STIR/SHAKEN Caller ID Authentication

STIR/SHAKEN is the caller ID authentication standard that US and Canadian carriers use to confirm a call is really coming from the number it claims.

CloudTalk signs every outbound call with the right attestation level automatically, so your calls arrive verified instead of arriving as "Spam Likely." Nothing to configure, and no separate provider to sign up with.

Our price: Included in all plans starting at $25

SOC2 Compliant
ISO 27001

Trusted by 30,000+ sales & support professionals to power more & better conversations

STIR/SHAKEN: Everything You Need to Know

What the standard is, how attestation works, who enforces it, and why compliant calls still get flagged as spam.

STIR/SHAKEN is the caller ID authentication framework that voice providers in the United States and Canada use to confirm a call is genuinely coming from the number displayed. The originating provider attaches a cryptographic signature to each outbound call, and the receiving provider verifies that signature before the phone rings.

One thing worth being precise about: STIR/SHAKEN does not block spoofing. It makes spoofing detectable. The framework produces a verdict about whether a call's caller ID can be trusted, and each carrier decides what to do with that verdict, whether that means passing the call through, labeling it, or filtering it entirely. It also only operates across the IP portions of a network, so a call that crosses legacy TDM infrastructure can lose its signature along the way.

STIR stands for Secure Telephone Identity Revisited. It is the set of IETF standards that define how a digital signature is created and attached to a call.

SHAKEN stands for Signature-based Handling of Asserted information using toKENs. It is the ATIS specification that tells carriers how to actually deploy STIR across their networks.

The short version: STIR is the standard, SHAKEN is the deployment framework built around it. In practice the two are always referenced together, which is why the STIR/SHAKEN protocol is usually treated as a single thing.

Three steps, all of them finished before the recipient's phone rings.

Authentication. Your provider checks who is placing the call and whether they have the right to use the number on the caller ID. Signing. The provider adds a signed SIP Identity header to the call, carrying its certificate and an attestation level describing how confident it is. Verification. The terminating provider validates that signature against the originating provider's certificate and passes the result to its own spam analytics.

What the recipient actually sees at the end of that chain is up to their carrier. STIR/SHAKEN supplies the evidence; the carrier's analytics engine makes the call.

Every signature carries an attestation level saying how much the originating provider actually knows about the call. There are three.

Full attestation (A): the provider knows the customer and has confirmed they are entitled to use the number. This is the level most likely to reach the recipient unlabeled. Partial attestation (B): the provider knows the customer but has not verified their right to that specific number, which is common when a business brings its own numbers. Gateway attestation (C): the provider is only passing the call along and cannot vouch for its origin at all, which is typical for international traffic entering the US network.

Carrier analytics weight these heavily. A calls generally sail through, C calls attract scrutiny. If your outbound answer rates are poor and you cannot work out why, your attestation level is one of the first things worth checking with your provider.

In the United States, yes. Under the TRACED Act, the FCC adopted rules in 2020 requiring voice providers to implement STIR/SHAKEN across the IP portions of their networks by June 30, 2021. Small providers with 100,000 or fewer subscriber lines were granted an extension to June 30, 2023, later shortened to 2022 for a subset originating high call volumes. The obligation has since been extended to gateway and intermediate providers as well.

Providers also file certifications in the FCC's Robocall Mitigation Database, and since September 2021 carriers have been barred from accepting traffic directly from providers that are not listed in it. Canada operates a parallel requirement through the CRTC.

Worth knowing if you are the one making the calls rather than carrying them: STIR/SHAKEN compliance is an obligation on your voice provider, not on your business. You do not file anything. But your provider's implementation directly determines how your calls are treated, which makes it a fair question to ask any vendor you are evaluating.

Not directly, and this is the most common misunderstanding about it. STIR/SHAKEN authenticates caller ID. It makes no judgment about what a call is for. A perfectly legal robocall with full attestation passes through untouched, and a scammer can still place a spoofed call. The call just arrives carrying an honest label saying nobody can vouch for it.

What the framework does is remove anonymity from the network. Because every signed call can be traced back to the provider that originated it, regulators and carriers can identify repeat offenders instead of chasing untraceable traffic, and carriers get a reliable signal to filter on. Fighting STIR/SHAKEN robocalls is a byproduct of that traceability rather than the mechanism itself.

