A company cuts over to a cloud phone system on a Friday. The numbers port, the handsets register, call quality is fine. Six weeks later the sales manager notices that outbound answer rates have fallen by roughly half, and a customer forwards a screenshot of the main line arriving on her phone as Spam Likely.
Here is the number worth sitting with before you start troubleshooting. In its December 2025 triennial report on the technologies used to combat robocalls, the FCC cited industry data showing that 43 percent of spam traffic on production networks carried A-level attestation, the highest grade of caller ID authentication that exists. In honeypot data, scam calls received A-level attestation more than half the time. Whatever paints that label on a screen, it is not simply reading the authentication signature and reacting to it.
That single fact explains most of the confusion around this problem. Businesses are told to get STIR/SHAKEN sorted out, they get it sorted out, and the label stays. The reason is that two entirely separate systems are involved, and only one of them is the one you have been reading about.
Two systems, not one
What the authentication signature actually asserts
STIR/SHAKEN is a signing framework. The provider that puts your call onto the IP network attaches a signed token to the call, and that token carries an attestation value of A, B, or C. RFC 8588 defines the claim itself and defers the meaning of the three values to the industry standard ATIS-1000074, which sets out the conditions precisely.
For A, full attestation, the signing provider must satisfy all three of the following: it is responsible for the origination of the call onto the IP-based voice network, it has a direct authenticated relationship with the customer and can identify that customer, and it has established a verified association with the telephone number used for the call.
For B, partial attestation, the first two conditions hold and the third does not. The provider knows who you are and can trace the call back to you, but has not verified that you are entitled to use the number you are presenting as caller ID.
For C, gateway attestation, the signing provider has no relationship with the originator of the call at all. International gateways are the standard example. The provider can only point at the network it received the call from.
Read those conditions again and notice what is missing. Nothing in any of them describes whether the call is wanted, whether the recipient will be annoyed, or whether the caller is running a scam. Every condition is about what the signing provider knows about its own customer, and whether that customer is entitled to the number being presented. Identity, not intent.
What decides the label
The label is produced downstream by an analytics engine operated by or for the terminating carrier. Under the current federal rules in Part 64 of Title 47, a terminating provider may block calls when the blocking rests on reasonable analytics designed to identify unwanted calls, and those analytics must include consideration of caller ID authentication information where available. The phrasing matters. Authentication is an input the analytics must consider, not the decision itself. The triennial report describes attestation as one factor in determining call treatment, meaning whether to block or label the call.
The FCC has said the quiet part out loud. In a further notice adopted in October 2025, the Commission observed that a spam label transmitted by a terminating provider might not be related to the STIR/SHAKEN attestation information it transmits, and could therefore be misleading to consumers. The agency is aware that the checkmark and the warning come from different places.
Why the cutover changed anything
Go back to the three conditions for A-level attestation. The third one, a verified association with the telephone number, is the one a migration disturbs. When you bring existing numbers to a new provider, that provider has a direct relationship with you from day one but does not necessarily have a verified association with numbers it never assigned. Platform documentation describes exactly this: ported numbers may not initially receive full attestation because the new originating provider cannot independently confirm the registration relationship. Until that association is established, calls sign as B.
B is not a scam marker. It is a weaker input into a scoring system that is already suspicious of a number whose calling pattern changed abruptly. There is also attrition in transit. The triennial report cites industry estimates that more than 60 percent of signed calls lose their attestation detail before reaching the terminating provider, because the call crosses non-IP network segments that cannot carry the token. Roughly 84 percent of traffic between major carriers was signed and verified by mid-2025, but signed at origin and readable at termination are not the same thing.
The Robocall Mitigation Database, and why it is your problem
Every voice service provider using North American Numbering Plan resources must file in the Robocall Mitigation Database, certifying its STIR/SHAKEN implementation status and filing a robocall mitigation plan describing its know-your-customer process. Providers must recertify annually by March 1, with the first annual recertification deadline having fallen on March 1, 2026. Providers may not accept call traffic from a voice service provider that is not listed, with an exception for emergency calls. An enforcement advisory released in February 2026 warned that many mobile virtual network operators and resellers remained non-compliant despite obligations that took effect in February 2024, and set out a base forfeiture of ten thousand dollars for false or inaccurate database information.
