
What is a stir shaken certificate?
Key Facts
- Answer rates crash from roughly 40% to 5% the instant a call gets labeled "Spam Likely," according to industry data.
- An estimated 46 billion robocalls hit the US in 2020 alone, per industry tracking data.
- STIR/SHAKEN coverage at call termination fell to 40.4% in June 2025, down from a 49.3% peak in October 2024, TransNexus statistics show.
- Coverage recovered to 48.8% by June 2026 — the highest level in 20 months, recent tracking data reports.
- Attestation is a self-declaration by the originating provider, not independent verification, as TelcoBridges explains.
- 97.4% of calls authenticated by the top ten prolific robocall signers carried A-level attestation, TransNexus tracking found.
- FCC rules effective September 18, 2025 let providers outsource technical signing only if they control attestation decisions with their own certificate, per current compliance guidance.
Why Your Calls Get Flagged as Spam
Every legitimate business call now fights for attention in a phone system flooded by billions of robocalls — and the numbers tell a stark story. Before caller ID authentication existed, an estimated 46 billion robocalls hit the US in 2020 alone, following 5.7 billion in just October 2019, according to industry tracking data. That flood is exactly why carriers built aggressive spam defenses — and why your calls get caught in them.
The most important fact for any outbound caller: mobile-carrier spam-analytics engines treat attestation levels A, B, and C dramatically differently. Industry data shows that answer rates drop from approximately 40% to roughly 5% the moment a call gets labeled "Spam Likely." That is not a minor dip — it is the difference between a campaign that connects and one that burns budget on rings nobody answers.
Unsigned or C-attested calls are treated as very high spam probability and are often blocked outright, while B-attested calls face moderate and increasing flagging. Even when the actual call content is identical, a call signed at B-attestation starts from a worse position than an A-attested call, because the carrier lacks a verified relationship to the caller ID being displayed.
Here is how the attestation levels are treated:
- A-level attestation — the originating provider has authenticated the caller, has a direct relationship with them, and verified they are authorized to use the displayed number. Best chance of avoiding spam flags.
- B-level attestation — the provider knows the call origin but cannot fully verify the caller's right to the number. Moderate spam probability.
- C-level attestation or unsigned — the provider cannot verify the caller's relationship to the number. Treated as very high spam risk, often blocked.
One nuance matters: attestation is a self-declaration by the originating provider, not independent verification. As technical analysis explains, verification on the terminating side only confirms the signature is cryptographically valid and the certificate chain is trusted — no one checks whether the provider chose the right letter at the moment of signing.
The problem is getting worse before it gets better. TransNexus statistics show STIR/SHAKEN coverage at call termination fell to 40.4% in June 2025, down from a peak of 49.3% in October 2024, because authentication information gets lost when calls route over non-IP network segments. Coverage recovered to 48.8% by June 2026 — still short of what full call authentication requires.
This is why list discipline and proper call signing go hand in hand. My AI Call Center runs structured campaigns only against approved, permissioned, or reviewed lists, and A-level attestation on properly signed traffic is what keeps those calls from being lumped in with the robocall flood. A permissioned list means nothing if the carrier's analytics engine never lets the phone ring.
How STIR/SHAKEN Certificates Authenticate Caller ID
Every time your phone rings and shows a name you trust, there's a quiet cryptographic handshake happening behind the scenes deciding whether that number is real. STIR/SHAKEN is the industry framework making that possible, and digital certificates are its foundation.
Originating service providers obtain digital certificates from a trusted Certificate Authority — specifically an STI-CA — before they can sign outbound calls. As a TransNexus whitepaper explains, STIR/SHAKEN uses digital certificates based on common public key cryptography to secure the calling number of a telephone call. To get a certificate, the provider first obtains an SPC token from the Policy Administrator and presents it to a Certificate Authority, a process outlined in current FCC compliance guidance.
When a call is placed, the originating provider signs key identity information into a PASSporT token using the private key tied to its certificate. The terminating provider on the receiving end then verifies that the signature is cryptographically valid and that the certificate chain traces back to a trusted authority. This is what allows the called party's network to confirm the calling number is accurate and has not been spoofed.
The PASSporT also carries an attestation claim — a single character, A, B, or C — naming the provider's confidence in the caller's right to use that number. As TelcoBridges notes, A-level applies only when the provider has authenticated the calling party, has a direct relationship with them, and has verified they are authorized to use the displayed number. It is a self-declaration, not independent verification — downstream networks confirm only the signature's validity and the trusted certificate chain.
