STIR/SHAKEN
STIR/SHAKEN is a caller-ID authentication framework that lets phone networks assess how confidently an originating provider can vouch for a caller's authority to use the displayed phone number. It uses digitally signed call information to help detect number spoofing as calls move between providers.
How STIR/SHAKEN works
On an authenticated call path, the originating provider creates a signed identity token containing information about the call and its calling number. The provider also assigns one of three attestation levels. Full attestation (A) means the provider knows the customer and has verified the customer's right to use the calling number. Partial attestation (B) means the provider knows the customer but has not verified the number. Gateway attestation (C) means the provider is passing along a call it received from elsewhere, such as an international gateway, and can vouch only for the point where the call entered its network. A receiving provider can validate the signature, confirm that it came from an authorized signer, and use the attestation as one input when deciding how to present or handle the call.
STIR/SHAKEN protects the integrity of caller-ID information; it does not judge the full purpose or quality of a call. A properly authenticated call can still be unwanted, and an unauthenticated call is not automatically fraudulent. Older network segments, international routes, gateways, and call forwarding can affect whether authentication information survives from origin to destination.
The framework is primarily associated with calls that use SIP signaling between providers. It does not encrypt the conversation audio, replace consent requirements, or populate a business name or logo. Those concerns belong to other controls such as SRTP, CNAM, branded calling, and responsible calling practices.
Why STIR/SHAKEN matters for AI phone calls
AI phone agents can place many calls through software, so the relationship between the calling organization, its provider, and each outbound number needs to be clear. Correct number assignment and carrier configuration give the originating provider the information it needs to authenticate calls accurately. Frequently rotating numbers or presenting numbers the caller is not authorized to use can undermine that chain.
Authentication is one part of deliverability, not a complete deliverability strategy. Businesses should also identify themselves truthfully, call for expected purposes, honor opt-outs, monitor reputation, and investigate routing changes when verification begins failing. When a recipient sees a verification indicator, it should be understood as evidence about the calling number—not an endorsement of the message or caller.