CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
Data Privacy Standards

What is STIR/SHAKEN caller ID and how does it work?

Back to InsightsWhat is STIR/SHAKEN caller ID and how does it work?

What is STIR/SHAKEN caller ID and how does it work?

Key Facts

  • Among the top 10 prolific robocall signers, 91.7% of their signed calls used A-level attestation, yet 59.6% of those A-level calls were still identified as robocalls according to September 2024 data.
  • In February 2025, B-level robocalls among top signers increased by 47.7% month-over-month, signaling bad actors are shifting tactics to exploit lower attestation levels per industry monitoring.
  • Only 42.8% of calls arrived at termination with SHAKEN signatures intact in February 2025, down from 49.3% in September 2024, as non-IP call path segments strip authentication data according to TransNexus analytics.
  • A-level attestation represented just 28.0% of signed calls in February 2025, while C-level dropped to 8.3%, showing declining coverage despite more providers signing calls per February 2025 statistics.
  • U.S. subscribers received approximately 38 billion robocalls in 2024, fueling consumer distrust that causes legitimate calls to be ignored or blocked according to the YouMail Robocall Index.
  • The number of Originating Service Providers signing calls increased by 2.6% in February 2025, yet fewer signed calls reach termination due to fragmented call paths per TransNexus monitoring data.
  • STIR/SHAKEN uses PASSporT JWT tokens in SIP headers following IETF RFCs 8224, 8225, 8226, and 8588 to cryptographically verify caller identity across networks per the technical standards.

The Caller ID Trust Problem: Why Your Legitimate Calls Get Ignored

For decades, anyone with basic VoIP access could claim to be calling from any number, turning caller ID into a tool of deception rather than trust. Scammers exploited this relentlessly, making robocall campaigns, phishing attempts, and fraud dependent on spoofing to bypass skepticism. As a result, legitimate outbound callers now face an uphill battle: even when using verified numbers and permissioned lists, their calls are often ignored or blocked because recipients have been conditioned to distrust unsolicited contact.

This erosion of trust has real consequences. In 2024 alone, U.S. subscribers received approximately 38 billion robocalls, flooding phone lines and conditioning consumers to screen or reject unfamiliar numbers. Legitimate businesses — from healthcare clinics confirming appointments to franchises following up on leads — pay the price in lower answer rates, increased call blocking, and diminished engagement. When consumers can no longer rely on caller ID to distinguish a genuine reminder from a scam, even well-intentioned outreach gets caught in the crossfire.

The problem is compounded by how easily spoofing undermines traditional call-blocking efforts. For years, spoofers could rotate numbers or mimic local area codes to appear familiar, defeating simple blacklists and encouraging answer rates through false familiarity. STIR/SHAKEN was designed to break this cycle by replacing blind trust with cryptographic verification, but its effectiveness depends on end-to-end implementation. As long as call paths include non-IP segments that strip authentication data, or bad actors exploit lower attestation levels to mimic legitimacy, the trust gap persists — and legitimate callers continue to lose ground.

  • Among the top 10 prolific robocall signers, 91.7% of their signed calls used A-level attestation
  • Yet 59.6% of those A-level signed calls were still identified as robocalls
  • In February 2025, B-level robocalls among this group increased by 47.7%
These patterns show that while authentication technology exists, its integrity is under constant pressure — making it harder for compliant services like My AI Call Center to ensure their permissioned outreach reaches the people who expect it. Without reliable caller ID authentication, even the most carefully managed campaigns risk being drowned out by noise, forcing businesses to work harder just to be heard.

How STIR/SHAKEN Works: Signatures, Tokens, and Attestation Levels

How STIR/SHAKEN Works: Signatures, Tokens, and Attestation Levels

STIR/SHAKEN operates through a three-stage process: call origination and certification, call verification, and call blocking or tagging based on attestation levels. During origination, the originating service provider signs the call using a digital certificate and generates a PASSporT JWT, which is embedded in the SIP header as an Identity field. This token contains the calling number, called number, timestamp, and attestation level, cryptographically signed with the provider’s private key. The verification stage occurs when the terminating carrier validates the signature against the originating carrier’s public certificate, confirming whether the caller ID has been spoofed. Finally, based on the attestation level and verification result, the call is either allowed to proceed, tagged as potential spam, or blocked entirely.

The PASSporT JWT follows IETF RFC standards, specifically RFC 8224, RFC 8225, RFC 8226, and RFC 8588, which define how STIR information is structured and transmitted across SIP networks. Attestation levels indicate the degree of confidence the originating provider has in the right to use the calling number: A (Full) attestation means the provider has authenticated the customer and verified their right to use the number; B (Partial) means the customer is authenticated but the number’s authorization cannot be verified; C (Gateway) means the call originates from a gateway where the provider authenticates the source but cannot verify the customer or number authorization. These levels directly influence how terminating carriers treat the call, with A-level calls most likely to be delivered without labeling.

