Ir al contenido principal

Software, apps, sitios web, redes y automatización con IA

Perspectivas tecnológicas

Caller ID in 2026: Why Spoofed Numbers Still Get Through, What STIR/SHAKEN Attestation Actually Proves, and How to Keep Your Business Calls Out of the Spam Likely Pile

Caller ID in 2026: Why Spoofed Numbers Still Get Through, What STIR/SHAKEN Attestation Actually Proves, and How to Keep Your Business Calls Out of the Spam Likely Pile

  • Equipo de Internet Pros
  • October 4, 2026
  • Redes y Seguridad

Este artículo está disponible solo en inglés.

Caller ID was designed in an era when only phone companies could put a number on the line, so nobody thought to check it. Today any internet calling service can send any number it likes, and scammers routinely borrow your bank’s number, your local area code or even your own number. The industry’s answer is STIR/SHAKEN, a system of signed caller ID that most large US carriers have been required to use since 2021. It has helped, but it is widely misunderstood. A verified call can still be a scam, and a perfectly legitimate business call can still show up as “Spam Likely”.

Why Caller ID Was So Easy to Fake

On the old circuit-switched network, the calling number was a field the originating switch filled in and every later switch simply passed along. When calling moved to Voice over IP, that field became a line of text in a SIP message. Anyone with a cheap VoIP account could type in whatever number they wanted, and the receiving network had no way to tell a genuine number from a borrowed one.

Spoofing is what makes robocall scams work. People answer local numbers and familiar names, and blocking a number is useless when the next call arrives from a different one. US consumers still receive several billion robocalls a month, according to call-blocking companies that track the traffic.

What STIR/SHAKEN Actually Does

STIR (an IETF standard) and SHAKEN (the industry rules for using it) add a digital signature to each call. The carrier that originates the call signs a small token, called a PASSporT, that states the calling number, the called number, a timestamp and how confident the carrier is about the caller. The token is signed with a certificate that only approved carriers can obtain. The terminating carrier checks the signature before the phone rings.

The confidence level is the part that matters most, and it comes in three grades:

Attestation What the originating carrier is saying Typical situation
A (Full) We know this customer, and they are authorised to use this number Your own carrier-assigned office or mobile number
B (Partial) We know this customer, but cannot confirm they own the number shown A PBX or call centre presenting a main number it got from another carrier
C (Gateway) We passed this call along but know nothing about where it started International traffic or calls handed over from another network

An A attestation proves who is responsible for a call. It does not prove the call is welcome.

Why Spoofed and Scam Calls Still Get Through

  • Gaps in the chain: signatures only travel over IP connections. When a call crosses an older circuit-switched link, the token is often lost, and the call arrives unsigned. Federal regulators have pushed carriers to close these gaps, but legacy links still exist.
  • Foreign gateways: much scam traffic starts abroad and enters through a gateway that can only give it a C, if anything at all.
  • Real numbers, bad intent: a scammer who buys genuine numbers from a lax provider can get A attestation. The signature tells you which carrier to blame, not whether the caller is honest.
  • Unsigned is not blocked: carriers rarely reject a call just because it lacks a signature, since too many legitimate calls would be lost too.

The real value of STIR/SHAKEN is traceback. Because each signed call names the carrier that let it in, regulators can find the provider behind a campaign quickly. Providers must also file a robocall mitigation plan in the FCC’s Robocall Mitigation Database. Carriers that fail to do so can be removed from it, which obliges other networks to stop accepting their traffic. That threat has pushed a number of small, lax providers out of the business.

AI has raised the stakes. After a cloned-voice robocall impersonated President Biden before the 2024 New Hampshire primary, the FCC ruled that AI-generated voices count as “artificial” under the Telephone Consumer Protection Act. It then fined both the political consultant and the carrier that signed the calls.

Where “Spam Likely” Really Comes From

The warning on a phone screen is not produced by STIR/SHAKEN itself. It comes from analytics engines run by firms such as Hiya, First Orion and TNS, working for the major carriers and phone makers. They combine the attestation level with behavioural signals:

  • Call volume from one number, especially sudden spikes
  • Very short call durations and low answer rates
  • Many calls to numbers that are not in service
  • Complaints, and how often recipients block the number
  • Number rotation, where many numbers are cycled to dodge reputation scores

That is why an honest clinic sending appointment reminders, or a contractor returning web leads, can be labelled as spam. Its traffic simply looks like a dialler.

Checklist: Keeping Legitimate Business Calls Out of the Spam Folder

  • Ask your provider what attestation your calls get. If your outbound number came from a different carrier, you may be getting B. Move the number, or have the provider confirm your right to use it, to earn A.
  • Register your numbers with the analytics firms. The free industry portal at FreeCallerRegistry.com reaches the main ones in one form.
  • Set your caller name (CNAM) so the line shows your business name rather than just a city.
  • Stop rotating numbers. Use a few stable, registered numbers and keep volume per number steady.
  • Look at branded calling. Rich Call Data services can show your logo and the reason for the call on supported phones, and they only work with properly signed calls.
  • Respect consent rules. Use prerecorded or AI-voiced calls only where the TCPA allows them, and honour do-not-call requests promptly.
  • Monitor your numbers. Call your own lines from major carriers regularly to catch a spam label before customers do.

What Everyone Should Do When the Phone Rings

For staff and customers, the rule is simple: caller ID is a hint, not proof. If a caller claiming to be your bank, a supplier or the IT help desk asks for a code, a password or a payment change, hang up and call back on a number you already have. Many organisations now pair this with a shared verbal passphrase for payment approvals, which defeats both spoofed numbers and cloned voices.

En resumen

STIR/SHAKEN did not end robocalls, but it changed who is accountable for them. Carriers can now be traced and cut off, and signed calls make up the bulk of traffic on the major networks. For businesses, the practical lesson is that call reputation now matters as much as email sender reputation. Get your numbers fully attested, registered and named, keep your calling patterns predictable, and your customers will be far more likely to pick up.

Need help with business phone systems, call-centre setup or security awareness training? Contact Internet Pros to make sure your calls are trusted and your team knows when not to trust one.

Compartir:
Etiquetas: Redes y Seguridad Business

Artículos relacionados