Because attestation is one input among many. Carrier analytics engines also weigh how many calls a number places per day, how long those calls last, how often they are answered, how many recipients have reported the number, how recently it was activated, and whether it appears in the analytics providers' registries.

A brand new number dialing three hundred times a day with an average duration of four seconds looks exactly like a robocaller, and full attestation will not save it. That is a dialing behavior problem, not a signing problem.

The things that actually move the needle: register your numbers with the analytics providers, spread volume across enough numbers that no single one looks frantic, keep an eye on your average call duration, and add Branded Caller ID so recipients see who is calling rather than an unfamiliar string of digits.

STIR/SHAKEN is verification. It runs between carriers, the recipient never sees it, and its job is to tell the receiving network that your call is what it claims to be.

Branded Caller ID is display. It puts your company name, and on supported handsets your logo and a reason for calling, on the recipient's screen. Its job is to give a human a reason to pick up.

They solve adjacent halves of the same problem and work best together: signing gets your call past the filter, branding gets it answered. Signing is included in your CloudTalk plan. Branded Caller ID is a paid add-on billed per outbound call.

No. STIR/SHAKEN is a North American framework, mandated by the FCC in the US and the CRTC in Canada. Other countries are pursuing their own approaches to caller ID authentication, and many have none at all yet.

This matters more than it sounds if you sell into the US from elsewhere. Calls originating outside North America typically enter the US network through a gateway provider, which means gateway attestation (C), which means a higher chance of being labeled before anyone picks up. Using a local US number from a provider that signs your traffic at origin avoids that path entirely.

Signing happens automatically on outbound calls to US destinations. There is no setting to enable, no certificate to manage, and no separate authentication vendor to contract with. STIR/SHAKEN implementation is handled on the carrier side of the platform, which is where the regulatory obligation actually sits.

Around it sits the rest of the deliverability toolkit: anti-spam number registration, spam remediation for numbers that have picked up a bad reputation, Branded Caller ID for display, and local numbers in 160+ countries so your calls originate close to the people receiving them. Delivery is rarely fixed by one lever, and signing is the one that has to be in place before the others matter.

Build Credibility and Keep Fraud
Out of Your Calls

Earn Trust Before You Even Speak

Verified calls feel safer. With STIR/SHAKEN in place, your business calls show up as legitimate, making customers far more likely to pick up and engage.

Block Spoofing and Phone Scams

Stop fraudsters from using your number. STIR/SHAKEN technology authenticate your caller ID, protecting your brand image and safeguarding customers from fake calls.

Get More Calls Answered

More verified calls = more answered calls. By avoiding spam labels and blocked numbers, you increase connection rates and get through to the people that matter.

STIR/SHAKEN

What Is STIR/SHAKEN Caller ID Verification?

STIR/SHAKEN is the caller ID authentication standard US and Canadian carriers use to check that a call is really coming from the number on the display.

Your provider attaches a digital signature to each outbound call attesting to your right to use that number, and the receiving carrier verifies it before the phone rings. It doesn't block spoofing. It makes spoofed calls identifiable, which is what lets carriers filter them.

CloudTalk signs every outbound call automatically, using your verified outbound caller ID. No separate provider, no setup.

How Does STIR/SHAKEN Protocol Work?

Every time you place a call, CloudTalk’s STIR/SHAKEN verification app digitally signs your outbound caller ID using an encrypted certificate. The recipient’s carrier then verifies this signature, confirming the call’s authenticity and ensuring it hasn’t been spoofed.

Legitimate, verified calls get delivered smoothly, while spoofed or unverified numbers are filtered out—protecting customers and strengthening your outreach.

Where Can You Use a STIR/SHAKEN App?

  1. 01
    Outbound Business Calls: Ensure your outbound sales, service, and notification calls aren’t flagged as spam. Verified numbers improve pick-up rates and customer trust.
  2. 02
    Call Centers: Verify your identity on every call, giving customers confidence they’re speaking with a legitimate call center business. Reduce manual ID checks and streamline call handling.
  3. 03
    VoIP and Telecom Providers: Protect your network from spoofed calls. STIR/SHAKEN verification secures outbound traffic, reduces fraud, and improves service quality.
  4. 04
    High-Risk Industries: Guarantee sensitive, urgent calls get through without being blocked in healthcare and finance industries. Verified numbers help protect private information and ensure critical updates are delivered securely and reliably.