Current data shows that only 42.8% of calls were signed at termination in February 2025, down from 49.3% in September 2024, highlighting ongoing challenges with non-IP call path segments stripping SHAKEN information. Among signed calls, A-level attestation accounted for 28.0% in February 2025, while B-level and C-level represented 3.8% and 8.3%, respectively. Notably, among the top 10 prolific robocall signers, 91.7% of their signed calls used A-level attestation, yet 59.6% of those A-level calls were still identified as robocalls, demonstrating that high attestation does not guarantee legitimacy. For businesses using managed calling services like My AI Call Center, maintaining A-level attestation through proper list verification and SIP interconnection is critical to ensuring calls are trusted and answered.

  • Monitor attestation level trends to detect shifts in robocaller behavior
  • Ensure end-to-end IP connectivity to preserve SHAKEN information
  • Verify voice service providers support SIP interconnections throughout the call path
Organizations should prioritize working with providers that maintain full SIP interconnection to maximize authentication coverage and avoid call delivery issues stemming from fragmented call paths.

What the Data Says: Adoption Is Up, but Bad Actors Are Adapting

STIR/SHAKEN adoption is growing, but the numbers tell a more complicated story than "authentication is working." Roughly 42.8% to 49.3% of calls are signed at termination, depending on the month measured, which means nearly half of all calls still arrive without any authentication data attached. More providers are signing calls, yet fewer signed calls actually make it through intact.

The gap comes down to call paths. When a call routes across non-IP network segments, SHAKEN information gets stripped out along the way, according to February 2025 industry data. This problem persists until those segments are upgraded to SIP interconnections or transit providers adopt solutions like Out-of-Band SHAKEN. For legitimate callers, that means even a properly signed call can still land with no verification for the recipient to see.

Attestation levels show similar volatility. A-level attestation, the strongest form of verification, applied to 28.0% of signed calls in February 2025, down from 29.3% the month before, per the same reporting. B-level attestation held at 3.8%, while C-level dropped to 8.3%. The direction of these numbers matters less than what bad actors are doing with them.

That is the troubling part. Among the top 10 prolific robocall signers, A-level attestation was used for 91.7% of their signed calls, according to September 2024 statistics. Worse, 59.6% of those A-level calls were still identified as robocalls. High attestation is no longer a reliable signal of legitimacy.

The tactics are shifting, too. In February 2025, robocalls signed with B-level attestation among this group jumped 47.7% month-over-month, while these signers shifted more of their call volume toward B-level attribution overall. The pattern suggests illegal callers are deliberately manipulating authentication signals to make unwanted calls look more trustworthy. For businesses running outbound campaigns, this erodes the value of attestation as a differentiator and puts pressure on answer rates for everyone.

So what should a legitimate caller take from this? A few practical points:

  • Signed calls can still lose their authentication data in transit, so a verified origin does not guarantee a verified arrival.
  • Scammers increasingly exploit lower attestation levels, which means carriers and recipients must treat attestation as one signal among several, not a stamp of approval.
  • Roughly 38 billion robocalls reached U.S. subscribers in 2024, so even strong authentication frameworks face enormous volume pressure.
  • Compliance discipline matters as much as technology — who you call, and whether you have permission, determines outcomes more than a token in a SIP header.

This is why list discipline sits at the center of how we work at My AI Call Center. Campaigns run only against approved, permissioned, or reviewed contact lists, with consent records checked before anything launches. Authentication frameworks like STIR/SHAKEN verify identity, but they cannot verify intent — that responsibility stays with the caller.

What This Means for Your Outbound Campaigns: Compliance and Answer Rates

When your outbound campaign calls hit the recipient's phone, STIR/SHAKEN verification determines whether they see a trusted label or a spam warning—directly impacting answer rates. The TRACED Act and FCC/CRTC mandates require voice providers to implement this caller ID authentication framework, making attestation levels a critical factor in deliverability. Calls with full A-level attestation indicate the carrier has verified your right to use the number, while B or C levels suggest partial or gateway-only verification, increasing the likelihood of flagging.

End-to-end IP connectivity is essential for preserving SHAKEN information throughout the call path; non-IP segments strip authentication data, causing signed calls to lose verification by termination. Research shows only 42.8-49.3% of calls remain signed at termination, with A-level attestation representing just 28.0-32.3% of those signed calls. Even among prolific robocall signers who use A-level for 91.7% of their signed calls, 59.6% of those A-level calls are still identified as robocalls, highlighting that attestation alone doesn't guarantee legitimacy—it must be paired with clean list practices.

  • Monitor attestation trends: B-level robocalls among top signers increased 47.7% in February 2025, signaling evolving spoofing tactics.
  • Verify SIP interconnections: Declining coverage despite rising participation indicates non-IP path segments are stripping SHAKEN data.
  • Maintain list discipline: Only use approved, permissioned, or reviewed lists with verifiable consent records to complement STIR/SHAKEN authentication.

For managed services like My AI Call Center, combining STIR/SHAKEN compliance with rigorous list hygiene—checking consent records and call windows before launch—helps ensure legitimate campaigns avoid spam flags and maintain connection rates. This approach aligns with the TRACED Act’s goal of restoring trust in caller ID while protecting businesses that follow proper outreach protocols.

