Telecom network equipment processing authenticated calls

6 Steps to A Level STIR/SHAKEN Attestation for U.S. SMBs

STIR/SHAKEN is the U.S. call-authentication framework that cryptographically signs outbound calls so recipients and carriers can verify caller ID and reduce spoofing. STIR is the IETF technical standard; SHAKEN is the ATIS/SIP Forum profile that puts it to work over SIP trunks. For your business, calls that carry a verified signature generally perform better than calls flagged as “Spam Likely” or left unlabeled.


TL;DR:

  • Achieving A-level attestation requires direct relationship and number ownership verification with your provider, which increases call trust and answer rates.
  • Providers relying on upstream certification or functioning through resellers often cannot deliver A-level signatures, reducing call credibility.
  • The FCC mandates implementation of STIR/SHAKEN for all U.S. voice providers, with ongoing requirements extending to gateway and intermediate carriers.
  • Signatures do not protect against spoofing via legacy networks or international calls, which usually arrive with C-level attestation or unsigned, risking unverified delivery.
  • Confirm your provider’s signing certificate ownership, FCC filing status, and ensure number ownership documentation to improve call authentication and reduce spam labels.

Table of Contents

What Is Stir Shaken? Definitions and the Standards Behind It

STIR/SHAKEN is not one thing. It is two acronyms stitched together, and the difference between them matters if you are ever troubleshooting a delivery problem with a carrier.

STIR stands for Secure Telephone Identity Revisited, a set of technical specifications published by the Internet Engineering Task Force. SHAKEN stands for Signature-based Handling of Asserted information using toKENs, and it is the implementation profile developed by ATIS and the SIP Forum that tells carriers exactly how to apply the STIR standard across real phone networks. Think of STIR as the blueprint and SHAKEN as the building code that turns that blueprint into something carriers can actually deploy consistently.

Both pieces exist because caller ID spoofing used to be trivial. A robocaller could punch in any number, including yours, and display it to thousands of people. STIR/SHAKEN closes that gap by attaching a digital signature to a call at the moment it originates, so the carrier on the receiving end can check whether the number is legitimate before the phone even rings.

That verification only works on IP-based call paths. Here’s the breakdown of who is involved and what governs each layer:

  • IETF publishes the underlying STIR protocol and the RFCs that define how signatures are structured and transmitted.
  • ATIS/SIP Forum publishes the SHAKEN implementation guidance that carriers actually build against.
  • STI-CAs (Secure Telephone Identity Certificate Authorities) issue the digital certificates carriers use to sign and verify calls.
  • The FCC mandates adoption and enforces compliance among U.S. voice providers.

If your business runs calls over a cloud-based phone system rather than a legacy copper line, this framework applies directly to your outbound traffic. Calls that never touch an IP network are a different story, and we will get to that gap later.

How Does Stir Shaken Verify a Call in Real Time?

Every signed call carries something called a PASSporT, a small signed token that rides along in the SIP Identity header. It is not much bigger than a shipping label, but it carries everything a receiving carrier needs to make a trust decision in milliseconds.

A PASSporT includes four core pieces of information: the attestation level, the originating phone number, the destination number, and a timestamp. That timestamp matters more than it sounds. It prevents someone from capturing a valid signature and replaying it later on a different call.

Here is roughly what happens between the moment you dial and the moment the other person’s phone rings:

  1. Your originating carrier receives the outbound call request and checks whether it can vouch for your right to use that number.
  2. The carrier generates a PASSporT, signs it with its private key, and attaches it to the SIP Identity header.
  3. The call routes across the network, carrying that signed token with it.
  4. The terminating carrier retrieves the originating carrier’s public certificate from an STI-CA repository.
  5. The terminating carrier verifies the signature against the certificate and checks the timestamp for freshness.
  6. Based on the result, the terminating carrier’s network (or the recipient’s phone) displays a verified badge, a neutral label, or nothing at all.

That entire exchange happens before the first ring. Public and private key pairs make it work: the originating carrier holds a private key it never shares, and the terminating carrier checks against a public certificate anyone can retrieve from an accredited STI-CA. It is the same asymmetric cryptography that secures web traffic over HTTPS, just applied to phone calls instead of browsers.

Pro Tip: If your provider can’t explain, in plain terms, whether they hold their own signing certificate or borrow one from an upstream carrier, that’s a signal worth pressing on before you commit to a contract.

Attestation Levels A, B, and C: What They Actually Mean for Your Calls

Not every signed call gets treated the same way, and this is the part most business owners never hear explained clearly. STIR/SHAKEN assigns one of three attestation levels to every call, and that letter grade follows the call all the way to the recipient’s screen.

  • A (Full Attestation): the carrier has a direct relationship with you, knows you own or are authorized to use the number, and vouches for the entire call.
  • B (Partial Attestation): the carrier knows who you are as a customer but cannot fully verify your right to the specific number displayed.
  • C (Gateway Attestation): the call entered the carrier’s network from an external source, often international or wholesale traffic, with no way to verify the origin at all.

Which level you get depends heavily on your setup. A business with a direct SIP trunking relationship or a dedicated business phone system tied to numbers it owns outright is far more likely to land A-level signatures. A business routed through a reseller, a wholesale aggregator, or a CPaaS platform that does not hold its own signing certificate often gets stuck at B, even if every call is legitimate and TCPA-compliant.

