Security & Compliance 4 min read

STIR/SHAKEN Attestation Levels Explained: Why Your Calls Show ‘Scam Likely’

Discover how STIR/SHAKEN cryptographic attestation levels (A, B, or C) impact outbound call deliverability and how to ensure your lines receive Level A trust.

STIR/SHAKEN Attestation Levels Explained: Why Your Calls Show ‘Scam Likely’

Why do your outbound business calls show up as “Spam Risk,” “Scam Likely,” or go completely unanswered by prospects? While many business owners assume their calling behavior is the cause, the root issue is typically cryptographic.

The telecommunications network signs outbound voice traffic with a digital trust signature under the federal STIR/SHAKEN framework.

If your service provider assigns a low trust score to your calls, downstream carriers (AT&T, Verizon, T-Mobile) will flag your caller ID before the recipient’s phone even rings.

To secure your caller ID reputation, you must understand the three STIR/SHAKEN attestation levels and audit the infrastructure your provider uses to route your calls.

What is STIR/SHAKEN and Why Does it Exist?

STIR/SHAKEN (Secure Telephone Identity Revisited and Signature-based Handling of Asserted information using toKENs) is a suite of cryptographic protocols mandated by the FCC to combat caller ID spoofing and illegal robocalls.

Under this framework:

  1. Signing: When you place an outbound call, your originating voice provider digitally signs the call SIP header using a secure token.
  2. Verification: The terminating carrier receives the call, decrypts the signature, and verifies that the caller ID matches the digital certificate.
  3. Display: Based on the signature validity, the carrier decides whether to show your clean caller ID name, attach a “Scam Likely” flag, or block the call entirely.

The level of cryptographic trust assigned to your outbound call header is called the Attestation Level.

The Three STIR/SHAKEN Attestation Levels

The FCC defines three distinct tiers of trust. The differences in how carriers handle these signatures directly impact your answer rates:

Attestation Level Technical Definition Carrier Action Est. Answer Rate
Level A (Full) The provider verified the customer’s identity AND confirmed they own the phone number. Clean caller ID display, highest network trust. 85% – 95%
Level B (Partial) The provider verified the customer’s identity but CANNOT verify they own the number. Lower trust. Call may be flagged as spam if call volume spikes. 50% – 70%
Level C (Gateway) The provider only verifies the gateway where the call entered the network, with NO validation of identity or number ownership. Marked as Spam Risk or Scam Likely on most networks. 20% – 40%

If your outbound voice traffic receives Level B or Level C signatures, your outbound calls are structurally set up to fail, regardless of whether your business is entirely legitimate.

Why Per-Seat VoIP Providers Struggle to Deliver Level A Attestation

Many businesses using standard per-seat VoIP providers find their outbound lines flagged. This happens because of how retail VoIP providers structure their routing networks.

Because retail providers resell telephone lines, they route their customers’ call traffic through shared trunking gateways and recycled number pools. Because the provider does not directly control the underlying numbering database at the carrier level, they often sign calls with Level B (Partial) attestation.

Furthermore, if another business using the same recycled number pool engages in aggressive telemarketing, the carrier reputation engines flag the entire pool. Your business numbers are marked as “Spam Risk” due to the actions of a vendor you don’t know.

For a detailed walkthrough on diagnosing and cleaning flagged lines, see our guide on fixing spam risk phone numbers.

Securing Level A Attestation with Direct Carrier Routing

The only permanent way to protect your business caller ID reputation is to secure direct Level A (Full) Attestation.

Under a decoupled telecom architecture, you achieve this by lease-owning your numbers directly from a wholesale carrier:

  1. Direct Verification: You open a direct account with a wholesale carrier like Twilio and complete business identity verification.
  2. Number Control: You lease your phone numbers directly in your carrier account. Because the billing account and number ownership match, Twilio signs your outbound calls with Level A attestation.
  3. Zero-Code Interface: You connect a zero-code client like Blueprint Softphone to make and receive calls. The client routes calls through your Twilio account, inheriting the full Level A cryptographic signature.

This architecture ensures your business calls route with maximum network trust.

The Bottom Line

Outbound call deliverability is governed by STIR/SHAKEN attestation levels. Traditional per-seat VoIP providers often route call traffic through shared infrastructure, resulting in Level B or C signatures that trigger “Spam Risk” flags. Shifting to a decoupled telecom architecture allows you to lease numbers directly from a wholesale carrier like Twilio, securing Level A attestation and protecting your caller ID reputation. Stop letting middleman routing infrastructures block your outbound connections.


Ready to Secure Level A Call Attestation?

Blueprint Softphone provides a premium, zero-code frontend interface that routes calls directly through your personal Twilio account, ensuring you inherit full Level A cryptographic trust. Learn more in our How It Works explainer, read our guide on building a Twilio phone system without coding, or Get Started Free to connect your lines in under ten minutes.

Brent Pope

Founder, Blueprint Softphone · 40+ years enterprise IT

Related Articles