How to Activate CloudTalk’s STIR/SHAKEN App

  1. 01
    Log in to your CloudTalk dashboard.
  2. 02
    Go to the Numbers tab and select the number you want to verify.
  3. 03
    Check that your outbound caller ID details are accurate.
  4. 04
    CloudTalk automatically applies STIR/SHAKEN verification to your calls.
  5. 05
    Review your call logs regularly to ensure smooth, verified delivery.

Benefits of STIR/SHAKEN App

Protect Your Brand and Drive More Conversions with STIR/SHAKEN

Boost Call Center Efficiency

With verified calls, agents spend less time on identity verification and can focus on solving customer issues faster. This improves service speed, reduces handling times, and enhances the customer experience.

Stay Compliant and Future-Proof

CloudTalk’s STIR/SHAKEN app keeps your business aligned with the latest telecom regulations, helping you avoid penalties and ensuring your operations remain secure and reliable as standards evolve.

Enhance Brand Reputation

By preventing scammers from spoofing your business numbers, you protect your brand from reputational damage linked to fraudulent calls. Verified, authenticated calls show customers you take security seriously.

Increase Revenue Generation

A higher pick-up rate means more conversations, more conversions, and fewer lost opportunities. By protecting your brand’s reputation and offering verified, trusted calls, you retain loyal customers and attract new business.

Features

Other features you might like

Spam Protection

Block known spam numbers manually or automatically for both inbound and outbound calls, and streamline calling.

Learn more about Spam Protection

Contact Tags

Easily categorize customer interactions with contact center tags. Deliver efficiency and personalized service.

Learn more about Contact Tags

Call Tagging

Use custom or pre-existing call tags to track different types of interactions, goals, outcomes, and many other metrics.

Learn more about Call Tagging

Single Sign-On (SSO)

Speed up, simplify, and secure the sign-in process for your entire team with Single Sign-On (SSO).

Learn more about Single Sign-On (SSO)

Ready to get started with STIR/SHAKEN

Join over 5,500+ modern companies that already trust CloudTalk to have MORE and BETTER calls.

STIR/SHAKEN FAQs

You do not buy STIR/SHAKEN separately. Your voice provider implements it on your behalf, which means the practical step is choosing a business calling platform that signs outbound traffic. CloudTalk does this automatically, with nothing to configure.

Carriers can block them, once they know which calls are spoofed. That is what STIR/SHAKEN provides: authentication of your caller ID so receiving networks can tell a verified call from an unverified one. CloudTalk signs your outbound calls so they land on the right side of that line.

It makes caller ID verifiable, so carriers can separate legitimate business calls from spoofed ones and robocalls. For businesses, the benefit runs the other way too: signed calls are far less likely to be mislabeled on the way to a real customer.

Anything that relies on faking a number: neighbor spoofing, bank and government impersonation, and phishing calls that borrow a trusted caller ID. STIR/SHAKEN does not judge what a call is about, so it flags the forged identity rather than the scam itself.

By digitally signing each call at origin and validating that signature at the other end. A spoofed call cannot produce a valid signature, so it arrives unverified and carriers can label or block it accordingly.

No. Signing and verification happen in the signaling layer before the call connects, so call quality and audio performance are untouched.

Under the TRACED Act, the FCC required voice providers to implement STIR/SHAKEN across the IP portions of their networks from June 30, 2021, with limited extensions for smaller providers. CloudTalk signs outbound calls to US destinations in line with those rules, so the compliance obligation stays with the platform rather than with your team.

They are the voice and messaging halves of the same problem. STIR/SHAKEN authenticates who is placing a call, while 10DLC registers the business behind an SMS number. Both exist so carriers can tell legitimate traffic from fraud.

Hello 👋 My name is Emma. Still have questions?

Can’t find the answer you’re looking for? Please chat to our friendly team.

Get in touch