Skip to content
AI Dialer

Deliverability

STIR/SHAKEN and CNAM, explained for people who make calls

  • 7 min read

By Last updated

The short answer

STIR/SHAKEN is how US and Canadian carriers cryptographically sign calls so the receiving network can judge whether the caller ID is trustworthy. CNAM is a separate, older system that displays a business name next to the number. Attestation A plus a registered CNAM record is the combination that keeps business calls out of the spam bucket.

Two systems decide what a person sees when your call arrives, and they are frequently confused with each other. One answers “can this caller ID be trusted?”. The other answers “whose name goes on the screen?”. You need both, they are configured in different places, and getting one right does not get you the other.

STIR/SHAKEN: is this caller ID real?

Caller ID was designed in an era when only carriers could originate calls, so it was never authenticated: the originating network simply asserted a number and everyone downstream believed it. That assumption is what made mass caller-ID spoofing trivially cheap.

STIR/SHAKEN fixes the trust gap without changing how you dial. When your provider originates a call, it signs it with a certificate and includes a claim about how confident it is in your right to use that calling number. The terminating carrier verifies the signature and passes the claim to its analytics engine.

The three attestation levels
LevelWhat the originating provider is assertingTypical situation
A: FullI know this customer, and I confirm they have the right to use this calling number.A number you bought from the provider that is originating the call.
B: PartialI know this customer, but I cannot confirm the origin of this number.A number you brought from elsewhere and are presenting as caller ID.
C: GatewayI passed this call along. I cannot vouch for the customer or the number.Wholesale or international traffic transiting the network.
The three STIR/SHAKEN attestation levels. A (Full) asserts a known customer and that the number is theirs, available on owned numbers, not possible on a shared pool. B (Partial) asserts a known customer but not the number, the best a shared pool can reach. C (Gateway) asserts neither, only that the call arrived from elsewhere.
What each level actually claims, and what a rented number can and cannot reach.

This is why rented pool numbers underperform

Attestation A requires the originating provider to confirm your right to the number. A number drawn from a shared local-presence pool, or a caller ID you set to a number you do not own, cannot earn it. That is a structural limit, not a setting someone forgot to enable.

Attestation is not a spam verdict in itself. It is an input (a well-weighted one) into the analytics models that decide whether to display your call normally, label it, or block it outright. A calls get the benefit of the doubt; C calls get very little.

CNAM: whose name shows on the screen

CNAM (caller ID name) is much older and works in a way that surprises most people: the name is not sent with the call. The receiving carrier takes the calling number, looks it up in a shared database, and displays whatever it finds.

Three practical consequences follow from that lookup model:

  • Updates are not instant. Different carriers refresh their caches on different schedules. Register a new name and allow several days before a campaign depends on it.
  • You get 15 characters. Not 15 words. “Bright Insurance Group of Greater Chicago” is not going to fit; decide what the 15 characters say before someone else decides for you.
  • Not every carrier honours it. Mobile carriers increasingly prefer their own branded-calling programmes over the legacy database, and some display nothing at all rather than an unverified name.

If you register nothing, the handset shows a bare number, or a guessed city name, or “Unknown”. Every one of those is answered less often than a name.

Branded calling is a third thing

Newer branded-calling programmes go further than CNAM: they display a verified business name, a logo, and sometimes a reason for the call, on the incoming-call screen itself. They are run per carrier, require identity verification, and generally cost money per number or per call.

They are worth evaluating if your outbound volume justifies it, and they are not a substitute for the two layers underneath. Branded calling on a number with a poor reputation and Attestation C does not save the call.

The order to set these up in

  1. 1

    Own the numbers you will call from

    This is a prerequisite, not a preference. It is what makes Attestation A possible and what makes callbacks reach your team.
  2. 2

    Confirm attestation on a live call

    Ask your provider what attestation your outbound calls carry. If the answer is B or C, find out why before you spend anything on remediation or branded calling.
  3. 3

    Register CNAM on every outbound number

    Pick the 15 characters deliberately. Use the name people would recognise, not your legal entity name: “Northgate Dental” beats “NGD HOLDINGS LLC”.
  4. 4

    Register with the analytics providers

    Free, and it lets you declare your numbers and call reasons before a model has to guess. This is also the channel through which you would later request remediation.
  5. 5

    Then consider branded calling

    Once the foundation holds, the incremental lift from a logo on the screen is real. Before that, it is decoration on a call that is already being filtered.

