Illegal robocalls and spam texts can be worth $500 to $1,500 each.Free case review: (917) 551-6690

News

STIR/SHAKEN Caller ID Rules: What the FCC Changed and Proposed in 2025 and 2026

Short answer

STIR/SHAKEN lets phone carriers check that a call’s caller ID number is real. In 2025 the FCC began requiring carriers to sign calls with their own certificates, effective September 18, 2025. It then proposed verified caller names and foreign-call labels (October 28, 2025) and tighter carrier vetting and signing rules (May 20, 2026). Most of those are still proposals.

What STIR/SHAKEN does, in plain terms

STIR/SHAKEN is a caller ID authentication system. The FCC describes it as a way for carriers “to verify that a caller’s number matches the caller ID information transmitted with a call.” The first carrier signs the call with a digital certificate and a trust level called an attestation. Carriers down the line can check that signature. Call blocking and labeling tools use that information when they decide whether to show “Scam Likely” or block a call.

It has limits. The FCC notes that it “only works in IP networks.” Calls that pass through older, non-IP networks lose that signature along the way. And STIR/SHAKEN tells you whether the number is likely real. It does not tell you who is calling or whether the call is legal.

September 18, 2025: carriers must sign with their own certificate

In an order adopted November 21, 2024, the FCC closed a gap involving third-party signing. Some carriers let an outside vendor sign their calls using the vendor’s credentials. Under the new rules, a carrier may still use a vendor, but the call must be signed with the carrier’s own token and certificate, and the carrier must make its own attestation decisions. According to call authentication vendor TransNexus, the rules were published in the Federal Register on August 19, 2025 and compliance began September 18, 2025. Carriers that do not comply must say so in their Robocall Mitigation Database filings.

That link matters. The FCC has removed more than 1,400 carriers from that database since August 2025, which cuts them off from U.S. networks. Our story on the FCC’s Robocall Mitigation Database removals covers those orders.

April 2025: closing the non-IP gap

In April 2025 the FCC proposed rules for calls that pass through older, non-IP networks. Its fact sheet, released April 7, 2025, says the proposal would find that two industry standards for non-IP authentication meet the requirements of the TRACED Act, repeal the ongoing extension for carriers that rely on non-IP technology, and give those carriers two years from the rules’ effective date to put a non-IP solution in place.

October 28, 2025: verified names and foreign calls

On October 28, 2025, the FCC adopted a further proposal (FCC 25-76). It would require the last carrier to show a verified caller name whenever the call’s authentication shows the number is unlikely to be spoofed. It would require the originating carrier to verify that name. It also proposes that gateway carriers mark calls that start outside the United States, that your carrier pass along a foreign-origin indicator, and that blocking tools consider foreign origin. The FCC asked whether to ban spoofing of U.S. numbers on calls that start abroad.

The FCC’s release put it this way: “Consumers have the right to choose which calls they answer, but that choice is meaningful only when they know who is calling.”

May 20, 2026: vetting upstream carriers

On May 20, 2026, the FCC adopted another proposal (FCC 26-32). It would require every carrier to collect information about the carriers that send it traffic, verify it, monitor that traffic, and cut off an upstream carrier when the evidence shows it is a bad actor. The draft fact sheet released April 29, 2026 also proposed to codify attestation levels, repeal the two remaining hardship extensions, bar routing calls on purpose to strip authentication data, and require blocking of unauthenticated calls.

What this means for the calls you get

For now, most of this is proposed, not final. What you see on your screen today still comes from your carrier’s analytics. Our guide to phone spam labels explains what each one means, and our page on the Scam Likely label covers why legitimate calls sometimes get flagged too.

If the verified-name proposal becomes a rule, you may see a checked business name on more calls. That would help with a common problem in TCPA cases: finding out who called. A spoofed or blank caller ID is often the biggest obstacle to a claim.

Spoofing is its own violation. The Truth in Caller ID Act, 47 U.S.C. 227(e), bars misleading caller ID used to defraud or cause harm. The FCC enforces it, and in 2024 it fined one caller $6 million under it. Your own claim usually runs under other TCPA sections, such as consent rules for prerecorded calls or the Do Not Call rules, which our FCC TCPA regulations overview lists.

What to do when the caller ID looks fake

Do not call the number back. Write down the number shown, the time, and anything the caller said about who they were. If you answer a sales call, ask for the company name and its callback number, then note them. A real company name is what turns a spoofed call into a case. If you never get a name, our guide for when you cannot identify the caller explains what to track until you can.

Frequently asked questions

Does STIR/SHAKEN stop robocalls?

Not by itself. It verifies whether the caller ID number is likely real, which helps carriers block and label calls. It does not tell you who is calling or whether the call is legal.

Why do I still get spoofed calls if STIR/SHAKEN exists?

The system only works on IP networks, so calls that pass through older networks can lose their authentication. Calls from abroad and carriers that sign calls poorly also create gaps, which the FCC’s 2025 and 2026 proposals target.

Will my phone show the real caller’s name?

The FCC proposed in October 2025 to require verified caller names on calls that pass authentication. As of September 2026 it is a proposal, not a final rule.

Can I sue someone for spoofing my caller ID?

The FCC enforces the Truth in Caller ID Act, and it fined one caller $6 million under it in 2024. A consumer’s own claim usually rests on other TCPA provisions, such as prerecorded call consent or Do Not Call rules.

Sources

  1. FCC Fact Sheet: Closing the Non-IP Caller ID Authentication Gap (Apr. 7, 2025)
  2. FCC news release: FCC Takes First Major Step in Fresh Approach to Combatting Illegal Robocalls (Oct. 28, 2025)
  3. FCC 25-76, Call Branding and foreign-originated calls FNPRM (adopted Oct. 28, 2025)
  4. FCC news release: FCC Proposes Enhanced Know-Your-Upstream-Provider Requirements (May 20, 2026)
  5. FCC Fact Sheet: Enhancing STIR/SHAKEN to Combat Illegal Robocalls (Apr. 29, 2026)
  6. TransNexus: Effective date set for FCC third-party SHAKEN rules (2025)
  7. FCC Forfeiture Order FCC 24-104 (Truth in Caller ID Act, $6,000,000)

Free case review

Getting calls or texts you never agreed to?

Tell us who is calling and how often. Every submission is reviewed. If you can't name the company yet, the form will show you how to find out.

  • No fee unless you recover
  • Nationwide, through co-counsel where needed
  • Takes about 2 minutes

Or call (917) 551-6690

Do You Qualify?

Illegal calls and texts can be worth $500 to $1,500 each. Three quick steps, about a minute.

Step 1 of 3: What is happening

What are you getting? Choose all that apply
Which phone do they reach? Choose all that apply
Do you know the name of the company?

Prefer to talk? Call (917) 551-6690

Call (917) 551-6690