What Is STIR/SHAKEN? Caller ID Authentication in Plain Words
STIR/SHAKEN is a system that lets phone carriers digitally sign a call to show the caller ID information is legitimate, so the carrier receiving the call can check it. It was built to make caller ID spoofing harder. It's one piece of the call quality and compliance picture, and it's narrower than most people assume.
This is general information, not legal or technical advice. The rules and how carriers apply them change, so confirm details with your phone provider and an attorney.
The plain-words version
Caller ID has always been easy to fake. The phone network was designed decades ago on trust: whatever number the caller's system said it was, the receiving carrier showed. That's how a scammer in another country can make a call look like it's coming from a local number, or from your own number.
STIR/SHAKEN adds a check. When a call starts, the carrier that originates it attaches a digital signature saying, in effect, "we know this customer, and we vouch for this number." The carrier that receives the call can check that signature. If it's valid, the call can be marked as verified. If it's missing or doesn't check out, the receiving carrier or your phone's spam tools can treat it with more suspicion.
Think of it like a notarized stamp. The stamp doesn't tell you what the person wants. It tells you the identity claim was checked by someone who had a reason to check it.
What the pieces mean
- STIR is the set of technical standards for signing and verifying caller identity.
- SHAKEN is the framework that tells carriers how to use those standards across the network.
- Attestation levels are how confident the signing carrier is. In general terms, a higher level means the carrier knows the customer and knows the customer is allowed to use that number. A lower level means the carrier knows the call came from its network but can't vouch for the number. The exact labels and rules are set by industry standards and regulators, so check current documentation if you need the specifics.
In the United States, the FCC has required carriers to implement caller ID authentication, and the framework applies to calls that travel over IP-based networks. Coverage and requirements have expanded over time, so check the FCC's own pages on caller ID authentication for the current state of the rules rather than relying on a summary.
What it does well
It makes one kind of fraud harder: pretending to be a number you don't control. That matters for homeowners who get calls spoofed to look local, and for businesses whose real numbers get spoofed and then flagged as spam because of other people's abuse.
It also gives phone apps and carriers better data. A call with a verified signature can be shown differently from one with no verification, and spam-labeling tools can use the signal.
What it can't do
This is the part that matters most for contractors.
It doesn't verify intent. A verified call can still be a robocall, a sales pitch, a wrong number or a fake lead. The signature says the number is legitimate. It says nothing about whether the person on the line wants a roof.
It doesn't verify the person. A scammer who owns a real phone line can place verified calls. Verification attaches to the line, not to the character of the caller.
It doesn't prove a lead is real. If someone wants to inflate call counts by dialing a tracking number with a real phone plan, STIR/SHAKEN won't stop it. That kind of abuse shows up in call logs and recordings. See how to spot fake pay-per-call leads for those signs.
It doesn't cover everything. Older non-IP networks, some call paths and some international routes may not carry the signature the same way. Calls can lose their signature when handed between carriers.
It isn't a blocklist. The framework supplies information. What a carrier or app does with it varies.
Why it matters to a contractor
Your outbound calls
If your office calls customers back, returns missed calls or confirms appointments, the number your call shows matters. Calls that carry a good signature are more likely to be treated as trustworthy by receiving carriers and apps. Calls from numbers that have been flagged before, or that go through a provider that doesn't sign, are more likely to show up as "Spam Likely" and get ignored.
Practical steps:
- Ask your phone or VoIP provider whether they sign your outbound calls and at what level.
- Keep your caller ID number consistent with a number you actually own and answer.
- If your number gets labeled spam, ask your provider how to request a review. Procedures vary by carrier.
Your inbound calls
STIR/SHAKEN is a weak filter for lead quality, but it's still a data point. If you buy calls, ask the vendor whether they look at caller ID verification status in their quality screening and how they use it. Ask follow-up questions too, because the answer reveals how seriously they take fraud. The full question list is in questions to ask a lead generation company.
Vendor due diligence
When you evaluate a source, "we use STIR/SHAKEN" isn't a quality guarantee. It's a baseline for a telecom provider and doesn't replace call recordings, duplicate caller filtering, fraud monitoring and a fair dispute process. Use it as one box on the vendor audit checklist, not as a substitute for the rest.
Where it sits among other rules
STIR/SHAKEN is about authenticating caller identity. It's separate from rules about whom you may call and what consent you need. Telemarketing, autodialed calls and texts fall under different laws, which are covered at a high level in TCPA lead compliance. Following one set of rules doesn't satisfy the others. Inbound-only calls from homeowners who dial you on their own raise different questions than outbound marketing calls, and an attorney can tell you which apply to your business.
A quick mental model
| Question | Does STIR/SHAKEN answer it? |
|---|---|
| Is this caller ID number being spoofed? | Helps indicate it |
| Is the number actually theirs? | Helps indicate it, depending on the level |
| Is the caller a real homeowner? | No |
| Did the caller want a contractor? | No |
| Is the call a duplicate? | No, see duplicate caller filtering |
| Is the caller allowed to call me? | No, that's a consent and calling rules question |
What to do next
- Ask your phone provider how your outbound calls are signed.
- Check whether your main numbers show as spam on a few test calls to different carriers.
- When you evaluate lead vendors, ask what fraud controls they run besides caller authentication.
- Read call fraud in home services for the scam patterns authentication doesn't catch.
If you're comparing call sources, how pay per call works shows how qualifying-call billing is structured, and you can apply to see how RankLocal handles it. Keep the legal questions with your attorney.
Frequently asked questions
What does STIR/SHAKEN stand for?
STIR stands for Secure Telephone Identity Revisited, and SHAKEN stands for Signature-based Handling of Asserted information using toKENs. Together they're a framework for phone carriers to verify that a call's caller ID information is legitimate.
Does STIR/SHAKEN stop spam and scam calls?
No. It helps carriers verify caller ID and make spoofing harder, but it doesn't block calls by itself. A real number can still make a bad call, so it's one layer of protection, not a full fix.
Why should a contractor care about STIR/SHAKEN?
It affects whether your outbound calls show up as trusted or get flagged as spam, and it's one signal for judging call quality from vendors. It does not prove a caller is a real, interested homeowner.
Is this legal advice?
No. It's a general overview, and the rules and carrier practices change. Ask your phone provider and an attorney about your specific setup.
More in this guide
Related resources
Want exclusive inbound calls routed to your phone? You pay only for qualifying calls.
Apply for a territory