STIR/SHAKEN Attestation Levels Explained: A, B, and C
June 18, 2026 · 6 min read
In a STIR/SHAKEN environment, there are three ways a call can be attested to or signed by a service provider: full, partial, or gateway. Understanding these levels is critical because they determine how your calls are treated by terminating carriers and whether they'll be delivered or flagged as potential spam.
The Three Attestation Levels
| Level | Name | Description | Impact |
|---|---|---|---|
| A | Full Attestation | The service provider knows the caller AND their association with the calling phone number | Highest trust; best chance of delivery |
| B | Partial Attestation | The service provider knows the caller but NOT their relationship with the calling phone number | Moderate trust; may be flagged |
| C | Gateway Attestation | The service provider is transiting the call but can't authenticate the call source | Lowest trust; highest risk of blocking |
The full standards regarding attestation are listed in ATIS-1000074.
A-Level (Full Attestation)
The service provider has authenticated the caller AND verified their association with the calling phone number. This applies when the caller is a known customer, the number is provisioned directly through the carrier, and the provider has verified ownership of the number.
Impact: highest trust level, best chance of reaching the recipient, and may display "Verified Caller" or a shield icon.
B-Level (Partial Attestation)
The service provider has authenticated the caller's identity but could NOT verify their authorization to use the number. This applies when the provider knows the caller but cannot verify the relationship with the calling phone number.
Impact: moderate trust level — may be flagged as "Spam Likely" or "Unverified Number," not automatically blocked but subject to stricter scrutiny.
C-Level (Gateway Attestation)
The provider is transiting the call and cannot authenticate the call source. This applies to calls from international gateways, when the provider cannot authenticate call origin, or when the call passes through a non-IP network.
Impact: lowest trust level, highest risk of blocking, often flagged as "Potential Fraud."
Important Clarifications
Attestation is not the same as call blocking or spam identification. Those are separate features within the terminating service provider's network. Different call analytics solutions have different decision-making parameters and may not treat STIR/SHAKEN information the same way.
This means A-level calls aren't guaranteed to be delivered without a "spam" label, and B-level calls shouldn't automatically be blocked or labeled.
The Problem of Improper Attestation
Scammers have exploited a loophole through invalid attestation scams, where calls originating from invalid or spoofed numbers maintain an "A" attestation. Recent findings showed that out of 585,000 calls placed using invalid telephone numbers, 340,000 were signed with an "A" level attestation — many originating from within Tier-1 networks.
This highlights a real limitation of STIR/SHAKEN and underscores the need for stronger call signing and attestation frameworks.
How to Improve Your Attestation Level
For providers: maintain accurate customer records and verify caller ID ownership, implement robust Know Your Customer (KYC) procedures, ensure your certificate is valid and properly configured, and monitor for improper attestation practices.
For enterprises: work with providers who can deliver A-level attestation, ensure your calls are properly configured for STIR/SHAKEN, and consider number reputation management services.
Conclusion
Attestation levels are a critical component of the STIR/SHAKEN framework. While A-level attestation provides the highest trust and best deliverability, even A-level calls aren't guaranteed to avoid spam filters. The key is to work with a compliant provider and maintain good calling practices.
Need help with this?
Our specialists handle the filings discussed in this article end-to-end.
Start Your Application →