Skip to content
Voice7 min

Caller ID reputation, STIR/SHAKEN and spam labelling

Your calls can be perfectly legitimate and still show up as "Scam Likely". How call authentication works, why analytics engines label numbers, and the operational habits that keep an enterprise's outbound numbers clean.

DC
Dollu Carrier Relations
Carrier Relations

Two problems that get confused - Enterprises calling into the United States and, increasingly, the UK, France and other markets, face two related but separate issues. The first is call authentication: can the terminating network verify that the caller ID presented was legitimately authorised for use by the originating party? That is what STIR/SHAKEN addresses. The second is reputation: given a number that is authenticated, do the analytics engines used by carriers and handset apps think it belongs to a spammer? That is decided by call behaviour and complaint data, and STIR/SHAKEN attestation does not fix it. Solving one and not the other leaves you with fully authenticated calls that nobody answers.

How STIR/SHAKEN works - When a call originates on a participating US carrier's network, that carrier signs the call with a cryptographic token carried in a SIP Identity header. The token asserts one of three attestation levels. Full attestation (A) means the originating carrier knows the customer and has verified they are authorised to use the calling number. Partial attestation (B) means the carrier knows the customer but has not verified the number. Gateway attestation (C) means the carrier is merely passing the call through, typically from an international gateway or a customer it cannot vouch for. The terminating carrier verifies the signature and can pass the attestation level to its analytics engine and to the handset. Since 2023 the framework has been extended so that intermediate providers must also authenticate calls, and the FCC's Robocall Mitigation Database requires providers to be registered and to describe their controls or have their traffic blocked.

Why international callers struggle to get A-level attestation - A contact centre in India or the Philippines dialling US customers on behalf of a US brand generates calls that enter the US network at a gateway. Unless the entity presenting the number has a direct relationship with a US originating provider that has verified its right to use that number, the calls will typically be signed at C level. Analytics engines treat C attestation as a weak negative signal, and combined with high call volume it pushes numbers towards a spam label. The remedy is architectural: originate the calls from a US provider that holds the numbers or has a documented letter of authorisation for them, and can therefore sign at A level. In practice that means the enterprise or its BPO uses a carrier with US origination and a delegated-certificate or know-your-customer process for the numbers being presented.

Where reputation actually comes from - The labels shown on handsets - Scam Likely, Spam Risk, Potential Fraud - are produced by analytics vendors working with the terminating carriers, and by app-based services. Their inputs are call volume from a number, short call durations, low answer rates, dialling patterns that resemble sequential or predictive dialling, complaint reports from subscribers, honeypot hits, and, since STIR/SHAKEN, attestation level. A legitimate collections or appointment-reminder campaign that makes 30,000 short calls a day from a single number looks, from the outside, very much like a robocaller. The engines cannot see intent; they see behaviour.

Operational habits that keep numbers clean - Spread outbound volume across a pool of numbers sized to keep per-number daily volume in a defensible range, and rotate deliberately rather than randomly. Present a number that is local to the called party where regulation allows, and make sure that number is answered when called back, ideally with an IVR that identifies your company. Register your numbers and your brand with the major analytics vendors' business registration programmes and with the carriers' branded calling services; registered numbers with a verified business identity are treated more favourably and, in some cases, display your company name. Monitor your numbers by placing test calls to handsets on the major US networks and checking how they are labelled, and do it weekly. Retire and replace numbers that have been labelled, then investigate why before reusing the pattern. Keep answer rate and average call duration healthy by dialling clean, consented lists at reasonable pacing.

The regulatory backdrop - In the US, TCPA and the FCC's rules govern consent, dialling technology and time-of-day, and violations are litigated actively. In the UK, Ofcom's CLI guidelines require presenting a valid, dialable number that the caller is authorised to use, and UK networks now block calls from abroad that spoof UK numbers. France has introduced its own call authentication framework, and several other European regulators are moving the same way. The direction everywhere is the same: numbers must be authenticated, presented honestly and answerable.

What to ask your voice provider - Can you sign my calls at A level, and for which numbers? What is your process for verifying my right to present a number? Do you offer branded calling or reputation registration as part of the service? Can you show me attestation level and label status per number in the portal? Do you monitor number reputation and alert me before answer rates collapse? A provider with real US origination and carrier relationships will answer these directly. One that only terminates international traffic into the US will not be able to.

The pay-off - For outbound operations, the difference between a labelled and a clean number pool is not marginal. Contact centres routinely see answer rates on labelled numbers fall to a fraction of clean ones, and every unanswered attempt is a wasted agent minute. Authentication and reputation management are, in that light, revenue engineering.