Book a Discovery Call
Back to Resources
Glossary

Caller ID authentication

Caller ID authentication defined: what STIR/SHAKEN actually signs under 47 CFR 64.6301 and 64.6305, whose duty it is, and why a legitimate call to a fresh lead can still arrive on the handset under a spam warning.

VisionXLab 4 min read

Caller ID authentication is the STIR/SHAKEN process in which a phone company signs the caller ID on a call it puts onto the network. Under the FCC's rules the duty sits with the voice service provider, not with the business dialling. The signature attests that the caller ID is accurate. It says nothing about whether the person answering wants the call.

The rule is written to your carrier, not to you

Section 64.6301 of title 47 tells a voice service provider to obtain a signing token from the Secure Telephone Identity Policy Administrator, to authenticate caller identification information on the SIP calls it originates before handing them to another provider, and to verify that information on the SIP calls it receives and will terminate. The subject of every duty in the section is the provider. A lender, a call centre or an individual loan officer cannot comply with this rule, because the rule was never addressed to them.

The signature is narrower than the word suggests

The definitions section describes authenticating caller identification information as the process by which a provider attests to the accuracy of the caller identification information transmitted with a call it originates. Accuracy of the number, and nothing past it. Wanted, expected, welcome and lawful are absent from the text. A borrower who filled in a form twenty minutes ago and a stranger working a cold list are, to the signature, the same call.

Where the A, B and C letters actually live

The attestation letters that come up in vendor conversations are not in the Code of Federal Regulations. They belong to the industry standard, ATIS-1000074, and the authority for saying so is the FCC's own order rather than the rule. Full, or A-level, requires the signing provider to be responsible for putting the call on the network, to have a direct authenticated relationship with the customer and be able to identify it, and to have established a verified association with the number used. Partial, or B-level, drops that last requirement. Gateway, or C-level, covers a provider that is only the entry point and has no relationship with whoever started the call. Citing 64.6301 as the source of those letters would be a genuine citation attached to a claim it does not make.

Sources for the two paragraphs above, both read in full on 20 September 2026 at ecfr.gov and docs.fcc.gov: 47 CFR 64.6300 and 64.6301 support the duties resting on the voice service provider, the SPC token, the authenticate and verify steps for SIP calls, and the definition of authentication as attesting to the accuracy of caller identification information. Neither section defines an attestation level or names any ATIS document. The A, B and C levels and their contents come from FCC 24-120, the Eighth Report and Order in WC Docket No. 17-97, which states at paragraph 10 that providers apply them pursuant to ATIS-1000074.

The Robocall Mitigation Database lists carriers, and its penalty is refusal

Section 64.6305 requires each voice service provider to certify that the calls it originates are subject to a robocall mitigation program, and that program must include reasonable steps to avoid originating illegal robocall traffic. The enforcement runs between companies: a provider may accept calls directly from another provider only when that provider's filing appears in the database. What happens to an unlisted provider is that its traffic stops being taken, upstream and invisibly. Nothing in the section concerns how a call is displayed, and nothing in it asks an end business to file anything.

Source: 47 CFR 64.6305, read in full on 20 September 2026 at ecfr.gov. It supports the certification of a robocall mitigation program, the requirement that such a program include reasonable steps to avoid originating illegal robocall traffic, and the rule that a provider accepts calls directly from another provider only when that provider's filing appears in the Robocall Mitigation Database. The section contains no language about spam labelling or call display, and imposes no filing duty on an end business that makes calls through a carrier.

Why a warning on the screen is an opinion, not a status

No rule read for this page defines the phrase a handset prints, sets who may apply it, or creates a route to have it withdrawn. The FCC treats authentication as information that flows to call blocking and labelling applications, which combine it with other analytics before deciding what to do with a call. That is the whole explanation for a fully signed call from a real office arriving under a warning. The signature is one input among several, the decision belongs to whoever owns the software on the other handset, and it cannot be paid off, because no rule creates the thing that would be bought.

What the mechanism leaves in the caller's hands

Two questions follow from the rule, and both are aimed at your own provider rather than at your prospects: does it originate your calls itself, and what has it established about your right to the number appearing in the caller ID. Those are the ingredients of the standard's top attestation level, and your provider is the only party the rule obliges to have an answer. Everything past that point is someone else's analytics. Why a purchased lead goes unanswered is a wider subject, covered in why mortgage leads do not answer, and whether dialling software belongs in the picture at all is decided in do you need a dialer for purchased leads.

One number is deliberately missing above. This page gives no figure for how much answering improves after a number is registered with a labelling or reputation service, because no primary source publishes one. The figures in circulation come from the companies selling the registration, and none traces to a study you can open. The regulations are a reliable source for who must sign a call and for what a signature means. They are not a source for what a carrier's software will print on a screen, and no document read here is.

Source: FCC 24-120, Eighth Report and Order in the Call Authentication Trust Anchor proceeding, WC Docket No. 17-97, read in full on 20 September 2026 at docs.fcc.gov. It supports the description of the framework as verifying that the caller ID transmitted with a call matches the caller's number, the statement that authentication provides information to call blocking and labeling applications, the note that such information may be incorporated with other analytics, and the attribution of the A, B and C attestation levels to ATIS-1000074. No source read for this page defines "Spam Likely" or any equivalent label, names who may apply one, or describes any way to remove one, and none gives a figure for the effect of registering a number anywhere.

Questions this page answers

Caller ID authentication is the STIR/SHAKEN process by which a phone company cryptographically signs the caller ID on a call it puts onto the network, so the next provider can check it. Title 47 of the Code of Federal Regulations defines it at section 64.6300 as the process by which a voice service provider attests to the accuracy of the caller identification information transmitted with a call it originates. Section 64.6301 places the duty to do it on the voice service provider, not on the business making the call.

No, and the two are separate systems. Authentication signs the number. The warning shown on a handset is applied afterwards by a carrier or a call blocking and labelling application, which the FCC describes as combining authentication information with other analytics before deciding what to do with a call. No federal rule defines the wording of those labels, sets who may apply one, or creates a procedure for having one removed. A correctly signed call from a real office can still arrive under a warning.

Section 64.6305 addresses voice service providers, gateway providers and intermediate providers, and requires them to certify a robocall mitigation program in the Robocall Mitigation Database. It places no registration duty on an end business that makes calls through a carrier. The database is a filing system for the companies carrying traffic, and its enforcement mechanism is that providers may accept calls directly from another provider only when that provider is listed. It is not a directory of callers and it is not a way to influence how a call is displayed.

Buying questions rather than research ones are answered on the FAQ, and anything that is not there gets asked on a call.

More in Resources

Find out whether we cover your states and products

A short call. We look at the states you are licensed in and the products you want, and tell you whether we have coverage before anybody talks about an order. One lead goes to exactly one client.