STIR/SHAKEN Attestation: Why Insurance Calls Show as Spam
Carriers score every call by its STIR/SHAKEN attestation level. Here's how that decides whether your insurance agency's calls say Spam Likely in 2026.
You dial a lead who filled out a form an hour ago, and the call connects, rings twice, and drops to voicemail without the phone ever really ringing on their end. Their screen showed “Spam Likely.” Nothing about the call was actually spam. It was a real agent, calling about a real form they submitted, and the carrier’s software decided otherwise before the person ever saw who was calling. That’s not a mystery you can shrug off in 2026: it’s a scoring system, it runs on a specific technical signal called an attestation level, and the federal government just voted to make the scoring stricter.
This article explains what that signal is, why the Federal Communications Commission just proposed new rules that tighten it, what the growing distrust in phone calls is actually costing businesses like yours in real numbers, and a full method for protecting a number’s reputation that you can run yourself before spending a dollar on automation. It also covers where a managed AI caller changes the math, and where it doesn’t.
The short version
- Every outbound call now carries an A, B, or C STIR/SHAKEN attestation level, a carrier's own signed statement of how confident it is about who's calling. That level, combined with call pattern data, is what feeds "Spam Likely" labels.
- On May 20, 2026, the FCC voted to open a rulemaking that would force carriers to vet each other more strictly and fine them up to $2,500 per call for skipping it, per the Commission's own April 29, 2026 fact sheet.
- 86% of consumers don't answer calls from numbers they don't recognize, and 73% say businesses should identify themselves on caller ID, according to Hiya's 2026 State of the Call survey of over 12,000 consumers.
- Phone calls were the named contact method behind $948 million in reported fraud losses in 2024, with a $1,500 median loss, the highest median of any contact method the FTC tracks, per the FTC's own 2024 Consumer Sentinel Network Data Book.
- None of this requires an insurance agency to file anything with the FCC. The new rule targets carriers. But it changes how strictly the infrastructure underneath your calling platform gets policed, which is exactly why the platform matters.
What “Spam Likely” Actually Means, and Why It’s Getting Stricter
A “Spam Likely” label isn’t a human decision. It’s the output of a carrier’s analytics engine, and one of the biggest inputs to that engine, since 2021, is a signed technical statement called a STIR/SHAKEN attestation. STIR/SHAKEN is the caller ID authentication framework that every U.S. voice carrier is required to implement on its IP network, built to make caller ID harder to fake. Every time a call originates, the carrier that places it onto the network attaches a cryptographically signed marker to that call, and that marker carries an attestation level: A, B, or C.
A-level attestation means the originating carrier has a direct, verified relationship with the caller and has confirmed the caller actually has the right to use the number showing on the display. B-level attestation means the carrier knows who the caller is but couldn’t verify their right to that specific number. C-level attestation means the carrier can’t vouch for either fact, typically because the call is passing through an intermediary the carrier doesn’t have a direct relationship with. Terminating carriers, the ones delivering the call to your lead’s phone, read that attestation level, combine it with call-pattern signals like volume spikes, high hang-up rates, and complaint history, and decide what to show on the recipient’s screen.
| Level | What the carrier is confirming | Effect on how the call is likely treated |
|---|---|---|
| A (full) | Verified caller identity AND verified right to use the number | Highest trust signal; least likely to be flagged on attestation grounds alone |
| B (partial) | Verified caller identity, NOT verified right to the number | Moderate trust; weighed alongside other signals |
| C (gateway) | Neither confirmed; typical of calls entering through an intermediary | Lowest trust signal; more likely to be scored as suspicious |
Source: Federal Communications Commission, Further Notice of Proposed Rulemaking, Call Authentication Trust Anchor, FCC 26-32, circulated for the May 20, 2026 Open Meeting, describing the ATIS-1000074 attestation criteria.
Here’s the part that matters for an insurance agency that doesn’t own or operate any telecom infrastructure: you don’t set your own attestation level. Whatever carrier your calling platform routes through does. If that carrier has a weak, indirect relationship with the platform’s calling infrastructure, calls placed through it land closer to B or C by default, no matter how legitimate the campaign behind them is. That’s a platform-and-carrier decision, not something you configure in a dialer settings screen.
