Key Facts
- Caller ID authentication framework: STIR/SHAKEN provides the standards used to authenticate caller ID information across voice networks.
- Designed to combat spoofing: The framework was created to reduce illegal caller ID spoofing and improve call traceability.
- Provider-driven implementation: Voice service providers authenticate and sign calls before they enter the network.
- Attestation-based model: Providers assign A-, B-, or C-level attestation based on their confidence in the caller's identity and number authorization.
- Supports accountability: Authentication helps identify which provider originated and authenticated a call.
- Not a spam-label solution: STIR/SHAKEN does not determine whether a call is wanted, trusted, or free from spam labels.
- Authentication and reputation are separate: Calls can authenticate successfully and still be labeled, blocked, or ignored due to reputation concerns.
TL;DR
Authenticating Caller Identity Across the Voice Ecosystem
STIR/SHAKEN is a framework used by voice service providers to authenticate caller ID information and help reduce illegal caller ID spoofing. The name combines two standards: STIR (Secure Telephone Identity Revisited) + SHAKEN (Signature-based Handling of Asserted Information Using toKENs).
Together, they create a standardized method for verifying that the provider originating a call has authenticated the caller and confirmed that the caller is authorized to use the telephone number being presented.
At a high level, STIR/SHAKEN helps answer a simple question: "Can this caller ID information be trusted?"
It does not answer: "Should I trust this caller?"
That distinction is important.
STIR/SHAKEN Is the Framework, Call Authentication Is the Process
Many people use STIR/SHAKEN and call authentication interchangeably, but they are not exactly the same thing. Think of STIR/SHAKEN as the technology and standards layer that powers caller authentication throughout the voice ecosystem.
Call authentication is the process of verifying caller identity information.
STIR/SHAKEN is the framework that makes that authentication possible.
Related: Call Authentication
Reducing Illegal Caller ID Spoofing
Before STIR/SHAKEN, caller ID information could often be manipulated with little standardized validation across networks. This made it easier for bad actors to impersonate businesses, government agencies, financial institutions, and consumers.
STIR/SHAKEN improves accountability by allowing providers to digitally sign calls and verify caller ID information as calls move through participating networks. This makes spoofing more difficult and substantially improves traceback efforts when suspicious traffic is identified.
Authentication Is Only One Trust Signal
One of the most common misconceptions about STIR/SHAKEN is that authentication automatically means a call is safe, wanted, or trustworthy. It does not.
STIR/SHAKEN helps verify that a caller is authorized to use a number. It does not evaluate:
- Consumer complaints
- Calling behavior
- Call intent
- Business legitimacy
- Number reputation
As a result, a fully authenticated call can still receive a spam label or poor call treatment if other trust signals are negative.
How It Works
How STIR/SHAKEN Works
Providers Authenticate Calls Before Origination
The STIR/SHAKEN process begins with the originating voice service provider. Based on this assessment, the provider authenticates the call and applies an attestation level.
Before placing a call into the network, the provider evaluates:
- Who the caller is
- Whether the caller is known to the provider
- Whether the caller is authorized to use the displayed number
Attestation Signals Provider Confidence
Attestation reflects provider confidence, not trustworthiness. STIR/SHAKEN uses three primary attestation levels:
- A-Level (Full Attestation): The provider knows the customer and has verified the customer's right to use the number.
- B-Level (Partial Attestation): The provider knows the customer but cannot fully verify number authorization.
- C-Level (Gateway Attestation): The provider received the call from another network and has limited visibility into the original caller.
Related: Attestation
Calls Are Digitally Signed and Verified
After authentication, the provider attaches a digital signature to the call. As the call moves through the network, downstream providers can validate that signature and confirm that the caller ID information has not been altered. This verification process helps support caller identity integrity across participating networks.
Authentication Information Travels With the Call
When the call reaches the terminating provider, that provider can evaluate the authentication information and determine whether the caller ID information can be verified. On supported networks and devices, additional indicators (like a checkmark) may be displayed to consumers, though implementations vary.
Why This Matters
Why It Matters
Caller ID Spoofing Became a Major Industry Problem
Consumers increasingly rely on caller ID when deciding whether to answer calls. As spoofing became easier and more widespread, trust in the voice channel declined. Businesses, carriers, regulators, and consumers all faced increasing challenges in determining whether caller identity information was legitimate.
STIR/SHAKEN was developed to restore confidence in caller ID information by improving authentication and accountability.
Better Accountability Supports Enforcement
One of STIR/SHAKEN's greatest strengths is traceback. When providers can identify which network authenticated and originated a call, enforcement agencies and industry groups can investigate suspicious traffic more effectively. This accountability makes it harder for bad actors to hide behind falsified caller identities.
Authentication Does Not Solve Every Calling Problem
STIR/SHAKEN is often viewed as a foundational trust technology rather than a complete trust solution. Authentication helps establish identity. Other processes help determine how that identity is perceived and treated.
Organizations still need to address:
- Number reputation
- Caller identity management
- KYC and entity verification
- Spam labeling
- Consumer trust
- Calling behavior
Common Questions
Is STIR/SHAKEN the same as call authentication?
Not exactly. Call authentication is the process of verifying caller identity information, while STIR/SHAKEN is the framework used to perform that authentication. In practice, STIR/SHAKEN enables call authentication across participating voice networks, but the two terms are not interchangeable.
Does STIR/SHAKEN stop spoofing?
It helps reduce and expose caller ID spoofing, but it does not eliminate it entirely. STIR/SHAKEN improves accountability by authenticating caller ID information and making suspicious traffic easier to trace. However, spoofing can still occur, particularly when identity verification is weak or bad actors exploit gaps elsewhere in the ecosystem.
Does STIR/SHAKEN stop robocalls?
No. STIR/SHAKEN was designed to authenticate caller ID information, not block robocalls. Many robocalls are legitimate and use authorized phone numbers. The framework helps verify identity information, but it does not determine whether a call is legal, wanted, or compliant.
Why are my calls still being labeled spam if they authenticate?
Authentication and reputation are evaluated separately. STIR/SHAKEN verifies caller ID information, while spam-labeling systems evaluate factors such as consumer complaints, calling behavior, historical reputation, and other analytics signals. A call can successfully authenticate and still receive a spam label.
Is A-Level Attestation enough to guarantee trust?
No. A-Level Attestation indicates that the originating provider has a high degree of confidence that the caller is authorized to use the number. It does not guarantee that the caller is legitimate, that the call is wanted, or that the number has a positive reputation. Authentication and trustworthiness are related but separate concepts.
Our platform empowers organizations to manage branded calling, improve caller id reputation, and stay compliant with evolving regulatory and industry standards. FAQs like this are designed to provide clear, actionable guidance backed by our expertise in verified identity, call labeling mitigation, and spam prevention.
To explore how Numeracle supports trusted and effective outbound communications, visit www.numeracle.com.



