What Is STIR/SHAKEN? A Simple Guide for Outbound Call Centers

STIR/SHAKEN does not tell the customer that your call is good. It does not certify the lead. It does not remove a Spam Likely label. It does not guarantee that the phone will ring. What it does is much narrower and more useful: it gives participating voice networks a standard way to authenticate information about […]

Business Systems What Is STIR/SHAKEN? A Simple Guide for Outbound Call Centers 2026.09.17

STIR/SHAKEN does not tell the customer that your call is good.

It does not certify the lead. It does not remove a Spam Likely label. It does not guarantee that the phone will ring.

What it does is much narrower and more useful: it gives participating voice networks a standard way to authenticate information about the caller ID attached to an IP voice call.

Start with the problem STIR/SHAKEN was built to address

Caller ID can be manipulated. Before stronger authentication became common in IP voice networks, a receiving carrier had limited cryptographic evidence about who inserted the calling number into the call path.

STIR/SHAKEN adds signed identity information that can travel with a SIP call so downstream providers can verify that the authentication came from a trusted provider and see the level of attestation that provider assigned.

What does STIR/SHAKEN stand for?

STIR stands for Secure Telephone Identity Revisited.

SHAKEN stands for Signature-based Handling of Asserted information using toKENs.

The names are less important operationally than the workflow: authenticate at origination, pass the signed identity with the call, and verify it downstream.

What actually gets signed?

In a typical SIP implementation, the originating provider creates a signed PASSporT token and places identity information in the SIP INVITE’s Identity header.

That information includes the calling number and an attestation level that describes what the originating provider knows about its customer and that customer’s right to use the number.

The terminating provider can validate the signature using the trusted certificate framework.

A, B and C attestation are not grades

Attestation What the originating provider is asserting What it does not mean
A – Full The provider knows the customer and has a basis to believe the customer is authorized to use the calling number The call is safe, wanted, or compliant
B – Partial The provider knows the customer but cannot fully attest to that customer’s right to use the calling number The call is fraudulent
C – Gateway The provider is passing the call into the network but has limited relationship information about the original caller The call should automatically be blocked

Managers often treat A as “good” and C as “bad.” That is too simple. Attestation describes identity knowledge at origination, not the quality or legality of the conversation.

Why does an outbound call center care about attestation?

Because caller identity is part of deliverability and trust.

If your provider only gives partial attestation when you expect full attestation, investigate the account and number-ownership relationship. The provider may need verified business information or proof that the numbers are assigned for your use.

Do not solve the issue by changing caller IDs randomly. Fix the identity chain.

Full attestation does not remove Spam Likely

This is one of the most persistent misunderstandings.

STIR/SHAKEN authentication and caller reputation are separate systems.

A call can carry valid A-level attestation and still be labeled as spam because reputation systems also consider complaint patterns, traffic behavior, number history, recipient feedback, call duration, and other signals.

Authentication helps receiving networks trust the caller-ID assertion. It does not require them to trust the calling behavior.

CNAM, branded calling and STIR/SHAKEN solve different problems

  • STIR/SHAKEN: authenticates caller-ID information through the network.
  • CNAM: can provide a caller-name value in supported U.S. caller-ID ecosystems.
  • Branded calling: can deliver richer verified brand identity on supported networks and devices.
  • Reputation: reflects how carriers and analytics systems classify the calling number or traffic.

A complete caller-identity strategy can involve all four without treating them as interchangeable.

Where STIR/SHAKEN appears in a SIP call

The authentication is not something an agent enters into VICIdial or another agent screen on every call.

It is handled in the provider and SIP-signaling layer. The originating voice provider signs the identity, intermediate providers pass the relevant information, and the terminating provider verifies it when supported.

Your dialer still needs to present an authorized caller ID and route the call through a provider that can correctly authenticate the traffic.

What if your call passes through several carriers?

The identity information is designed to travel through the IP call path, but real routes can include intermediate providers, gateways, and non-IP segments.

When troubleshooting authentication, identify which provider originates the call into the authenticated network and which provider is responsible for signing it.

Do not assume the company selling you minutes is always the entity creating the attestation.