Two more pieces of vocabulary matter here, because the FCC’s new proposal is built entirely around them. Know Your Upstream Provider (KYUP) is the existing rule requiring a carrier to take reasonable steps to confirm that any carrier feeding it traffic isn’t a source of illegal calls; the FCC’s proposal would turn that loose, flexible obligation into a specific checklist, covering business-legitimacy checks, ongoing monitoring, and a defined process for cutting off a bad-acting upstream carrier. The Robocall Mitigation Database (RMD) is a public FCC registry every voice carrier must file in, certifying its STIR/SHAKEN implementation status and describing its own anti-robocall practices; under current rules, a carrier is only supposed to accept traffic from other carriers that actually appear in that database. Neither term shows up on an agent’s phone bill, but both determine, several layers upstream, whether the number an agency dials from gets treated as trustworthy the moment a call reaches a lead’s phone.
Why This Is Getting Worse, Not Better, in 2026
If it feels like caller ID scrutiny has tightened over the past year, that’s not a coincidence. On May 20, 2026, the FCC voted to advance a Further Notice of Proposed Rulemaking that would meaningfully raise the bar for how carriers vet each other and how they apply attestation levels, according to the Commission’s own April 29, 2026 fact sheet. The proposal would require every voice carrier to run specific background checks, called Know-Your-Upstream-Provider requirements, on any other carrier it connects to before accepting traffic from them: confirming business legitimacy, checking for a filing in the FCC’s Robocall Mitigation Database, and monitoring ongoing call patterns for signs of illegal traffic.
The proposal also directly targets improper attestation. The FCC’s own rulemaking cites a 2024 enforcement action against Lingo Telecom, which the Commission found had applied A-level, the highest trust tier, to 3,978 spoofed robocalls that carried a deepfake AI-generated voice impersonating then-President Joe Biden. That’s the exact failure mode the new rule is written to close: a carrier signing a call as fully trustworthy without actually doing the verification work the A-level attestation is supposed to represent.
If adopted as proposed, carriers that skip the new vetting requirements would face a proposed base forfeiture of $2,500 per call for Know-Your-Upstream-Provider failures and $1,000 per call for improper attestations, per the FCC’s own proposed rule text. None of that liability falls on the insurance agency or agent placing the call. It falls on the carrier. But the practical effect reaches you anyway: as of April 21, 2026, only 10,872 voice service providers had an active filing in the FCC’s Robocall Mitigation Database, according to the Commission’s own count in the same rulemaking, against roughly 471 million total voice connections active in the United States as of mid-2024, per the FCC’s own separate report on voice telephone services. A relatively small number of carriers sit underneath the entire country’s call volume, and the FCC is proposing to make every one of them accountable for who they let onto their network. A calling platform built on a carrier that takes that seriously routes differently than one that doesn’t.
This is a proposed rule, not a final one
As of this writing, the FCC has voted to open the rulemaking and take public comment; it has not yet adopted a final Report and Order. The specific per-call forfeiture amounts and effective dates described here are the Commission's own proposal, subject to change through the rulemaking process. What's already true, regardless of the outcome, is the underlying attestation framework and the carrier-level scrutiny it depends on.
What a Flagged Number Actually Costs You
The distrust driving all of this isn’t abstract. Phone-based fraud is large enough, and common enough, that consumers have been trained to treat an unrecognized number as guilty until proven innocent. Of the fraud reports the FTC’s Consumer Sentinel Network received in 2024 where the consumer identified how the scammer first reached them, phone calls accounted for 19% of the total, and those phone-based fraud reports carried $948 million in aggregate losses with a $1,500 median loss per report, the highest median loss of any contact method the FTC tracks, ahead of email, text, and social media, according to the FTC’s own 2024 Data Book. Imposter scams specifically, the category built on someone pretending to be a trusted business or government agency, drew 845,806 reports and $2.952 billion in losses in 2024 alone.