You are not the filer here unless you operate as a provider. What this means for a business is narrower and more practical: your call delivery depends on the compliance posture of a carrier you probably did not vet for this. Pending proposals from July 2026 would broaden the definition of a voice service provider to reach PBXs, cloud providers, call centers, and VoIP resellers, and would require filers to identify the third-party vendors handling their call analytics and STIR/SHAKEN signing. Those are proposals under comment, not rules in force.
What genuinely moves the needle
Confirm the number is registered to you and the name is right
Caller name display does not travel with your call. The terminating carrier performs a database lookup and pays the carrier hosting the name record, and the practice is not standardized across providers, so some carriers do not offer it at all. The FCC has found that these databases are reportedly not reliably accurate and subject to manipulation, and in February 2025 it declined to require caller name display alongside authentication partly on that basis. Verify what your provider has published for each number rather than assuming the name follows the port.
Check reputation with the analytics providers directly
A shared registration portal submits business numbers to the three dominant analytics providers in one pass, up to twenty numbers per submission. Read the disclaimer carefully: registration does not guarantee redress, because each provider performs its own independent analysis, and submitting the same number repeatedly adds nothing. That registration data is also not used to deliver caller name information, so it does not substitute for fixing a wrong name.
Treat branded calling as a product, not a right
Rich Call Data would carry a verified name and logo inside the signed token rather than through a legacy database lookup. As of September 2026 the FCC has proposed requiring terminating providers to transmit verified caller identity information alongside A-level attestation, but has not adopted it. Branded calling today is a commercial offering, purchased per vendor, with reach that varies by carrier and handset.
Fix the behavior that earned the label
Analytics providers publish the signals they weigh. One of the major engines grades a number on maturity, meaning how well established it is through call volume and frequency over time; connection, meaning answer rates; engagement, meaning whether recipients stay on the line once they pick up; and sentiment, meaning whether recipients block or report the caller. Read that list as a description of what a new, high-volume, rarely answered number looks like to a scoring system. In practice it points at a short checklist:
- Ramp volume on a new or newly ported number gradually rather than moving a full dialing day onto it at once.
- Stop dialing sequences that generate many one-ring or few-second calls.
- Present a caller ID that matches the number you actually answer calls on.
- Keep outbound campaign traffic on different numbers than the main business line.
- Retire abandoned-call patterns from any dialer configuration.
The trap nobody warns you about
Reputation is a score with memory. Providers describe spam labeling as dynamic and evaluated per call, but the inputs are historical, and history does not clear the moment you change your dialing. A number that has carried a label keeps carrying it for a while after the underlying behavior is fixed, because the pattern that produced the score is still inside the scoring window. Registration and review requests speed this up. They do not reset it.
The obvious workaround is the worst one. Moving to fresh numbers does not remove a reputation problem, it relocates it, and the analytics providers say as much: the underlying number reputation issue still needs to be addressed. Worse, a brand-new number has no established history, and lack of maturity is itself a risk signal. Rotating numbers to escape a label puts you permanently in the least trusted state, dialing from numbers that never accumulate the calling history that would eventually vouch for you.
One asymmetry is worth understanding before you go looking for someone to appeal to. The federal redress machinery was built around blocking, not labeling. The rules require a terminating provider to publish a single point of contact for call blocking error complaints, to resolve caller ID authentication disputes within a reasonable time with a status update within 24 hours, and to stop the treatment promptly once erroneous blocking is confirmed. A 2025 order went further and mandated a specific signaling code so that a blocked caller receives redress contact information automatically. A label is not a block. The call connects, the phone rings, and the recipient simply chooses not to answer. That path runs through the analytics vendors' own review processes rather than a mandated channel, which is why fixing the calling pattern is not merely the polite option. It is the input you control that the scoring system actually reads.
