Introduction
Spam calls are the biggest trust problem in telephony today, costing the US economy billions a year and pushing down answer rates for legitimate campaigns. Regulators now require carriers to adopt caller-ID verification and filing requirements as the baseline. This guide explains how carriers prevent spam calls and what businesses need to do to avoid being labelled as spam.
Why Spam Calls Are a Wholesale VoIP Problem
Spam calls exist at the scale they do because VoIP made them cheap. Programmable voice APIs let anyone with a credit card place millions of calls per day.
On top of that, caller-ID spoofing lets the originator hide their identity behind a different number.
For wholesale VoIP carriers, that combination is both a business opportunity and a regulatory problem. The same infrastructure that lets a legitimate contact centre dial 100,000 customers a day also lets a fraudster dial 100,000 victims a day. That happens whenever controls are not in place.
The defence against this is a stack of technical and regulatory countermeasures:
- STIR/SHAKEN attestation
- Caller-ID verification
- Robocall Mitigation Database filings
- Traffic-pattern monitoring
- Blocked-prefix lists for premium-rate IRSF targets
- Call-analytics partner registrations
A wholesale VoIP carrier that uses all of these protects its own reputation. It also protects its customers' answer rates and the regulatory licences that the whole business depends on.
STIR/SHAKEN: The Protocol Stack Behind Spam-Call Defence
Further reading: Wholesale pricing & rate deck
STIR/SHAKEN is the caller-ID verification framework the FCC requires for US telephone traffic. STIR (Secure Telephony Identity Revisited) is the underlying cryptographic protocol.
SHAKEN (Signature-based Handling of Asserted information using toKENs) is the deployment framework. Originating carriers use it to attach attestation tokens to outbound calls.
Together, they cryptographically tie the displayed caller ID to a verified business identity. That identity is one the originating carrier has already checked, known as KYC.
Attestation comes in three levels: A, B, and C.
- A-attestation: the carrier verified both the customer and their right to use the specific caller ID
- B-attestation: the carrier verified the customer but not the specific number
- C-attestation: the carrier verified neither, beyond the basic customer relationship
Calls with A-attestation get the highest downstream trust, the fewest spam labels, and the best answer rates. Calls without any attestation are increasingly filtered out at the terminating carrier.
That's how STIR/SHAKEN actually reduces spam calls in practice.

Caller-ID Spoofing and Why It Persists
Caller-ID spoofing displays a false number on the recipient's screen. That lets scammers impersonate legitimate businesses, government agencies, or local neighbours.
It is the hardest part of the spam-call problem, because most people decide whether to answer based on the displayed number.
Spoofing persists even with STIR/SHAKEN in place. This happens when calls come from carriers that have not fully rolled out attestation. These are usually offshore VoIP providers outside the FCC's direct reach.
The defensive response is layered.
- A US wholesale VoIP carrier verifies the caller ID against the customer's registered numbers before signing the call
- Downstream carriers then verify that signature when they receive it
- Call-analytics providers like Hiya, First Orion, and TNS add machine-learning models on top to catch new spam patterns
No single layer solves caller-ID spoofing on its own. Together, though, they make spoofed calls steadily less profitable for fraudsters.
FCC Robocall Mitigation Database Filings
Further reading: Wholesale voice solutions
The Robocall Mitigation Database (RMDB) is the FCC's registry of voice providers that have filed a robocall mitigation plan. Filing is mandatory for US wholesale VoIP carriers.
Downstream carriers must block calls from any provider not listed in the RMDB.
The filing documents what the provider actually does, technically and operationally, to prevent spam calls and robocall abuse on its network.
A credible wholesale VoIP carrier's RMDB filing covers:
- STIR/SHAKEN implementation
- KYC and customer onboarding policies
- Traffic-pattern monitoring
- Response procedures for traceback requests
- IRSF and IRSF-adjacent fraud controls
The filing is public. Any business about to sign with a US wholesale VoIP carrier can look it up. It shows whether the carrier's robocall mitigation programme is real or just paperwork.