Phone-Based Fraud, 2024
By reported contact method, among fraud reports that named one
Source: Federal Trade Commission, Consumer Sentinel Network Data Book 2024, published March 2025.
That backdrop is exactly why consumer behavior has shifted so hard against answering. 86% of consumers say they don’t pick up calls from numbers they don’t recognize, and among the small share who do answer, most either send the call to voicemail or reject it outright rather than engage, according to Hiya’s State of the Call 2026 report, based on a survey of more than 12,000 consumers conducted between December 17, 2025 and January 2, 2026. When Hiya asked what single piece of information would make someone more likely to answer a business call, the top answer, at 29%, was seeing the business’s verified name on the screen; the second most common answer, at 24%, was simply seeing that the number hadn’t been flagged as spam by their carrier. 73% of respondents agreed outright that businesses should identify themselves in caller ID when they call.
Complaint volume feeds the same scoring loop from a different angle. Every time a recipient reports a call as spam through their carrier’s app or presses the “block this caller” option, that report becomes one more data point in the analytics engine deciding what to show the next person that number calls. A number that’s compliant on paper, meaning every person on the list gave prior express consent, can still accumulate complaint reports from people who forgot they opted in, changed their mind, or simply don’t recognize the caller ID showing up. That’s a separate problem from consent itself, but it lands on the same number’s reputation either way, which is one more reason honoring an opt-out immediately, on the first request, matters beyond the direct TCPA exposure.
Run the math on what that means for a batch of leads. Say your agency dials 500 fresh leads a week and, before any spam label enters the picture, you’d expect a reasonable share to at least answer or engage with a voicemail. If a number’s reputation slips and even a modest share of those calls now get screened out before the phone rings on the other end, that’s not a soft, hard-to-measure cost. It’s leads you paid for, sitting in a queue, that never had a chance to hear a human voice at all. Multiply an eroded answer rate across a week’s worth of purchased leads at whatever your agency pays per lead, and the reputation of a single outbound number becomes a line item, even though nobody wrote it down as one.
How to Fix It: The Method, Step by Step
None of what follows requires buying anything. It’s the discipline that keeps a number’s reputation clean, and you can run every piece of it with a spreadsheet, a dialer, and a calendar reminder.
Step 1: Register for branded calling on every active outbound number. Branded calling is separate from attestation. It’s a registration process, typically free through a carrier program or a branded-ID service, where you submit your business name, logo, and the general reason you’re calling. Once approved, that information can display on the recipient’s screen instead of a bare, unfamiliar number. Given that 29% of consumers say seeing a verified business name is the single thing most likely to get them to answer, per Hiya’s 2026 survey, this is close to a free lever with real upside, and most agencies simply haven’t done it.
This method builds on the mechanics of spam labeling we’ve covered before on this blog, specifically why a number’s reputation collapses in the first place and how carriers watch dial patterns; what’s new here is the attestation layer sitting underneath all of it, and the FCC’s move to police the carriers that assign it.
Step 2: Stage the volume ramp on any new number. A number that goes from zero calls to hundreds a day overnight is the single clearest signal carrier analytics engines watch for, because it’s exactly what a robocall operation looks like from the outside. Ramp gradually instead: start a new number at a modest daily cap, increase it in stages over several weeks, and never let a single number carry a full campaign’s volume from day one.
Step 3: Never fake area-code matching to work around a spam label. Local presence dialing, matching a lead’s area code with the outbound caller ID, is a real, legal tactic when it displays a number you actually own. Spoofing a number you don’t control to make an unrelated call look local crosses into the exact caller ID falsification STIR/SHAKEN and the FCC’s proposed rules are built to catch, and it accelerates a bad reputation instead of avoiding one.
Step 4: Spread volume across a pool of numbers instead of hammering one line. No single number should carry the full weight of a high-volume outbound campaign. Rotating across a small pool of properly warmed numbers keeps any individual line’s daily call count, and its resulting spam-analytics footprint, in a range that reads as normal business activity rather than a mass-dialing operation.
