Not every robocall is illegal. Schools, pharmacies, and fraud alerts use prerecorded or autodialed calls with consent or statutory exceptions. Illegal robocalls combine unsolicited marketing or fraud with spoofed caller ID and high-volume origination. The FCC's anti-robocall architecture for providers is separate from a business's TCPA compliance, though they meet on outbound trunks.
FCC robocall mitigation database
Voice service providers that originate, terminate, or otherwise carry U.S. calls must register in the FCC's Robocall Mitigation Database (RMD) and certify either that they have implemented STIR/SHAKEN on their IP networks or that they have a robocall mitigation plan (or both, as the rules require for their role). Intermediate providers face related duties. Downstream providers are restricted from accepting traffic from providers that should be in the database and are not. The RMD is a know-your-upstream-provider control, not a consumer complaint form.
| Control | Who it binds | What it does |
|---|---|---|
| RMD registration and certification | Voice service providers and certain intermediate providers | Public listing plus a mitigation-plan or STIR/SHAKEN certification. Missing or deficient filings can isolate a provider from the rest of the network. |
| STIR/SHAKEN mandate | IP-based voice service providers (with extensions and deadlines the FCC has updated for smaller and non-IP networks) | Sign originating traffic and verify terminating traffic where technically feasible. |
| Traceback cooperation | Providers in the call path | Respond to traceback requests (Industry Traceback Group and FCC) so illegal traffic can be found at the origin, not only at the last hop. |
| Analytics blocking | Terminating providers and some analytics vendors | Label or block likely-illegal or likely-unwanted calls based on volume, invalid numbers, unsigned traffic, consumer reports, and similar signals. |
Traceback
Traceback starts at the terminating network that received the complaint and walks each prior hop: who sent this call, from which trunk, at what time. The Industry Traceback Group (ITG), operated with USTelecom, coordinates many of these requests. STIR/SHAKEN origination identifiers and signing certificates shorten the search when the Identity header survived the path. TDM conversion still forces providers to use CDRs and trunk IDs. Knowingly continuing to accept traffic from a source that will not cooperate with traceback is how intermediate providers end up in FCC enforcement actions.
Analytics blocking and labeling
Terminating carriers and third-party analytics (Hiya, First Orion, TNS, and carrier-internal models, among others) score calls. Outcomes range from unlabeled delivery to a "Spam Likely" label to blocking. Inputs include call rate from a number, invalid or unallocated calling numbers, attestation level, consumer DNC-style feedback, and campaign patterns. Legitimate outbound call centers can be labeled if they burst from a small number pool, present numbers they do not own, or skip A-level signing. Number reputation is not a TCPA defense and not a STIR/SHAKEN substitute.
STIR/SHAKEN mandate for voice service providers
The Pallone-Thune TRACED Act (2019) directed the FCC to require STIR/SHAKEN in the IP portions of voice networks. The Commission has since expanded related duties (gateway providers, non-IP caller-ID authentication workarounds, and stricter RMD enforcement). End-user businesses are not "voice service providers" merely because they run a PBX. The mandate still affects them: unsigned or poorly attested outbound traffic is more likely to be labeled. The signer is the originating provider behind the SIP trunk or CPaaS platform.
Lawful high-volume calling vs illegal robocalls
- Consent and DNC: see TCPA. Carrier mitigation does not grant consent.
- Identity: present numbers you are authorized to use. See caller ID spoofing.
- Signing: confirm attestation with the originating provider.
- Complaint handling: a published callback number and a working opt-out reduce both TCPA risk and analytics damage.
Consumers vs providers
- Consumers
- Report illegal calls to the FCC. Blocking apps and carrier spam filters are analytics, and they produce false positives.
- Enterprises
- Watch outbound reputation, attestation, and consent records. Inbound illegal robocalls to a business DID are a terminating-provider and screening issue.
- Providers
- RMD, STIR/SHAKEN, traceback, and (if they terminate) analytics policy.