Skip to content
Report

Caller ID Spoofing and STIR/SHAKEN: How Fake Numbers Work

· 9 min read · Guides

Shield icon over a phone call, illustrating caller ID spoofing and STIR/SHAKEN verification

The number on your screen is not a fact. It’s a claim made by whoever placed the call, and for most of the phone network’s history nobody checked it.

That’s why a call can show your bank’s real number, the IRS, or a number one digit away from your own, and come from somewhere else entirely. This page explains how that works, when it’s legal, why so many scam calls look local, and what the STIR/SHAKEN system in the US and Canada can and can’t do about it.

A number you aren’t entitled to use

Spoofing is when a caller deliberately makes a different number appear on your screen than the one they’re really calling from. The displayed number might belong to a real business, a government agency, a random person, or nobody at all.

Caller ID has two separate parts, and that matters here. The number travels with the call itself. The name (CNAM) usually doesn’t: your carrier looks the number up in a database and shows what it finds, up to 15 characters. So a spoofed number can pull up a real company’s name even though the company never placed the call. “IRS” or your bank’s name on the screen proves nothing.

Scammers spoof for simple reasons. A local number gets answered. A bank or government number lends credibility. A borrowed number is hard to trace or block, and tomorrow they’ll use a different one.

One editable field in a call setup message

The old telephone network was built on trust between a few large phone companies. When a call passed from one carrier to the next, the calling number came along as data, and the receiving carrier displayed it without question. That was fine when placing calls took expensive equipment and a carrier contract.

Voice over IP (VoIP) changed the economics. Internet calls are set up with a signalling protocol called SIP, and the calling number is just a field in the setup message. Business phone systems often let the customer choose what goes in that field, for good reasons: a company with 200 desk phones wants every call to show its main line. The same flexibility lets a bad actor type in any 10 digits.

Carriers further down the line had no way to tell the number was false, so it was passed along until it reached your phone. According to the YouMail Robocall Index, Americans received about 52.5 billion robocalls in 2025, and spoofing is a big reason that blocking them one number at a time fails.

Diagram of a signed call: originating provider signs, call crosses networks, receiving carrier verifies, phone shows result
A STIR/SHAKEN call is signed where it starts and checked where it ends, as long as every link is IP-based.

Showing a number other than the line that physically dials out isn’t automatically a crime. The US Truth in Caller ID Act of 2009 makes it illegal to spoof caller ID with the intent to defraud, cause harm, or wrongfully obtain anything of value. The FCC can fine violators up to $10,000 per violation.

A doctor calling from a personal cell while showing the clinic’s main number is generally fine. So is a call centre displaying its customer service line instead of each agent’s desk phone.

A caller displaying an IRS number to demand payment is not. Neither is showing your bank’s real number to get your one-time passcode, or rotating random local numbers so nobody can trace the source.

The test is intent, not technique. Canada’s CRTC concentrates on blocking and authenticating calls rather than banning all number substitution. This is a summary, not legal advice; for a specific case, check the official FCC or CRTC source or speak with a lawyer.

Neighbour spoofing: a call that looks like it’s from down the street

Neighbour spoofing is when the fake number shares your area code, and often your next three digits. If your number is (312) 555-0147, a call from (312) 555-0199 could be your kid’s school or the pharmacy. People answer local calls they’d ignore from another state.

The fakes tend to give themselves away. The number is suspiciously close to yours. A callback reaches someone confused, or a dead line. And the call has the usual markers: a recorded voice and pressure to press 1.

The simplest defence is letting unknown local calls go to voicemail, since a real caller will leave a message. Looking up the number shows its area code, number type and any community reports or FTC complaint counts. With a spoofed call, though, those reports describe what other people saw on their screens, not who owns the line.

Phone screen showing an incoming call from a number that shares the recipient's area code and prefix
Neighbor spoofing copies your area code and prefix so the call looks local.

Strangers asking why you called them

Sometimes you find out you’re the “caller”. Strangers start phoning or texting: “Why did you call me?” or “Stop calling this number.” You didn’t. A robocaller picked your number, often because it matched the area codes they were targeting, and used it as the displayed caller ID.

Your phone hasn’t been hacked. Spoofing needs no access to your device or account; only the digits are borrowed. It usually stops on its own, because robocallers rotate numbers constantly and the wave often passes within days.

Meanwhile, a voicemail greeting helps: “If you got a call from this number, it was spoofed and didn’t come from me” saves a lot of conversations. Tell your carrier, and if it continues, file a complaint at fcc.gov/complaints. Changing your number rarely helps, since a new one can be spoofed too. There’s a fuller checklist for calls that seem to come from your own number, including the case where your own phone rings with your own number.

Confused recipients may also have reported your number on lookup sites, and those reports can stay up after the calls stop. On FreeSpy, a removal request hides the reports after verification and sets the page to noindex. Requests are reviewed within 72 hours.

