ID. Here's how STIR/SHAKEN turns that handshake into proof you can trust.

When a call travels over an IP network, the originating provider attaches a digital certificate of authenticity to it — essentially a tamper-proof signature that travels with the call. According to the FCC, this lets the receiving phone company verify that the number on the caller ID display is genuinely the number placing the call. The provider creates a SIP Identity header containing the calling number, called number, timestamp, attestation level, and an origination identifier, as technical documentation from TransNexus explains. If every verification step passes, the number hasn't been spoofed.

Not all signatures carry the same weight. The framework grades each call with one of three attestation levels, and the grade matters:

  • Full Attestation (A) — the provider has authenticated the caller and confirmed they're authorized to use the number. The gold standard.
  • Partial Attestation (B) — the caller is authenticated, but the provider can't fully verify their right to use the number.
  • Gateway Attestation (C) — the call originated elsewhere and the provider can only vouch for where it entered the network.

Full Attestation does the heavy lifting for legitimate businesses. As Bandwidth notes, A-level attestation "increases trust in your calls and may help lower the chance that your calls will be labeled or blocked by a terminating carrier." That matters enormously when speed-to-lead decides whether a customer books with you or a competitor.

This isn't optional. The FCC adopted rules in 2020 requiring implementation by June 30, 2021, following the TRACED Act signed into law on December 31, 2019. Providers must also file in the FCC's Robocall Mitigation Database to legally originate or carry calls, per Numeracle.

Adoption is real: industry tracking data shows SHAKEN-authorized providers hit an all-time high of 1,606 in June 2025. Yet only 40.4% of calls arrived at termination with authentication information intact that month, because calls routed over non-IP segments lose their signatures. By December 2025, that figure had climbed to 44.4%, according to TransNexus statistics.

There's a caveat worth knowing: STIR/SHAKEN verifies identity, not intent. Spam labels come from third-party analytics that have been scoring calling behavior since 2017. That's why services like CallMyLeads pair authenticated calling with proactive spam screening — so legitimate customer calls get through, and junk never wastes your team's time in the first place.

Why STIR/SHAKEN Alone Isn’t Enough—and What CallMyLeads Does About It

Here's the uncomfortable truth: a call can pass STIR/SHAKEN authentication with flying colors and still get labeled as spam. The framework was never designed to solve that problem—and for businesses that live and die by answered calls, that gap matters a lot.

STIR/SHAKEN only authenticates who is calling. It does not decide whether a call is spam, a scam, or unwanted. That judgment comes from third-party call analytics at the carrier level, in use since 2017, which label numbers based on calling behavior, call volume, and consumer feedback, according to Numeracle's STIR/SHAKEN resource center. Even a fully authenticated number can still get mislabeled by call reputation algorithms.

Coverage is the second weak spot. STIR/SHAKEN only works in IP networks, so when a call routes through older, non-IP segments of the phone network, the authentication information gets stripped out along the way, per the FCC. The numbers show how big this problem is: only 40.4% of calls arrived at their destination with authentication intact in June 2025, down from a peak of 49.3% in October 2024, according to TransNexus. That figure recovered only slightly to 44.4% by December 2025.

There's also a twist that should concern every legitimate business. In December 2025, 88.1% of calls signed by prolific robocallers carried A-level attestation—the highest trust level—as these bad actors shifted strategy to improve their call completion rates, per TransNexus December 2025 statistics. In other words, scammers are learning to look trustworthy.

So what actually protects your calls? Two things working together:

  • Full Attestation (A-level) on every outbound call—this increases trust and may lower the chance that calls get labeled or blocked by the receiving carrier.
  • Routing calls through providers with strong IP network coverage, so authentication isn't lost mid-journey.
  • Call reputation management, since authentication alone won't stop spam labels.
  • Clean calling behavior—steady volume patterns and proper number registration that reputation algorithms reward.

This is the approach CallMyLeads takes. Outbound lead responses are built on Full Attestation, and the broader system layers in compliance—A2P 10DLC registration, consent handling, and quiet-hours rules—plus spam screening on the inbound side so junk calls never eat into response time. For a business where the first reply usually wins the job, a missed call to a hot lead because it got mislabeled is a cost you can't afford.

STIR/SHAKEN is a strong foundation. But treating it as the whole answer is how legitimate calls end up in the spam folder.

Frequently Asked Questions

What is STIR/SHAKEN and does it actually stop robocalls?
STIR/SHAKEN is an FCC-required framework that uses digital certificates to verify that the number on your caller ID is genuinely the number placing the call. It doesn't stop robocalls — it only makes caller ID spoofing harder. The FCC notes it erodes scammers' ability to trick people into answering spoofed calls (FCC guidance).
Is STIR/SHAKEN mandatory for phone providers?
Yes. Following the TRACED Act signed into law on December 31, 2019, the FCC adopted rules in 2020 requiring voice providers to implement STIR/SHAKEN in the IP portions of their networks by June 30, 2021. Providers must also file in the FCC's Robocall Mitigation Database to legally originate or carry calls, per Numeracle.
What do the A, B, and C attestation levels mean?
Full Attestation (A) means the provider authenticated the caller and confirmed they're authorized to use the number — the gold standard. Partial Attestation (B) means the caller is authenticated but their right to use the number isn't fully verified, and Gateway Attestation (C) means the provider can only vouch for where the call entered the network. Per Bandwidth, A-level attestation increases trust and may lower the chance your calls get labeled or blocked.
Can my legitimate business calls still get flagged as spam even with STIR/SHAKEN?
Yes. STIR/SHAKEN only verifies identity, not intent — spam labels come from third-party call analytics that have been scoring calling behavior, volume, and consumer feedback since 2017, according to Numeracle. Even fully authenticated numbers can be mislabeled, which is why CallMyLeads pairs authenticated calling with proactive reputation and spam screening.
Why do so many calls lose their STIR/SHAKEN verification?
STIR/SHAKEN only works in IP networks, so when a call routes through older non-IP segments, the authentication signature gets stripped out mid-journey. Only 40.4% of calls arrived at termination with authentication intact in June 2025, down from a peak of 49.3% in October 2024 — a level one analysis called way too low for the framework to be effective (TransNexus).
Are robocallers finding ways around STIR/SHAKEN?
Unfortunately, yes. In December 2025, 88.1% of calls signed by the most prolific robocallers carried full A-level attestation — the highest trust level — a strategic shift apparently designed to improve call completion rates and slip past blocking systems (TransNexus data). This is why authentication alone isn't enough; clean calling behavior and reputation management matter just as much for legitimate businesses.

Beyond Authentication: Building Trust That Gets Answered

STIR/SHAKEN is a vital step in verifying caller identity, but as we've seen, authentication alone doesn't guarantee your calls will be answered—especially when robocammers now mimic full attestation to game the system and coverage gaps strip verification from over half of all calls. For businesses relying on speed-to-lead, the real solution lies in combining full A-level attestation with proactive spam screening, clean calling practices, and providers that maintain authentication across IP network paths. That’s exactly how CallMyLeads ensures your outbound lead responses aren’t just verified, but actually heard—turning more missed connections into booked appointments. If you’re ready to stop losing leads to silent phones, see how our done-for-you AI response service keeps your pipeline moving 24/7: Learn how CallMyLeads works.

Build My Lead Response Plan

Get lead response tips that actually work