Skip to content
14-day free trial · compliance included · one account for numbers, voice and SMS.14-day free trial · compliance included · one account for numbers, voice and SMS.14-day free trial · compliance included · one account for numbers, voice and SMS.14-day free trial · compliance included · one account for numbers, voice and SMS.
Twiching
All posts

Spam Calls on Wholesale VoIP: STIR/SHAKEN, Caller-ID Verification, and Robocall Mitigation

T
Author: Twiching TeamWholesale Voice Expert
July 7, 20239 min read
Spam Calls on Wholesale VoIP: STIR/SHAKEN, Caller-ID Verification, and Robocall Mitigation

Introduction

Spam calls are the biggest trust problem in telephony today, costing the US economy billions a year and pushing down answer rates for legitimate campaigns. Regulators now require carriers to adopt caller-ID verification and filing requirements as the baseline. This guide explains how carriers prevent spam calls and what businesses need to do to avoid being labelled as spam.

Why Spam Calls Are a Wholesale VoIP Problem

Spam calls exist at the scale they do because VoIP made them cheap. Programmable voice APIs let anyone with a credit card place millions of calls per day.

On top of that, caller-ID spoofing lets the originator hide their identity behind a different number.

For wholesale VoIP carriers, that combination is both a business opportunity and a regulatory problem. The same infrastructure that lets a legitimate contact centre dial 100,000 customers a day also lets a fraudster dial 100,000 victims a day. That happens whenever controls are not in place.

The defence against this is a stack of technical and regulatory countermeasures:

  • STIR/SHAKEN attestation
  • Caller-ID verification
  • Robocall Mitigation Database filings
  • Traffic-pattern monitoring
  • Blocked-prefix lists for premium-rate IRSF targets
  • Call-analytics partner registrations

A wholesale VoIP carrier that uses all of these protects its own reputation. It also protects its customers' answer rates and the regulatory licences that the whole business depends on.

STIR/SHAKEN: The Protocol Stack Behind Spam-Call Defence

STIR/SHAKEN is the caller-ID verification framework the FCC requires for US telephone traffic. STIR (Secure Telephony Identity Revisited) is the underlying cryptographic protocol.

SHAKEN (Signature-based Handling of Asserted information using toKENs) is the deployment framework. Originating carriers use it to attach attestation tokens to outbound calls.

Together, they cryptographically tie the displayed caller ID to a verified business identity. That identity is one the originating carrier has already checked, known as KYC.

Attestation comes in three levels: A, B, and C.

  • A-attestation: the carrier verified both the customer and their right to use the specific caller ID
  • B-attestation: the carrier verified the customer but not the specific number
  • C-attestation: the carrier verified neither, beyond the basic customer relationship

Calls with A-attestation get the highest downstream trust, the fewest spam labels, and the best answer rates. Calls without any attestation are increasingly filtered out at the terminating carrier.

That's how STIR/SHAKEN actually reduces spam calls in practice.

CallerID Spoofing and Why It Persists

Caller-ID Spoofing and Why It Persists

Caller-ID spoofing displays a false number on the recipient's screen. That lets scammers impersonate legitimate businesses, government agencies, or local neighbours.

It is the hardest part of the spam-call problem, because most people decide whether to answer based on the displayed number.

Spoofing persists even with STIR/SHAKEN in place. This happens when calls come from carriers that have not fully rolled out attestation. These are usually offshore VoIP providers outside the FCC's direct reach.

The defensive response is layered.

  • A US wholesale VoIP carrier verifies the caller ID against the customer's registered numbers before signing the call
  • Downstream carriers then verify that signature when they receive it
  • Call-analytics providers like Hiya, First Orion, and TNS add machine-learning models on top to catch new spam patterns

No single layer solves caller-ID spoofing on its own. Together, though, they make spoofed calls steadily less profitable for fraudsters.

FCC Robocall Mitigation Database Filings

Further reading: Wholesale voice solutions

The Robocall Mitigation Database (RMDB) is the FCC's registry of voice providers that have filed a robocall mitigation plan. Filing is mandatory for US wholesale VoIP carriers.

Downstream carriers must block calls from any provider not listed in the RMDB.

The filing documents what the provider actually does, technically and operationally, to prevent spam calls and robocall abuse on its network.

A credible wholesale VoIP carrier's RMDB filing covers:

  • STIR/SHAKEN implementation
  • KYC and customer onboarding policies
  • Traffic-pattern monitoring
  • Response procedures for traceback requests
  • IRSF and IRSF-adjacent fraud controls

The filing is public. Any business about to sign with a US wholesale VoIP carrier can look it up. It shows whether the carrier's robocall mitigation programme is real or just paperwork.

FCC Robocall Mitigation Database Filings

Traffic-Pattern Monitoring on a Wholesale VoIP Network

Beyond protocol-level defences, wholesale VoIP carriers also monitor traffic patterns for robocall signatures. Several signs flag a call for review:

  • Very high call velocity to new numbers
  • Extremely short average call duration (ACD)
  • Identical dialled-number patterns across many sources
  • Rapid round-trip dial patterns

A carrier that catches abusive traffic on its own network protects the answer rates of every legitimate customer sharing the same upstream interconnects.

Twiching runs real-time CDR analysis on every customer trunk, with hard spend caps, destination whitelists, and blocked-prefix lists. Suspicious traffic gets paused within seconds, not after a daily report.