The questions to send your VoIP provider

If your team is unsure what is happening, ask directly:

  • Do you sign our outbound calls with STIR/SHAKEN?
  • What attestation level are our calls receiving?
  • Is attestation different by DID, trunk, or route?
  • What business verification is required for A attestation?
  • How do you validate our right to use the caller-ID numbers?
  • Can you provide examples or SIP traces showing the Identity header?

What a dialer manager should verify internally

  1. Use caller IDs the business is authorized to use.
  2. Keep the number inventory tied to the correct provider and campaign.
  3. Make sure outbound routing does not unexpectedly bypass the signing provider.
  4. Track attestation separately from spam labels.
  5. Keep callback routing and business identity consistent with the presented numbers.

When A attestation still produces poor answer rates

Look beyond authentication.

Check caller reputation, CNAM or branded identity, local-presence strategy, lead quality, calling cadence, time of day, and the call pattern created by the campaign.

A-level attestation removes one uncertainty. It does not solve every reason a customer ignores a call.

For teams working across carrier routing, caller-ID operations, and call-center systems, Consaltek’s telephony and operational systems services can support the implementation layer around the selected providers.

Common misconceptions worth removing from the floor

“A attestation means the number cannot be marked spam”

False. Authentication and reputation are separate.

“B attestation means the call is fraudulent”

False. It means the provider cannot make the same number-authorization assertion it makes under full attestation.

“The dialer generates STIR/SHAKEN”

Usually the signing occurs at the originating voice-service-provider layer, not in the agent UI.

“STIR/SHAKEN proves the caller has permission to call”

False. It authenticates caller-ID information; it does not determine consent, DNC status, or telemarketing legality.

Frequently Asked Questions

1. What is STIR/SHAKEN?

It is a caller-ID authentication framework used in IP voice networks to sign and verify information associated with a call.

2. What does STIR stand for?

Secure Telephone Identity Revisited.

3. What does SHAKEN stand for?

Signature-based Handling of Asserted information using toKENs.

4. What is A attestation?

Full attestation means the originating provider knows the customer and can attest that the customer is authorized to use the calling number.

5. What is B attestation?

Partial attestation means the provider knows the customer but cannot make the same full assertion about the customer’s right to use the calling number.

6. What is C attestation?

Gateway attestation is used when the provider is bringing the call into the authenticated network but has limited information about the original caller relationship.

7. Is A attestation a guarantee that a call is legitimate?

No. It is an identity attestation, not a legal, compliance, or reputation verdict.

8. Does STIR/SHAKEN remove Spam Likely?

No. Spam labeling uses separate reputation and analytics systems.

9. Is CNAM the same as STIR/SHAKEN?

No. CNAM concerns caller-name display; STIR/SHAKEN concerns cryptographic caller-ID authentication.

10. Who assigns the attestation level?

The originating provider that authenticates the call assigns the attestation based on its knowledge of the customer and number authorization.

11. Does VICIdial assign A, B or C?

Normally the carrier or originating voice-service provider handles the signing and attestation, while VICIdial presents the configured caller ID into that route.

12. Can a call lose authentication across a route?

Complex routing, unsupported segments, or provider handling can affect what reaches the terminating network. Troubleshooting should follow the actual call path.

13. How do I know what attestation my calls receive?

Ask the originating provider and, where available, inspect SIP traces or provider reporting that exposes the Identity information.

14. Can STIR/SHAKEN prove that the lead consented to the call?

No. Consent and DNC eligibility are separate from caller-ID authentication.

15. What should a call center do if it is receiving B attestation unexpectedly?

Verify the provider relationship, business identity, DID assignment, caller-ID configuration, and the route responsible for signing the calls.

Final Takeaway

STIR/SHAKEN answers a narrow question: how much can the originating provider attest about the caller and the right to use the presented number?

That is important, but it is not the same as reputation, branding, consent, or call quality.

For a dialer manager, the practical job is to use authorized numbers, know which provider signs the traffic, verify the attestation being received, and troubleshoot reputation as a separate system instead of expecting A attestation to solve everything.

CE
Consaltek Editorial Team

Practical notes on data preparation, call center operations, workflow design, reporting, and the systems that support recurring operational work.