Traffic-Pattern Monitoring on a Wholesale VoIP Network
Beyond protocol-level defences, wholesale VoIP carriers also monitor traffic patterns for robocall signatures. Several signs flag a call for review:
- Very high call velocity to new numbers
- Extremely short average call duration (ACD)
- Identical dialled-number patterns across many sources
- Rapid round-trip dial patterns
A carrier that catches abusive traffic on its own network protects the answer rates of every legitimate customer sharing the same upstream interconnects.
Twiching runs real-time CDR analysis on every customer trunk, with hard spend caps, destination whitelists, and blocked-prefix lists. Suspicious traffic gets paused within seconds, not after a daily report.
This is what separates a wholesale VoIP carrier with a working robocall mitigation programme from one that filed the RMDB paperwork and then ignored it.
How Businesses Avoid Being Labelled as Spam
Further reading: Wikipedia: VoIP overview
- 01Use a STIR/SHAKEN-compliant wholesale VoIP carrier so every outbound call carries A-level attestation
- 02Ensure your outbound caller ID is a verified number registered to your business — not a borrowed or spoofed one
- 03Maintain healthy calling patterns — avoid extremely high call velocity to unfamiliar numbers
- 04Register your numbers with Hiya, First Orion, and TNS to prevent incorrect spam labelling
- 05Monitor your own number reputation regularly using carrier-provided reputation dashboards
- 06Honour do-not-call lists and use call-completion tracking to catch abandoned-call rate excess
- 07Comply with TCPA consent requirements before initiating any outbound campaign

Twiching's Spam-Call Prevention Posture
Twiching uses STIR/SHAKEN attestation on every US-bound outbound call. It enforces caller-ID verification tied to verified customer identities, and monitors traffic patterns for robocall signatures in real time.
It also blocks known IRSF and premium-rate spam destination patterns, and complies with FCC robocall mitigation requirements, including the Robocall Mitigation Database filing.
For businesses, this means calls placed through Twiching arrive at terminating carriers with the best possible attestation posture. That improves answer rates on legitimate campaigns and cuts the risk of incorrect spam labelling.
Number-reputation monitoring is built into the customer dashboard, so operators can spot reputation issues before they crater a campaign.
A Multi-Layer Approach to Spam Defence
Defending against spam calls on wholesale VoIP infrastructure needs several layers working together.
- Signalling layer: STIR/SHAKEN attestation and SHAKEN certificate validation filter out calls with invalid or low-trust credentials
- Application layer: CNAM database lookups identify known spam numbers, and real-time blacklists block numbers reported by crowdsourced spam databases
- Carrier interconnect layer: traffic from carriers with poor attestation rates or a history of fraud should be rejected outright
No single layer is enough on its own. Effective spam protection needs all three working together.
How Attestation Levels Work
The STIR/SHAKEN framework followed FCC mandates put in place in 2021. It requires carriers to digitally sign calls with attestation certificates.
Full attestation (A) certifies that the originating carrier has a direct relationship with the caller, and that the caller is authorised to use the presented number.
Partial attestation (B) certifies the call's originating carrier, but does not verify number authorisation. Gateway attestation (C) applies to calls entering the network from outside the STIR/SHAKEN ecosystem. That includes calls from international carriers or TDM gateways.
Calls with C attestation carry a higher risk of spam labelling by terminating carriers.
Managing Your Number Reputation
Reducing unwanted labelling on legitimate wholesale VoIP traffic takes proactive reputation management. Start by registering your originating numbers in the FCC's Robocall Mitigation Database.
Also make sure your STIR/SHAKEN certificates are set up correctly, with accurate CNAM data.
Work with your SIP providers to find out why numbers receive low attestation scores.
Appeal incorrect spam labels through the FCC's robocall complaint process. You can also appeal directly through the major analytics platforms — Hiya, First Orion, and Transaction Network Services — that supply labelling data to carriers.
Reputation management is now a core job for any wholesale VoIP operator sending traffic into North America.
Monitoring your outbound calling reputation means checking several data sources.
- The FCC's Robocall Mitigation Database shows whether your company has registered a mitigation programme
- Lookup tools from Hiya, TNS Transaction Network Services, and YouMail show individual number reputation
If specific numbers are being labelled as spam, look into the calling patterns tied to those numbers. Then work with your carrier to update their attestation records.
Proactive reputation monitoring prevents a worse customer experience. It stops legitimate business calls from being labelled as spam and going unanswered.
Conclusion
Spam calls are a layered defence problem. The wholesale VoIP carrier you sign with shapes how much of that defence you get by default, versus how much you have to build yourself. A few things are non-negotiable: STIR/SHAKEN attestation on every outbound call, a real Robocall Mitigation Database filing rather than a stub one, traffic-pattern monitoring on the carrier's own CDR stream, IRSF and spam-prefix blocking, and number-reputation view in the customer dashboard. For businesses, the practical outcome is answer rates that hold up under campaign load, and call analytics labels that do not blow up your inbound channels. Twiching is built around exactly that posture, so customers launch on a wholesale VoIP carrier where spam-call prevention is the default, not the upsell.