The downstream effect is real. Carriers and handset makers increasingly use attestation level to decide whether a call gets a “Verified Caller” badge, a neutral display, or a “Spam Likely” warning, and that decision happens before the recipient ever considers picking up. A-level attestation correlates directly with higher answer rates, which is exactly why it deserves attention from anyone running outbound sales, appointment reminders, or collections calls.

FCC Rules and the Compliance Timeline Your Providers Should Already Meet

The FCC mandated that voice service providers implement STIR/SHAKEN across the IP portions of their networks by June 30, 2021. That deadline was just the starting line. The FCC has since extended obligations to gateway providers, intermediate providers, and smaller carriers that initially qualified for extensions, closing loopholes that let unverified traffic slip through secondary networks.

The rules target three categories specifically:

  • Voice service providers that originate calls directly for customers like your business.
  • Gateway providers that hand off international or wholesale traffic into the U.S. network.
  • Intermediate providers that route calls between the originating and terminating carriers without directly serving either end customer.

Every one of these provider types must also file with the FCC’s Robocall Mitigation Database, a public registry that lists whether a provider has implemented STIR/SHAKEN or committed to an alternative robocall mitigation plan. If your provider doesn’t appear in that database, other carriers can legally block its traffic outright. Asking your provider for their RMD filing status is one of the fastest ways to confirm they take call authentication seriously.

Where Stir Shaken Falls Short: Non-IP Networks and Other Gaps

STIR/SHAKEN is not a complete fix, and pretending otherwise sets businesses up for confusion when a legitimate call still gets flagged. The framework has real, well-documented gaps.

  • Signatures don’t survive the trip across older TDM and SS7 network segments, so a call that starts IP and gets handed to a legacy network partway through often arrives unsigned, leaving the terminating carrier to fall back on other spam-scoring signals.
  • A bad actor working with a lax or willing provider can sometimes still obtain a valid signature, which is why the industry backs up STIR/SHAKEN with traceback investigations and certificate revocation for providers that sign fraudulent traffic.
  • International calls routed through gateway providers almost always arrive with C-level attestation, since the gateway has no way to verify the true originating party.
  • STIR/SHAKEN verifies that a number is authorized for use. It says nothing about consent, calling hours, or do-not-call status, so it does not replace TCPA compliance in any way.

How to Get A-Level Attestation and Protect Your Call Reputation

Getting A-level signatures is not automatic. It takes a few deliberate conversations with your provider and some ongoing monitoring on your end.

  1. Ask your provider directly whether they sign at A-level for your traffic, and whether that depends on your specific plan or number ownership documentation.
  2. Confirm who holds the SP-KI (signing certificate). If your provider doesn’t hold its own certificate and instead relies on an upstream carrier, you’re more likely capped at B-level regardless of how clean your calling practices are.
  3. Check the provider’s Robocall Mitigation Database filing to confirm they’re registered and in good standing with the FCC.
  4. Verify number ownership and porting documentation is current, especially after a number port, since mismatched records are a common cause of downgraded attestation.
  5. Ask what logs or reporting the provider can share on attestation levels and answer rates so you can track performance over time instead of guessing.
  6. If calls start getting flagged, request a traceback investigation through your provider, review your RMD status, and consider moving to a carrier that signs directly rather than through a reseller layer.

Direct SIP trunking arrangements tend to produce more consistent A-level results than reseller relationships, largely because the signing carrier has a clear, documented line of ownership over your numbers.

Pro Tip: A-level attestation solves the display and delivery problem, but it won’t shield you from TCPA complaints. Pair strong attestation with clean do-not-call list hygiene and documented consent records. That combination does more to protect your call reputation than either one alone.

Solid intermediary practices help too. A business answering service or shared reception line can unintentionally introduce attestation gaps if the provider behind it doesn’t sign at A-level, so it’s worth confirming that detail before routing high-volume outbound campaigns through a third party.

Talkroute’s Take on Call Authentication and Delivery

Businesses often assume caller ID trust is out of their hands. It isn’t. The setup you choose, direct number ownership, a provider with its own signing certificate, and clean call routing, determines whether your calls arrive as trusted or get buried under a spam label. Talkroute’s approach centers on giving businesses ownership of their numbers and transparent routing, because attestation quality starts with who actually controls the number, not just who dials it.

The most common mistake we see isn’t technical. It’s businesses choosing a cheap reseller arrangement without ever asking who signs their calls.

— Paul

Protect Your Call Delivery with Talkroute

If unverified caller ID is costing you answered calls, the fix usually isn’t more dialing, it’s better number ownership and cleaner routing. Talkroute gives your business direct control over local, toll-free, and vanity numbers, along with the call routing and reporting you need to spot delivery problems before they hurt your answer rates.

Talkroute

A few things worth doing this week: check with your current provider about your account’s attestation level, confirm their Robocall Mitigation Database status, and compare how your setup stacks up using Talkroute’s business phone system comparison checklist. If you’re running high call volumes for sales or outreach, a platform like Sdr paired with properly signed numbers can help maintain both volume and trust.

Ready to see what direct number ownership and transparent routing look like in practice? Explore Talkroute’s business phone systems and start a trial to check your own attestation setup today.

Sources

Stephanie

Stephanie is the Marketing Director at Talkroute and has been featured in Forbes, Inc, and Entrepreneur as a leading authority on business and telecommunications.

Stephanie is also the chief editor and contributing author for the Talkroute blog helping more than 200k entrepreneurs to start, run, and grow their businesses.

Stephanie6 Steps to A Level STIR/SHAKEN Attestation for U.S. SMBs