Voice Fraud & Compliance Wiki

    Call Authentication

    STIR/SHAKEN

    The FCC-mandated framework that cryptographically signs calling numbers so terminating carriers can verify the caller ID was not spoofed.

    STIR (Secure Telephone Identity Revisited) is the set of IETF standards that define how a calling number is signed. SHAKEN (Signature-based Handling of Asserted information using toKENs) is the ATIS/SIP Forum profile that describes how North American carriers deploy STIR across their networks.

    In practice the originating provider signs each outbound call with a certificate tied to its OCN, attaching an Identity header that carries a PASSporT token. The terminating provider verifies that signature and can display or suppress a verification indicator to the subscriber.

    STIR/SHAKEN proves who put the call on the network and how confident that provider is in the calling number. It does not prove the call is wanted, legal, or truthful — a fraudster with legitimate numbers can still receive full A attestation.

    Why it matters to carriers

    Every US voice provider is required to implement STIR/SHAKEN or file a robocall mitigation program. Signing alone does not stop fraud, which is why the FCC also expects affirmative, effective mitigation measures.

    Handling stir/shaken on your own switch

    SipShield scores live SIP traffic with patented AI so the controls behind this term run automatically — and leave the audit trail regulators expect.