The Robocall Mitigation Database (RMD)
The RMD is the FCC database where every voice, intermediate, and gateway provider certifies its robocall mitigation. It's provider-side — but a provider falling out of it gets your traffic blocked. Annual recertification is due Mar 1, 2026.
The Robocall Mitigation Database (RMD) is the FCC’s registry where every voice provider certifies how it fights illegal robocalls. Providers that fully implement STIR/SHAKEN attest to that; providers that can’t must file a robocall mitigation plan describing their controls. Either way, being in the RMD — and staying in it — is a precondition for having your traffic accepted across the network.
This is a provider-side obligation. You, the brand, don’t file. But it belongs in your voice-trust playbook because your provider’s RMD standing directly determines whether your calls get delivered at all.
What the RMD is and who must file
STIR/SHAKEN is FCC-mandated on IP networks. To enforce it, the FCC requires that all voice, intermediate, and gateway providers be filed in the RMD — including MVNOs. The certification covers their authentication status and mitigation practices, and downstream providers are prohibited from accepting traffic from any provider not listed in the database.
| Provider type | Obligation |
|---|---|
| Voice providers (originating) | File certification + mitigation status |
| Intermediate providers | File certification |
| Gateway providers (foreign-originated traffic) | File certification; must authenticate |
| MVNOs | Must file / recertify |
Annual recertification
The RMD now requires annual recertification — not a one-and-done filing. Every voice, intermediate, and gateway provider (including MVNOs) must reconfirm its information each year.
The recertification requirement was formalized through the FCC’s CORES registration-system rule (Federal Register, Jan 6, 2026). Related: new third-party caller-ID authentication obligations took effect Sept 18, 2025, broadening who must authenticate — see STIR/SHAKEN and attestation.
What non-compliance costs
The consequences of a bad or missing filing are severe and they cascade downstream:
- Removal from the RMD → downstream providers must block 100% of the removed filer’s traffic. This is the part that reaches you: if your provider is removed, your calls stop.
- Forfeitures of roughly $10,000 base per false or inaccurate submission.
The August 2025 enforcement
The FCC’s 2025 cleanup made the stakes concrete. In August 2025, the FCC revoked RMD certification for 185 providers and then 1,200+ more — roughly 1,400 total — the most aggressive RMD enforcement to date. In parallel, 51 state attorneys general launched “Operation Robocall Roundup,” warning 37 voice providers.
This sits alongside the broader traceback regime run by the ITG (Industry Traceback Group) — the USTelecom-led, FCC-designated Traceback Consortium under the TRACED Act — whose live-call identifications jumped from 607 (2023) to 1,408 (2024). The direction of travel is unambiguous: more enforcement, faster removals, lower tolerance for providers that don’t keep their filings clean.
Why it matters to a brand
You don’t file in the RMD, but you depend on it completely. The practical actions for a brand:
- Vet your provider’s RMD standing before signing — is it filed and currently certified?
- Confirm annual recertification each year, around the March 1 deadline.
- Factor RMD risk into provider choice — a provider that gets removed takes your delivery down with it.
It’s the quiet foundation under everything else in the voice-trust stack: A-level attestation, clean analytics reputation, and branded calling all assume your traffic is being accepted in the first place, and the RMD is what makes that true.
Next: back to the calling overview or run the outbound calling trust checklist.