What this does not fix

Signing and naming a call tells the network who you are. It says nothing about whether the person wants the call, and the analytics models weight behaviour heavily. A perfectly attested, beautifully named number still gets labelled if it makes eight hundred calls a day that nobody answers.

The layers work together: attestation and CNAM buy you the benefit of the doubt, and number reputation management keeps you from spending it. See also why calls show as Spam Likely for the behavioural side.

Outside North America

STIR/SHAKEN is a North American framework. Other regions are addressing the same problem differently: the UK and EU through number-integrity obligations on originating providers, and several Asian markets through registered-sender schemes closer in spirit to branded calling than to call signing.

The practical advice generalises anyway. Own your numbers, register your identity with whoever the local gatekeeper is, keep per-number volume sane, and make sure a callback reaches a human. Those hold in every market, whatever the acronym.

How to check what your calls are actually carrying

Both systems are invisible from your side of the call, which is why teams operate for months on an assumption. Three checks settle it.

  1. 1

    Ask your provider for the attestation level, in writing

    Not “we support STIR/SHAKEN”; every provider says that. Ask what level *your* outbound calls are signed at, and why. If the answer is B, the usual reason is that the number is not one they issued you.
  2. 2

    Call a handset on each major network

    Look at what displays: your business name, a bare number, a guessed city, or a spam label. This is the only test that reflects what a customer actually sees.
  3. 3

    Check the CNAM record itself

    Several free lookup services return the registered name for a number. If it shows nothing, or shows a previous owner's name, the record was never created or never updated after a port.

Ported numbers are the classic gap

CNAM records frequently do not follow a number between providers. A business that ports in and never re-registers can spend a year displaying the previous owner's name, or nothing at all, without ever knowing.

Common misconceptions worth clearing up

  • “STIR/SHAKEN stops spam calls.” It does not stop anyone dialling. It makes it much harder to *present a number you do not own*, which removes the disguise rather than the caller.
  • “Attestation A means my calls will not be labelled.” No. Attestation is one input among several, and behaviour still dominates. A well-signed number making eight hundred unanswered calls a day is still scored as automated.
  • “CNAM is instant.” It is a cached database lookup performed by the receiving carrier, so propagation is uneven and takes days.
  • “My provider controls what displays.” For CNAM, the receiving carrier decides; your provider only maintains the record it reads.
  • “Setting my caller ID to any number is fine as long as I own the account.” Only if you own the *number*. Presenting a number you do not control is where the Truth in Caller ID Act starts to apply.

Frequently asked questions

What is Attestation A and why does it matter?
Attestation A is the highest STIR/SHAKEN confidence level: the originating provider confirms it knows the customer and that the customer has the right to use the calling number. It is the input carriers' analytics engines weight most heavily when deciding whether to trust your caller ID, and it can only be earned on numbers you actually own.
What is the difference between CNAM and STIR/SHAKEN?
CNAM decides what name appears on screen; the receiving carrier looks your number up in a shared database. STIR/SHAKEN decides whether the number itself is believable; your provider signs the call cryptographically. They are independent: you can have a registered name on an untrusted number, and vice versa.
How long does a CNAM update take to appear?
Usually a few days. Because each receiving carrier caches its own copy of the database, propagation is uneven: some networks show the new name within hours, others take the better part of a week. Set it up before a campaign starts, not during it.
Can I put any name I want in CNAM?
You are limited to 15 characters and it must legitimately identify the calling party. Registering a name designed to mislead the recipient is exactly what the Truth in Caller ID Act prohibits, and providers reject records that look like impersonation.
Do I need branded calling as well?
Only once the foundation is in place. Branded calling adds a verified name and logo to the call screen and does lift answer rates, but it is paid, per-carrier, and it does not rescue a number with poor reputation or low attestation. Fix ownership, attestation, and CNAM first.

Sources

  1. Combating Spoofed Robocalls with Caller ID AuthenticationFederal Communications CommissionThe STIR/SHAKEN framework, the attestation levels carriers sign calls with, and the mandate requiring providers to authenticate caller ID.
  2. 47 CFR Part 64 — Miscellaneous Rules Relating to Common CarriersElectronic Code of Federal RegulationsThe operative federal rules on caller ID transmission, call authentication, and robocall mitigation.

See it working: power dialer

A power dialer places one outbound call at a time from a loaded list, automatically dialling the next contact the moment the previous call ends. It removes manual dialling and hold time without the connection delay that makes predictive dialling feel robotic to the person who answers.

  • No subscription
  • Numbers in 100+ countries
  • Compliance built in