Do Not Originate

    Do Not Originate List for Voice Carriers

    A Do Not Originate (DNO) list is the cheapest, highest-confidence spoofing defense a carrier can deploy. If a number can never legitimately place a call, every call claiming it is fraud — no analytics required.

    What Is a Do Not Originate List?

    A Do Not Originate list is a curated set of telephone numbers that must never appear in the calling-party field of an outbound call. The concept came out of the industry's early anti-spoofing work with the IRS, whose inbound-only hotlines were being impersonated in millions of scam calls a year. Because those numbers never place outbound calls, any call presenting one is provably spoofed — and safe to block outright.

    For a voice service provider, DNO is unusually attractive: it produces near-zero false positives, requires no machine learning, and stops some of the most damaging impersonation campaigns before they reach a single subscriber. It is a baseline control, not a substitute for analytics — but it is the first control a carrier should turn on.

    What Belongs on a DNO List

    Four categories cover the vast majority of entries carriers maintain today.

    Inbound-Only Numbers

    Customer service and support lines that receive calls but never dial out. Any outbound call carrying one is spoofed.

    Government & Financial

    IRS, Social Security, and bank fraud-line numbers are the most-impersonated numbers in the U.S. — prime DNO candidates.

    Unallocated & Invalid

    NPA-NXX blocks never assigned by NANPA, numbers with invalid formats, and unassigned ranges inside allocated blocks.

    Enterprise-Declared

    Numbers an enterprise registers with its carrier as never used for outbound dialing, protecting their brand from impersonation.

    DNO vs. STIR/SHAKEN

    STIR/SHAKEN answers the question "does this originating provider vouch for the caller's right to use this number?" DNO answers a blunter one: "should this number ever originate a call at all?" A spoofed call from an IRS hotline can still carry a valid B-level attestation from a careless upstream provider — DNO catches it regardless of attestation.

    The two controls stack. Carriers running SipShield apply DNO screening at ingress, then STIR/SHAKEN verification, then behavioral AI scoring on whatever survives. Each layer removes traffic the next layer would otherwise have to guess about.

    Implementing DNO Without Blocking Good Calls

    The FCC permits blocking calls from invalid, unallocated, unused, and subscriber-designated DNO numbers, but requires a reasonable process and a point of contact so blocking errors can be reported and resolved promptly. Static lists go stale — numbers get reassigned, enterprises change dialing patterns.

    SipShield maintains DNO data continuously against numbering-authority sources and enterprise registrations, applies it in real time at your SBC, and logs every blocked call with its reason code so you can answer a dispute or an FCC inquiry with evidence rather than assurances.