The stakes are real. Industry data shows answer rates drop from roughly 40% to 5% when a call is labeled "Spam Likely," and carrier spam analytics treat A, B, and C attestation dramatically differently. Meanwhile, recent tracking data shows SHAKEN-authorized providers reached an all-time high, with coverage at termination climbing to 48.8% in June 2026.
For managed outbound calling operations like My AI Call Center, this framework matters on every campaign — appointment reminders, renewal calls, and lead follow-ups only work if the call gets answered. That's why properly signed calls with full attestation, run against approved, permissioned, or reviewed contact lists, are the baseline for legitimate outbound programs.
The practical checklist for any outbound caller:
- Obtain a dedicated STI-CA-issued certificate tied to your own numbers, not pooled across unrelated tenants
- Control attestation-level decisions internally, even when using third-party technical signing
- Verify that A-level attestation is achievable — it requires a direct, authenticated relationship with the calling party
- Monitor whether non-IP network segments in the call path are stripping authentication information before termination
Caller ID trust is no longer optional — unsigned or incorrectly signed calls face lower answer rates, spam labeling, and business-level risk in the interconnect chain.
Attestation Levels A, B, C — What They Mean for Deliverability
Every signed call carries a single letter — A, B, or C — and that one character inside the PASSporT claim largely determines whether your call rings through or lands in spam territory. Understanding these attestation levels matters more than almost any other part of STIR/SHAKEN for outbound calling performance.
Here is the critical nuance: attestation is a self-declaration by the originating provider, not an independent verification. As TelcoBridges explains, when a provider signs an outbound call, it chooses the letter that goes into the attest claim, and no one verifies that choice at the moment of signing. Downstream verification only confirms the signature is cryptographically valid and the certificate chain is trusted.
The three levels break down as follows:
- Full Attestation (A) — the provider has authenticated the calling party, has a direct relationship with them, and has verified they are authorized to use the displayed caller ID. All three conditions must hold.
- Partial Attestation (B) — the provider has a relationship with the caller but cannot verify the caller is authorized to use the number shown.
- Gateway Attestation (C) — the provider can verify the call's origin but cannot verify the caller's identity or their authorization to use the number.
The deliverability consequences are dramatic. According to industry data on spam labeling, mobile-carrier spam-analytics engines treat A, B, and C attestation very differently: A-attestation provides the best chance of avoiding spam flags, while unsigned or C-attested calls are treated as very high spam probability and often blocked outright. B-attested calls face moderate spam probability and increasing flagging — even when the actual call content is identical to an A-attested call.
The stakes are real. The same research shows answer rates drop from approximately 40% to roughly 5% once a call is labeled "Spam Likely." A campaign that would have connected with four in ten contacts suddenly reaches almost no one.
Attestation data also reveals who signs what. TransNexus tracking found that in June 2026, 30.8% of calls arrived signed with A-level attestation, against 4.4% at B and 7.8% at C. Notably, 97.4% of calls authenticated by the top ten prolific robocall signers carried A-level attestation — a reminder that attestation alone is one input among many, since analytics engines also weigh calling patterns, reputation history, and number-block age.
This is why providers like My AI Call Center treat attestation as a deliverability prerequisite for structured outbound campaigns, not a paperwork detail. Because its campaigns run only against approved, permissioned, or reviewed lists, the calling numbers it presents genuinely belong to the campaign owner — the honest foundation A-level attestation requires. For any organization running outbound calling, the practical takeaway is simple: ask your provider who signs your calls, at what level, and why.
Current Coverage Gaps and Regulatory Requirements
Despite growing provider participation, STIR/SHAKEN coverage at call termination declined to 40.4% in June 2025, down 1.9% from May and continuing a downward trend since peaking at 49.3% in October 2024. This decline stems from non-IP network segments in service provider voice networks stripping authentication information during call routing, even as the number of SHAKEN-authorized providers reached an all-time high of 1,606. By June 2026, coverage improved to 48.8%—the highest level in 20 months—though still below the threshold needed for full call authentication benefits.
Regulatory requirements continue to evolve, with the FCC and CRTC mandating STIR/SHAKEN implementation by mid-2021 and November 2021, respectively. A significant change effective September 18, 2025, permits providers to use third parties for technical signing of calls, but only if the obligated provider controls attestation-level decisions and signs calls using its own certificate—not the third party's. Additionally, annual Robocall Mitigation Database (RMD) recertification requirements take effect February 5, 2026, with a recertification window opening February 1, 2026 and a deadline of March 1, 2026 (annually), carrying penalties of $10,000 for false or inaccurate information and $1,000 for failure to update within 10 business days.
