Ask a health system how it handles call deliverability and you will often hear a version of the same answer: our carrier does STIR/SHAKEN, we're covered.
They are not covered. They are authenticated, which is a different and much smaller thing.
What STIR/SHAKEN actually does
STIR/SHAKEN is the caller-authentication framework the FCC has required of major voice providers since 2021. It cryptographically attests that a call's originating number was not spoofed in transit, at one of three levels — full, partial, or gateway attestation.
That is genuinely valuable. It is also the entire extent of the claim.
Authentication is not identity, and this is the shortcoming of STIR/SHAKEN. It can verify that a call genuinely comes from the number displayed. It says nothing about who that number belongs to, why they are calling, or whether the recipient should trust them.
A patient looking at an unfamiliar ten-digit number gains nothing from knowing it is cryptographically genuine. She cannot see the signature. What she sees is an unknown number, and what she does is let it go to voicemail.
The gap is now measurable
For most of the framework's life this was an argument from first principles. It is now an argument from telemetry.
Transaction Network Services analyzes call traffic for more than 150 carriers and sells voice security and branded calling into the same market, so read the numbers with that in mind. Its mid-2026 report found that 17% of confirmed spoofed calls carried the highest "A"-level attestation. Invalid numbers — unallocated, not in use, or flagged Do Not Originate — were attested at "A" about 1.6% of the time. Between 10% and 12% of traffic that passed verification was still tagged as unwanted.
The FCC's own record says much the same thing from the other side. In the Wireline Competition Bureau's December 2025 triennial report on STIR/SHAKEN, USTelecom told the Commission that some providers assign "A"-level attestation to calls that are "invalid, mis-formatted, unassigned, non-routable, or designated as Do Not Originate." ZipDX, another commenter, put it harder: "attestation is effectively meaningless. There are plenty of 'good' B and C-level calls, and plenty of 'bad' A-level calls."
The Bureau did not conclude that the framework fails. It found the technology still effective at authenticating caller ID and declined to revise or replace it. Both things are true at once, and the combination is the whole point. The cryptography works. A call that passes it is still not a call the recipient has any reason to answer.
Identity is separate work, and it never finishes
The practical conclusion is that STIR/SHAKEN is table stakes, not a deliverability strategy. Getting a call answered takes a set of disciplines that sit alongside it:
- Number registration and reputation management. Register calling numbers with the major carriers' analytics providers, monitor how every number displays across carriers, detect a "Spam Likely" label within hours rather than weeks, and remediate — including rotating or retiring burned numbers.
- Branded caller ID. Display the organization's verified name, and increasingly its logo and call reason, on the recipient's screen — across each carrier's separate branding program. The evidence that identity drives answers is strong: 78% of consumers say a verified business logo would make them more likely to pick up.
- Full attestation, not partial. Structure carrier relationships so calls sign at full attestation rather than partial or gateway. It is a prerequisite for branding programs and a baseline trust signal. It is also unevenly available. The seven largest US carriers have plateaued at roughly 85% signed traffic between networks, up a single point in a year, while smaller carriers sit near 20%. And a signature applied correctly at origin does not always survive the trip: where a call crosses a legacy TDM or SS7 segment, the authentication data is stripped in transit. The FCC calls those non-IP segments the largest obstacle to universal STIR/SHAKEN coverage.
- Screener-aware calling, pacing, and spoofing surveillance. Detect answering machines and AI screeners; spread attempts so volume patterns stay within what analytics engines tolerate; watch for your own numbers and name being spoofed, because a scammer's abuse of your identity becomes your reputation problem.

Two things stand out about that list.
Reputation is perishable. Carrier algorithms retrain, labels drift, and a number that is clean today can be flagged next month. This is a monitoring loop, not a setup task.
Almost none of it is visible in a product demo. Two outbound systems can sound identical in a demo and differ by double digits in real-world answer rates, because the difference lives in carrier relationships and reputation operations, not in the conversation.
Underneath all of it is a problem of ownership. A call clears five layers before the phone rings, and the caller owns none of them.
An outbound call clears five layers before the phone rings. The caller controls none of them.
The regulators have noticed the same gap
In October 2025 the FCC adopted a Further Notice of Proposed Rulemaking on call branding, proposing to require voice providers to display verified caller identity — name, logo, call reason — using Rich Call Data, the identity extension to STIR/SHAKEN. The proceeding acknowledges outright that attestation alone has not given consumers a reason to answer.
The months since have made the direction plainer. In April 2026 the Commission proposed enhanced Know-Your-Customer rules for the providers that originate calls: what they must collect from a calling customer, how they must verify it, how long they must keep the record, and when a shift in traffic patterns should force them to check again. A Know-Your-Upstream-Provider proposal followed in May, applying the same idea one step further down the call path. A third proceeding takes on telephone numbering itself, including the practice of churning through large blocks of numbers to stay ahead of analytics and blocking.
One connective detail is worth pausing on. The Commission has proposed tying that diligence to attestation decisions, so that whether a provider may sign a call at "A" level would depend partly on whether it actually knows who the customer is. That is the regulator conceding the argument. If a signature were sufficient evidence of identity, there would be nothing to fix.
The details are still being contested: which providers are covered, on what timeline, with what verification. The direction is not. Verified identity on the call is moving from competitive advantage toward regulatory expectation.
Organizations building branded, reputation-managed calling now are aligning with where the network is headed. Those that wait are betting the unanswered-call problem solves itself.
Our whitepaper, Getting Through, sets out the six components of a serious deliverability practice and who controls each layer of the stack.