Step 5: Monitor your own numbers’ reputation regularly, not just when someone complains. Several free and low-cost tools let you check whether a specific outbound number is currently carrying a spam or scam label on major carriers. Check weekly, not only after a producer mentions their connect rate cratered. Catching a flag early, before it’s been live for weeks, matters because carrier algorithms weight recent behavior heavily; a number caught and corrected fast recovers faster than one left flagged for a month.
Step 6: Cut call attempts to dead or disconnected numbers aggressively. A high rate of unanswered calls to bad numbers looks identical, to a carrier’s analytics engine, to a robocall list scraped from the open internet. Clean your list before dialing, not after the flag appears.
Step 7: Log consent and honor opt-outs the moment they come in. None of the above replaces the underlying TCPA requirement for prior express consent on automated or artificial-voice calls to a cell number, and complaint volume is itself one of the signals that degrades a number’s reputation. A clean consent record and immediate opt-out handling isn’t just a compliance requirement; it’s part of what keeps complaint-driven spam flags away from your numbers in the first place.
What it looks like
- New number goes live at full campaign volume on day one
- No branded calling registration; caller ID shows a bare number
- Nobody checks spam-flag status until answer rates visibly drop
- One or two numbers carry the entire outbound campaign
What it looks like
- New numbers ramp gradually over weeks, not days
- Branded calling registered on every active outbound line
- Spam-flag status checked on a routine, not a reactive, schedule
- Volume spread across a pool of numbers, none carrying the full load
An agent reading this list and thinking “I could run this myself with a spreadsheet and a weekly reminder” is right. It’s real, ongoing work, but none of it requires specialized software you don’t already have access to. The honest tradeoff, like most of what’s on this blog, is time: staging number ramps, rotating a pool, and checking flag status weekly is a standing task that competes with everything else on a busy producer’s plate, and it’s the kind of task that tends to slip first when the week gets full.
If you want to build a version of this yourself with a dialer and some discipline, plenty of agencies do exactly that, and for a smaller calling operation, it’s a completely reasonable way to run it.
A Worked Example: What One Flagged Number Actually Costs
Say your agency runs 2,000 outbound calls a week across a single number that never went through a staged warmup. This next part is a modeling assumption, not a sourced benchmark: assume that once a number picks up a spam label, connect rates on calls that would otherwise have reached a live person or a real voicemail drop by something in the range of a third, a plausible but unverified estimate given how aggressively consumers screen unidentified calls. On 2,000 weekly attempts, that’s several hundred calls a week that never had a real chance to connect, calls you already paid for in lead cost, producer time, or both.
Now price out the alternative. Running that same 2,000 weekly calls through a managed AI caller at TheAffordableAI’s published Single Account rate of $0.20 a minute, assuming a conservative average of 45 seconds per attempt across a mix of connects, voicemail drops, and no-answers, costs roughly $300 a week in usage, on top of the $200 monthly fee and a one-time $500 setup fee. On the Agency plan’s bulk rate of $0.16 a minute, the same volume runs closer to $240 a week. Neither number is a promise about how many of those calls convert to a sale; it’s the cost of running the volume through a system built to stage warmup and rotate numbers instead of concentrating that same 2,000 calls a week on one line that’s never been given a chance to build a clean reputation in the first place.
You can build a version of this yourself with a dialer, a spreadsheet tracking each number’s daily volume, and a weekly reminder to check spam-flag status. Plenty of agencies do exactly that. The comparison worth making before committing either way is the same one that applies to any calling-volume decision on this blog: hours of staff time spent managing number rotation by hand, against a usage bill in the low hundreds of dollars a week on a plan with no long-term contract.
How We Solve It
TheAffordableAI runs number warmup and spam defense as a standing operational routine, not a one-time setup step you configure once and forget. Per TheAffordableAI’s own published feature description, new numbers ramp on a staged schedule, roughly 10 calls the first stage, then 20, then 30, then 40 calls per day per number across successive weekly stages, so call volume looks organic to carrier analytics rather than spiking overnight the way a fresh robocall list would. Full feature details are on the features page.