STIR/SHAKEN: a signature on each call

STIR/SHAKEN is the industry’s answer to the trust problem. The names are acronyms for two technical standards, but the idea is simple. The carrier that starts a call adds a digital signature saying who it believes the caller is, and the carrier that delivers the call checks the signature before your phone rings.

A signed call goes through four stages:

  1. Signing. The originating provider checks its customer and the number they want to display, then attaches a signed token with the calling number, the called number, a timestamp and an attestation level.
  2. Transit. The token travels with the call across networks, as long as every hop is IP-based.
  3. Verification. Your carrier uses the signer’s public certificate to confirm the token is real and unaltered.
  4. Display. Your carrier combines the result with its own spam analytics and shows a verified mark, shows a spam label, or blocks the call.

The token also names the provider that signed it. So even when a bad call gets signed, investigators can see which carrier let it onto the network.

A, B and C attestation

The attestation level is the originating provider’s statement of how much it knows:

  • A (full): the provider knows the customer and knows they’re allowed to use that calling number.
  • B (partial): the provider knows the customer but can’t confirm their right to the number. A business displaying a number hosted by another provider often lands here.
  • C (gateway): the provider is passing along a call that came from somewhere else, such as an international gateway, and can’t vouch for the source.

A B or C rating doesn’t mean a call is a scam. Plenty of legitimate calls arrive with partial or gateway attestation. It means the network has less evidence, and carriers weigh that when deciding how to label the call.

Table comparing STIR/SHAKEN attestation levels A, B and C
Attestation describes how much the originating provider knows, not whether the call is wanted.

The “Verified” checkmark

Depending on your carrier and phone, a call that passes verification with A attestation may show a checkmark or the words “Verified Caller”. Not every carrier or device shows it, and the wording varies.

Read that mark narrowly. It means the caller is permitted to use the number. It doesn’t mean their business is legitimate or that you want to hear from them. A telemarketer breaking Do Not Call rules on their own real number can be fully verified.

Labels like “Spam Likely” or “Scam Likely” come from a different system, the carrier’s own call analytics, and they can appear on verified calls too.

The TRACED Act and the Robocall Mitigation Database

In the US, the push came from Congress. The TRACED Act, signed on December 30, 2019, required voice providers to put STIR/SHAKEN in place. The FCC set June 30, 2021 as the deadline for major providers on IP networks, with extensions for smaller providers running to June 30, 2022 and 2023.

Providers also have to file in the FCC’s Robocall Mitigation Database, describing their STIR/SHAKEN status and what they do to stop illegal robocalls. Other carriers must block providers that aren’t in the database. That rule gives the system teeth: a small carrier that ignores the requirements loses the ability to hand traffic to everyone else.

Canada’s track

Canada moved in parallel. The CRTC required STIR/SHAKEN caller ID authentication for IP-based voice calls starting November 30, 2021. Before that, a 2018 CRTC decision required carriers to block, at the network level, calls with blatantly illegitimate caller ID, such as numbers that can’t exist under the numbering plan.

Carriers have also tested pattern-based blocking. According to the CRTC, a Bell Canada AI call-blocking trial blocked more than 1.1 billion calls between July 2020 and October 2021.

You can run the numbering-plan check yourself. A number that can’t exist, such as one whose area code starts with 0 or 1, can only have been spoofed, and lookups flag it that way. The scoring method lists the other factors that go into a number’s rating.

Why robocalls barely dropped

STIR/SHAKEN made spoofing harder and tracing easier, but it isn’t a spam filter. YouMail estimated 52.8 billion US robocalls in 2024 and 52.5 billion in 2025, a drop of only a little over 1%. Several gaps explain it.

Old networks can’t carry the signature. When a call crosses older non-IP (TDM) equipment, the token is lost and the call arrives unsigned.

The system checks the number, not the intent. Scammers who rent real numbers can earn A attestation.

Calls from abroad get C at best. Gateway calls can’t be vouched for, so overseas operations are hard to stop. And what you see on screen depends on your carrier and your phone, so the display is inconsistent.

Comparison of what STIR/SHAKEN does and what it does not do
STIR/SHAKEN is one layer of protection, not a spam filter.

Your habits still do most of the work

Whether a spoofed call costs you anything comes down to what you do next. According to an Experian summary of FTC data, phone-call scams in 2025 had a median reported loss of $1,835, the highest median of the main contact methods.

Treat caller ID as a hint. If a call claims to be your bank, the IRS or the police, hang up and call back on a number from your card, your statement or the agency’s official site.

Screen unknown callers. Silencing or screening on your phone, plus your carrier’s free filter, catches a lot of spoofed traffic before it rings; the iPhone and Android settings take a few minutes.

Don’t call back strange numbers, since some missed calls are bait for costly international callbacks. And report what you get: to the FTC or FCC in the US, or the Canadian Anti-Fraud Centre (1-888-495-8501) in Canada.

Sources

Got a call like this?