Practical Steps: Making Sure Your Calls Verify and Connect

Knowing the framework is one thing; making sure your calls actually verify and connect is where most organizations stumble. The gap matters: recent monitoring data shows only 42.8% of calls arrive at termination with their SHAKEN signature intact, even as more providers sign calls than ever.

The culprit is usually the call path itself. When a call crosses a non-IP segment, the SHAKEN information gets stripped — meaning your provider may sign correctly at origination, but the terminating carrier never sees it. Industry analysis suggests this problem persists until those segments are replaced with SIP interconnections or transit providers adopt Out-of-Band SHAKEN. So your first question to any provider should be direct: do you maintain SIP interconnections across the entire call path?

Second, ask about attestation levels and Rich Call Data. You want Full (A-level) attestation whenever possible, because prolific robocall signers increased their B-level calls by 47.7% in one month, and carriers are responding by treating lower attestation levels with more suspicion. Rich Call Data embedded in the SHAKEN token can display your verified business name and reason for calling, which improves answer rates.

Here is a practical checklist to run before your next campaign:

  • Confirm your provider maintains SIP interconnections end-to-end, so signatures survive the full call path.
  • Ask what attestation level your calls receive, and request Rich Call Data support for verified caller display.
  • Monitor call completion rates monthly — a sudden drop can signal your calls are being tagged or filtered.
  • Track FCC deadlines, including the March 1, 2026 annual recertification of Robocall Mitigation Database filings.
  • Run campaigns only against permissioned lists with documented consent records.

The last point deserves emphasis. Authentication technology verifies who you are; it does not make unwanted calls welcome. List quality and caller ID verification work together — a perfectly signed call to a contact who never consented still risks complaints, blocks, and reputational damage. U.S. subscribers received roughly 38 billion robocalls in 2024, which means carriers and consumers are primed to distrust anything that feels indiscriminate.

This is why My AI Call Center reviews list source and consent records before any campaign launches, flagging or declining lists without clear permission records. Verification and permission are checked before the first call goes out, not after problems surface. The result is calls that both authenticate properly and land with people who actually agreed to hear from you — the combination that keeps completion rates healthy and your caller ID reputation clean.

Frequently Asked Questions

What is STIR/SHAKEN and how does it verify caller ID?
STIR/SHAKEN is a cryptographic framework that verifies caller ID by adding a digitally signed PASSporT JWT to the SIP header, which contains the calling number, called number, timestamp, and attestation level, and is validated by the terminating carrier using the originating carrier’s public certificate.
Why do legitimate calls still get blocked or ignored even with STIR/SHAKEN in place?
Legitimate calls can still be blocked or ignored because non-IP call path segments strip SHAKEN information, and scammers increasingly exploit lower attestation levels—like B-level—to make robocalls appear more trustworthy, with 59.6% of A-level signed calls from top robocall signers still identified as robocalls.
What do the attestation levels (A, B, C) mean in STIR/SHAKEN?
Attestation levels indicate the originating provider’s confidence in the caller’s right to use the number: A-level means the provider authenticated the customer and verified number authorization; B-level means the customer is authenticated but number authorization cannot be verified; C-level means the call comes from a gateway where the provider authenticates the source but not the customer or number.
How many calls are actually signed with STIR/SHAKEN at termination, and is this improving?
Only 42.8% of calls were signed at termination in February 2025, down from 49.3% in September 2024, showing declining end-to-end coverage despite more providers signing calls, due to non-IP segments stripping authentication data.
Can STIR/SHAKEN stop robocalls on its own, or do I need additional measures?
STIR/SHAKEN alone cannot stop robocalls, as it verifies identity but not intent—scammers exploit the system using high attestation levels, so businesses must pair it with list discipline, such as using only permissioned lists with verified consent, to maintain trust and answer rates.
What practical steps should I take to ensure my outbound calls verify and connect successfully?
To ensure calls verify and connect, confirm your provider maintains SIP interconnections end-to-end, request A-level attestation and Rich Call Data support, monitor completion rates for drops, track FCC deadlines like the March 1, 2026 Robocall Mitigation Database recertification, and run campaigns only against permissioned lists with documented consent.

Why Trusted Calling Starts With You

STIR/SHAKEN has reshaped caller ID from a tool of deception into a foundation of trust—but only when paired with disciplined practices. As we’ve seen, even properly signed calls can lose verification in transit, and high attestation levels alone don’t stop bad actors from exploiting the system. For legitimate businesses, the real advantage comes not just from technology, but from combining caller ID authentication with rigorous list hygiene: using only permissioned contacts, verifying consent, and maintaining end-to-end SIP connections to preserve signal integrity. This dual approach ensures your calls aren’t just verified—they’re welcomed. At My AI Call Center, we build every campaign around this principle, checking list quality and compliance before a single call is made so your outreach reaches people who expect to hear from you. If you’re ready to run more useful calls without expanding your team, explore our managed calling campaigns and see how permission-based outreach can restore answer rates and protect your reputation.

Get campaign planning tips