Reference

Outbound Calling Trust: The Two-Layer Voice Model

A business cannot sign its own calls. Voice trust is built in two layers — STIR/SHAKEN authentication and a commercial analytics/branding layer — and four concrete moves get you answered.

reference Last verified mid-2026 3 min read

US outbound voice trust has two distinct layers, and they are run by completely different parties. Confusing them is the most common reason brands waste money in the wrong place.

The first layer is regulatory and cryptographic: STIR/SHAKEN caller-ID authentication, FCC-mandated, where your voice provider signs each call so the destination carrier can confirm the number wasn’t spoofed. The second layer is commercial: a small set of private analytics engines (Hiya, TNS, First Orion) that score your reputation, decide whether the handset shows “Spam Likely,” and power branded calling.

The core constraint
You cannot sign your own calls and you cannot self-assign your own trust grade. Both layers are controlled by your provider and the carriers. Your job is to feed those systems clean signals — correct number ownership, registered identity, healthy dialing behavior — so they grade you favorably.

Layer 1 — STIR/SHAKEN authentication (regulatory)

Your originating provider’s authentication service stamps each call with a signed PASSporT (a JWT inside the SIP Identity header) carrying an attestation grade — A, B, or C. The terminating carrier verifies the signature against the certificate chain. This is the cryptographic backbone; it proves the call is what it claims to be, but it does not by itself decide whether the handset rings clean.

Every voice, intermediate, and gateway provider in the path must be filed (and annually recertified) in the FCC Robocall Mitigation Database . That is a provider-side obligation, but it matters to you: if your provider falls out of the RMD, its downstream carriers block all its traffic — including yours.

Layer 2 — Analytics and branding (commercial)

The three analytics engines — one per major carrier — independently score every calling number on volume, redial patterns, answer rates, call duration, and consumer complaints. A bad score gets you a “Spam Likely” label even if your STIR/SHAKEN is perfect. The fix is the same set of engines: register your numbers, keep your dialing clean, and remediate false labels. On top of that sits branded calling (RCD / BCID ), which displays a verified name, logo, and call reason on the handset — the strongest answer-rate lever available.

The four moves

Getting answered is four concrete moves, in roughly this priority order:

#MoveLayerPage
1Earn A-level attestation from your voice providerAuthenticationGet A-level attestation
2Stay covered by RMD compliance at the provider levelAuthenticationRobocall Mitigation Database
3Register numbers free at the Free Caller Registry and fight false spam labelsAnalyticsSpam-label remediation
4Adopt branded calling (BCID/RCD) to display name + logo + reasonBrandingBranded calling (BCID/RCD)

The legacy CNAM text-name lookup is a baseline, not a strategy — keep it accurate, but understand that branded calling supersedes it. See CNAM.

How the pieces fit

Your call
 └── Layer 1: STIR/SHAKEN  → provider signs → A/B/C attestation in the PASSporT
 └── Layer 2: Analytics    → Hiya / TNS / First Orion score → "Spam Likely" or clean
 └── Branding (optional)   → RCD/BCID → verified name + logo + reason on the handset

The mental model: authentication gets your call trusted as genuine, analytics decides whether it looks like spam, and branding makes people want to pick up. A high-volume outbound program needs all three.

Where to start

Next: STIR/SHAKEN and attestation →

Sources