That warmup routine runs across a pool of managed numbers rather than concentrating volume on one or two lines, and it pairs with fast voicemail and dead-air detection, so minutes and connection attempts aren’t wasted on calls that were never going to reach a live human anyway, which itself helps keep unanswered-call ratios in a healthy range. None of this changes who’s responsible for TCPA consent, or the fact that no platform, including this one, can guarantee a carrier won’t flag a given number; carrier spam-scoring algorithms are proprietary and change without notice. What a managed system can do is run the practices that measurably reduce the odds, consistently, without depending on someone remembering to check a dashboard every Monday.
If you want to hear what a call like this actually sounds like before you decide anything, there’s a demo call on the homepage: https://theaffordableai.com/
What You Get
Run this correctly, whether by hand or with help, and the change shows up in the numbers a producer actually watches day to day: a higher share of dialed leads connecting to a live conversation instead of dropping to voicemail before the phone finishes its first ring, a caller ID that shows your agency’s actual name instead of a bare, unfamiliar number, and a number pool that recovers from an occasional flag in days rather than sitting flagged for a month because nobody was watching for it.
The math above uses TheAffordableAI’s published Single Account rate of $0.20 a minute; run it against your own call volume and average call length. https://theaffordableai.com/pricing
Edge Cases the Basic Method Doesn’t Cover
A few situations come up often enough in caller ID reputation work that they’re worth naming directly, even where there’s no clean, universally sourced statistic behind them.
A number that inherits a bad reputation from a previous owner. Phone numbers get recycled. A newly assigned number can arrive already carrying spam-flag history from whoever had it before you, through no fault of your own campaign. Check a number’s reputation before you put it into heavy rotation, not after volume is already flowing through it.
Porting numbers between carriers or platforms. A number’s attestation history and spam-analytics reputation don’t always transfer cleanly when it moves between carriers. Treat a freshly ported number with the same staged-warmup caution as a brand-new one, even if it had a clean history at its previous home.
Regional and carrier-specific variation. Spam-labeling behavior isn’t identical across every mobile carrier, and a number that looks clean on one network can show differently on another. There’s no single dashboard that shows every carrier’s view of a given number at once, which is exactly why routine, repeated checking matters more than a one-time confirmation.
Attestation is a caller ID trust signal, not a consent record. It’s easy to conflate the two because both sit underneath the same phone call, but they answer entirely different questions. Attestation tells a terminating carrier how confident the originating carrier is about who placed the call and whether they own the number showing on the screen. It says nothing about whether the person receiving the call ever agreed to be contacted. A call can carry a clean A-level attestation and still violate the TCPA if there’s no valid consent behind it, and a call can have flawless consent documentation and still land on B or C attestation because of something happening several network layers upstream, entirely outside the agency’s control. Keeping these two systems straight matters because the fix for one doesn’t touch the other: branded calling and number warmup improve how a call is scored and displayed, while consent logging and opt-out handling protect against a completely separate category of legal exposure.
Where This Doesn’t Apply
If your agency runs a low outbound volume, mostly warm referrals and a small book of repeat clients, none of the number-reputation math above changes your day much. A handful of calls a week rarely draws the volume-spike attention that triggers spam scoring in the first place. This entire method earns its keep specifically for agencies dialing real volume against purchased or generated leads, where a single flagged number can quietly cost real connections before anyone notices the pattern. It’s also worth being direct about the limits: nothing here, including a managed platform, can force a carrier to label a specific call one way or another. What changes is the odds, run consistently, over time.
See number warmup and spam defense running live
Watch how a fresh number ramps into full volume, how voicemail and dead-air detection protect connect rates, and how calls hand off with a warm transfer the moment a lead is ready to talk.
Frequently asked
What does STIR/SHAKEN attestation actually mean?
STIR/SHAKEN is the caller ID authentication framework U.S. carriers use to sign outbound calls. Every call gets an attestation level of A, B, or C, showing how much the originating carrier actually knows about who's calling and whether they have the right to use that number. A-level means the carrier verified both the caller's identity and their right to the number; C-level means the carrier can't vouch for either. Terminating carriers use that attestation, along with call pattern data, to decide whether to label a call Spam Likely.
