STIR/SHAKEN is a framework for authenticating caller ID on phone calls that travel over IP networks. STIR (Secure Telephone Identity Revisited) is the set of technical standards for signing caller information, and SHAKEN (Signature-based Handling of Asserted information using toKENs) is the industry framework for how carriers deploy it. The originating carrier attaches a digital signature vouching for the calling number, and the terminating carrier checks that signature, so it can tell whether the caller ID was likely spoofed. US and Canadian regulators have required voice providers to implement it on their IP networks.
At a glance
- Carriers sign the calling number on outbound IP calls; the receiving carrier verifies the signature.
- The signature carries an attestation level (A, B or C) showing how much the signing carrier knows about the caller’s right to use the number.
- It authenticates caller ID; it doesn’t block calls on its own. Carriers use the result alongside analytics to label or block.
- Required for many voice providers in the US and Canada on IP networks; calls crossing older non-IP networks may lose the signature.
- Businesses influence attestation by making sure their providers can verify the numbers they display.
What problem it solves
The phone network was built on trust: the caller ID number sent with a call was simply passed along. Robocallers and scammers exploited that by spoofing numbers, making calls appear to come from local numbers, government agencies or real businesses. Recipients stopped answering unknown numbers, which hurt legitimate callers, and businesses found their own numbers spoofed in scam campaigns.
STIR/SHAKEN gives carriers a way to tell an authenticated number from one that may be spoofed. That doesn’t end unwanted calls, but it gives carriers and analytics providers a reliable signal to work with, and it lets them trace abusive calls back to the provider that signed them.
How it works
Signing. When your call enters an originating carrier’s IP network, the carrier creates a digital signature containing the calling and called numbers, a timestamp and an attestation level, and adds it to the SIP signaling.
Attestation levels. A (full attestation): the carrier knows the customer and that they are authorized to use the number. B (partial): it knows the customer but can’t confirm their right to the number. C (gateway): it is passing along a call it can’t vouch for, often one that came from another network.
Verification. The terminating carrier checks the signature against the signing carrier’s certificate, which comes from a governed certificate system. The result can feed into call analytics, labels such as “verified” on some devices, and blocking decisions.
Non-IP gaps. The signature travels in SIP. Where a call crosses older TDM (non-IP) networks, the signature can be lost. Regulators have required providers to address those gaps in different ways, and rules continue to change.
Robocall mitigation. In the US, voice providers have also been required to file robocall mitigation plans and to take part in efforts to trace illegal calls. Rules and deadlines have changed several times; check current requirements with your provider.
If you run outbound calling, our SIP Trunking page covers what to check with voice providers.
When it matters for buyers
- Outbound calling programs and contact centers. Attestation level and number reputation affect whether calls are answered.
- Using numbers from several providers. Calls displaying a number that the sending provider doesn’t control may get lower attestation.
- Changing voice providers. Confirm how the new provider will sign your calls before porting numbers.
- Your numbers are being spoofed. Authentication and carrier analytics are part of the response.
Questions to ask vendors
- What attestation level do our calls receive, and can you show it per call or per number?
- How do you verify our right to use numbers we bring from other carriers?
- Do any of our calls cross non-IP networks where the signature could be lost?
- Do you offer branded calling, number reputation monitoring or spam label remediation?
- How do you handle traceback requests and comply with current US robocall mitigation rules?
How it differs from spam call labeling
STIR/SHAKEN answers one question: was the caller ID likely spoofed? Spam call labeling answers another: is this call likely unwanted? Labeling engines run by carriers and analytics firms use the STIR/SHAKEN result as one input, alongside call volumes, patterns and complaints. A fully attested call from a legitimate business can still be labeled “Spam Likely” if its calling pattern looks like spam, and an unsigned call is not automatically labeled.