This is what separates a wholesale VoIP carrier with a working robocall mitigation programme from one that filed the RMDB paperwork and then ignored it.

How Businesses Avoid Being Labelled as Spam

Further reading: Wikipedia: VoIP overview

  1. 01Use a STIR/SHAKEN-compliant wholesale VoIP carrier so every outbound call carries A-level attestation
  2. 02Ensure your outbound caller ID is a verified number registered to your business — not a borrowed or spoofed one
  3. 03Maintain healthy calling patterns — avoid extremely high call velocity to unfamiliar numbers
  4. 04Register your numbers with Hiya, First Orion, and TNS to prevent incorrect spam labelling
  5. 05Monitor your own number reputation regularly using carrier-provided reputation dashboards
  6. 06Honour do-not-call lists and use call-completion tracking to catch abandoned-call rate excess
  7. 07Comply with TCPA consent requirements before initiating any outbound campaign
STIR SHAKEN The Protocol Stack Behind SpamCall Defence

Twiching's Spam-Call Prevention Posture

Twiching uses STIR/SHAKEN attestation on every US-bound outbound call. It enforces caller-ID verification tied to verified customer identities, and monitors traffic patterns for robocall signatures in real time.

It also blocks known IRSF and premium-rate spam destination patterns, and complies with FCC robocall mitigation requirements, including the Robocall Mitigation Database filing.

For businesses, this means calls placed through Twiching arrive at terminating carriers with the best possible attestation posture. That improves answer rates on legitimate campaigns and cuts the risk of incorrect spam labelling.

Number-reputation monitoring is built into the customer dashboard, so operators can spot reputation issues before they crater a campaign.

A Multi-Layer Approach to Spam Defence

Defending against spam calls on wholesale VoIP infrastructure needs several layers working together.

  • Signalling layer: STIR/SHAKEN attestation and SHAKEN certificate validation filter out calls with invalid or low-trust credentials
  • Application layer: CNAM database lookups identify known spam numbers, and real-time blacklists block numbers reported by crowdsourced spam databases
  • Carrier interconnect layer: traffic from carriers with poor attestation rates or a history of fraud should be rejected outright

No single layer is enough on its own. Effective spam protection needs all three working together.

How Attestation Levels Work

The STIR/SHAKEN framework followed FCC mandates put in place in 2021. It requires carriers to digitally sign calls with attestation certificates.

Full attestation (A) certifies that the originating carrier has a direct relationship with the caller, and that the caller is authorised to use the presented number.

Partial attestation (B) certifies the call's originating carrier, but does not verify number authorisation. Gateway attestation (C) applies to calls entering the network from outside the STIR/SHAKEN ecosystem. That includes calls from international carriers or TDM gateways.

Calls with C attestation carry a higher risk of spam labelling by terminating carriers.

Managing Your Number Reputation

Reducing unwanted labelling on legitimate wholesale VoIP traffic takes proactive reputation management. Start by registering your originating numbers in the FCC's Robocall Mitigation Database.

Also make sure your STIR/SHAKEN certificates are set up correctly, with accurate CNAM data.

Work with your SIP providers to find out why numbers receive low attestation scores.

Appeal incorrect spam labels through the FCC's robocall complaint process. You can also appeal directly through the major analytics platforms — Hiya, First Orion, and Transaction Network Services — that supply labelling data to carriers.

Reputation management is now a core job for any wholesale VoIP operator sending traffic into North America.

Monitoring your outbound calling reputation means checking several data sources.

  • The FCC's Robocall Mitigation Database shows whether your company has registered a mitigation programme
  • Lookup tools from Hiya, TNS Transaction Network Services, and YouMail show individual number reputation

If specific numbers are being labelled as spam, look into the calling patterns tied to those numbers. Then work with your carrier to update their attestation records.

Proactive reputation monitoring prevents a worse customer experience. It stops legitimate business calls from being labelled as spam and going unanswered.

Conclusion

Spam calls are a layered defence problem. The wholesale VoIP carrier you sign with shapes how much of that defence you get by default, versus how much you have to build yourself. A few things are non-negotiable: STIR/SHAKEN attestation on every outbound call, a real Robocall Mitigation Database filing rather than a stub one, traffic-pattern monitoring on the carrier's own CDR stream, IRSF and spam-prefix blocking, and number-reputation view in the customer dashboard. For businesses, the practical outcome is answer rates that hold up under campaign load, and call analytics labels that do not blow up your inbound channels. Twiching is built around exactly that posture, so customers launch on a wholesale VoIP carrier where spam-call prevention is the default, not the upsell.

FAQ

Questions about Twiching, answered.

STIR/SHAKEN is a caller ID verification framework. It attaches cryptographic attestation to telephone calls, confirming that the displayed number is legitimate.

When calls carry verified attestation, carrier networks and call screening apps treat them as trusted. That greatly cuts the chance they get labelled as spam.

You reached the end

Read the next one. Slide to continue.

What is Wholesale Voice? Powering Scalable and Cost-Effective Communication

Drag the dial fully to the right to open the next dispatch.

Start free

Try it for 14 days.
See what a real phone stack does.

Phone numbers, voice, SMS and AI on one account. No credit card required — no charges during the trial.

Compliance with applicable regulations required.