Why do some of my insurance agency's calls show Spam Likely and others don't?
It's rarely one thing. A lower attestation level from your carrier, a sudden jump in call volume on a number, a high percentage of unanswered or quickly-hung-up calls, and complaint reports all feed the same carrier analytics engines. A brand-new number placing hundreds of calls a day looks statistically identical to a robocall operation to those engines, regardless of who's actually dialing or why.
What did the FCC just propose about caller ID in 2026?
On May 20, 2026, the FCC voted to open a rulemaking that would require carriers to run baseline background checks on the other carriers they connect to, tighten the rules for when a call can carry a trusted A-level attestation, and fine carriers up to $2,500 per call for skipping those checks. It targets the carriers that route calls, not the businesses that place them, but it changes how strictly your calls get scored once they leave your platform's network.
Does this new FCC rule mean insurance agents have to file anything with the FCC?
No. The proposed Know-Your-Upstream-Provider requirements apply to voice service providers, meaning carriers and telephony platforms, not the insurance agencies and agents placing calls through them. Nothing in the rulemaking requires an agent to register with the FCC. What it does is raise the bar for the carrier infrastructure underneath whatever calling platform you use, which is exactly why the platform you pick matters more than it used to.
What is branded calling, and is it the same thing as attestation?
No, they're related but separate. Attestation is the trust signal a carrier attaches to a call before it's even dialed. Branded calling is a separate, mostly free step where a business registers its name, logo, and calling reason with a carrier or a branded-ID service, so that information can display on the recipient's screen instead of a bare number. A call can carry a clean A-level attestation and still show up as an unbranded, unfamiliar number if the business never registered.
How much does it cost to keep an outbound number's reputation clean?
Branded calling registration itself is typically free through a carrier's own program. The real cost is discipline: staged volume increases on new numbers, monitoring for spam flags, and not letting a campaign spike from zero to hundreds of calls a day overnight. At TheAffordableAI's published Single Account rate of $0.20 a minute, running a properly warmed-up number costs the same per minute as any other call; the expense is the labor of managing warmup manually, not a separate line item.
Can a managed AI caller guarantee my number won't get flagged as spam?
No, and no legitimate vendor should claim that. Carrier spam-labeling algorithms are proprietary and change without notice, and no platform controls them. What a managed caller can do is run the practices that reduce the odds: staged number warmup, monitoring for flags, voicemail and dead-air detection that avoids wasting minutes on unanswered calls, and spreading volume across a number pool instead of hammering one line.
Sources
- Federal Communications Commission — Fact Sheet, Enhancing STIR-SHAKEN to Combat Illegal Robocalls (April 29, 2026)
- Federal Communications Commission — Further Notice of Proposed Rulemaking, Call Authentication Trust Anchor, FCC 26-32 (circulated for the May 20, 2026 Open Meeting)
- Federal Communications Commission — Voice Telephone Services: Status as of June 30, 2024 (Office of Economics and Analytics, May 2025)
- Federal Trade Commission — Consumer Sentinel Network Data Book 2024 (published March 2025)
- Hiya — State of the Call 2026 (survey conducted December 17, 2025 to January 2, 2026)
- TheAffordableAI — Features (number warmup ramp schedule)
- TheAffordableAI — Pricing
Put this on your own phone line
See the AI dial, qualify, and warm-transfer a live call in under a minute. No contract, no dev work.
Keep reading
Why Your Outbound Number Says 'Spam Likely' — and How to Get It Clean Again
A flagged number quietly destroys a calling operation. Nobody tells you it happened; the pickups just stop. Here is what causes the label, how carriers decide, and the warmup routine that keeps a number healthy.
Local Presence Dialing for Insurance Agents (2026)
Does matching a lead's area code get more calls answered? What local presence dialing is, where it turns into illegal spoofing, and how to do it right.
AI Voice Disclosure Laws for Insurance Agents (2026)
Do you have to tell an insurance lead they're talking to AI? What the FCC, Utah, California, and CMS actually require, state by state, verified in 2026.