For My AI Call Center, maintaining compliant outbound calling operations requires navigating these coverage gaps and regulatory shifts while ensuring calls retain authentication integrity through IP-based routing or equivalent non-IP call authentication methods. Preserving A-level attestation remains critical, as industry data shows answer rates drop from approximately 40% to 5% when calls are labeled "Spam Likely" due to missing or low-attestation signatures. Addressing these challenges supports deliverability for permissioned campaigns across healthcare, franchises, recruiting, and other multi-location organizations relying on verified caller ID to reach contacts effectively.
- Ensure A-level attestation for all outbound calls through dedicated STI-CA-issued certificates
- Maintain internal control over attestation decisions even when using third-party signing services
- Prepare for annual RMD recertification starting February 2026 to avoid financial penalties
How My AI Call Center Uses STIR/SHAKEN for Compliant Campaigns
A certificate only matters if the calls behind it are legitimate. That is the principle that shapes how My AI Call Center approaches STIR/SHAKEN — the certificate is not a workaround for bad calling practices, it is the final layer on top of strict list discipline and consent review.
The starting point is the list itself. Every campaign runs against approved, permissioned, or reviewed contact lists only, with list source and consent records checked before anything launches. Bought lists without clear permission records are flagged and, in most cases, declined. This matters because attestation under STIR/SHAKEN is a self-declaration by the originating provider — no one verifies the choice at the moment of signing. A-level attestation claims only hold up if the underlying authorization to call is real.
That discipline connects directly to the attestation framework. A-level attestation applies when the provider has authenticated the calling party, has a direct relationship with that party, and has verified the party is authorized to use the displayed number — all three conditions must be true. The stakes are high: answer rates drop from approximately 40% to 5% when a call is labeled "Spam Likely," according to industry data on flagged calls. Calls signed with lower attestation start from a worse position even when the content is identical.
The FCC's September 18, 2025 rule change reinforced this structure, allowing providers to use third parties for technical signing only if the obligated provider controls attestation-level decisions and signs with its own certificate. Attestation decisions are handled internally, per FCC rules, rather than delegated away.
Compliance also extends to what happens on the call itself:
- AI disclosure on every call — recipients can ask if the call is AI-assisted, request a human, or opt out
- Keyword opt-outs STOP and REVOKE, logged and honored immediately
- DNC requests respected across all campaigns and carried into client DNC records
- Outcomes routed back with disposition codes, so consent status follows every contact
This matters because attestation is not a spam score. Analytics engines combine it with calling patterns, reputation history, and dozens of other signals, as TelcoBridges explains. Clean attestation paired with disciplined calling behavior — approved windows, opt-out handling, structured campaigns with one clear goal — is what keeps deliverability strong over time. Coverage at termination reached 48.8% in June 2026, the highest level in 20 months, which means the calls that arrive properly signed stand out even more.
If you are planning outbound campaigns against permissioned lists, managed campaigns start at 9¢ per connected minute, with the full campaign quoted before launch. The first campaign review is free — and it will tell you plainly whether your list will support the campaign before you spend anything.
Frequently Asked Questions
What exactly is a STIR/SHAKEN certificate and why does my business need one?
How do attestation levels A, B, and C affect whether my calls get marked as spam?
Can I use a third party to sign my calls with STIR/SHAKEN and still control the attestation level?
Why is STIR/SHAKEN coverage at call termination declining despite more providers participating?
What are the penalties for failing to comply with annual Robocall Mitigation Database (RMD) recertification requirements?
Does having an A-level attestation guarantee my calls won't be labeled as spam?
The Certificate Is the Floor, Not the Ceiling
STIR/SHAKEN certificates and attestation levels form the technical backbone of caller ID trust — but they are not a substitute for legitimate calling practices. The framework ensures originating providers cryptographically sign calls using certificates from trusted authorities, with A, B, or C attestation signaling the provider's confidence in the caller's right to use the displayed number. That single letter carries outsized weight: mobile carrier spam analytics treat A-attested calls far more favorably, while unsigned or C-attested traffic faces blocking and answer rates that plummet from roughly 40% to 5% when labeled "Spam Likely." Coverage at termination reached 48.8% in June 2026, the highest level in 20 months, yet non-IP network segments still strip authentication from nearly half of all calls. The FCC's September 2025 rule change reinforces that providers must control attestation decisions and sign with their own certificates, even when using third-party signing. For My AI Call Center, that means every campaign runs on approved, permissioned, or reviewed lists first — because A-level attestation only holds up when the underlying authorization to call is real. If you are planning outbound campaigns against permissioned lists, the first campaign review is free and will tell you plainly whether your list will support the campaign before you spend anything.