In May 2026, 97.4% of the calls signed by the ten most prolific robocall signers on the network carried full A-level attestation. Not B. Not gateway-level C. The top attestation grade the framework offers, on almost every call, from the providers whose signed traffic is most likely to be a robocall.
If your call platform surfaces attestation as a green badge and calls it done, you have built a trust indicator that the least trustworthy traffic on the network passes with ease.
What attestation actually claims
The A/B/C levels are not a scale of how legitimate a call is. They describe what the originating service provider is willing to assert about its own relationship to the call. A means the provider authenticated the customer and verified that customer's right to use the calling number. B means it authenticated the customer but can't vouch for the number. C — gateway attestation — means it's passing along a call it can't authenticate at all.
Read that again: A-level attestation is a claim about a provider's onboarding paperwork, not about the caller's intent. A provider that signs up a bad actor with clean documentation will hand that actor A-level signatures all day, and the signature will verify correctly at every hop. STIR/SHAKEN was designed to stop spoofing — to make caller ID hard to forge and easy to trace. It was never designed to score intent, and it doesn't. Treating it as a fraud score is a category error, and it's the single most common mistake I see in how inbound platforms present this data.
The coverage problem is worse than the semantics problem
TransNexus, which measures signed traffic across hundreds of voice service providers, put signed calls at termination at 45.6% in May 2026 — up 3.2% month over month, which is real progress, and still means the majority of calls arrive at the terminating network with no signature at all. Of the calls that were signed, 29.8% carried A, 3.5% carried B, and 7.1% carried C.
So the practical distribution of your inbound attestation field is roughly: unsigned most of the time, A when signed, B almost never. That's a low-cardinality feature with more than half its values missing — and critically, the missingness is not random. Whether a call arrives signed correlates strongly with which carrier the caller uses. Tier-1 wireless networks sign the overwhelming majority of their traffic; smaller regional carriers, some prepaid wireless, and long-tail VoIP originators lag badly.
Filter or deprioritize inbound calls on weak attestation and you are not filtering fraud. You are filtering carrier, which in practice means filtering by the economics of your caller's phone plan. That's a demographic filter wearing a compliance costume, and if you're spending money to make those phones ring, you are throwing away leads you already paid for.
Three ways to use the field honestly
As a data-quality flag, not a gate. Attestation tells you how much confidence to place in the calling number as an identifier. Unsigned or C-attested calls have a weaker ANI, which matters enormously downstream: repeat-caller deduplication windows, CRM record matching, and household-level source attribution all key off that number. Annotate the record with attestation and your analytics knows which joins to trust. Silently treating a gateway-attested ANI as ground truth is how duplicate customers and phantom repeat callers get into a database.
As one feature among many, never the rule. Attestation belongs in a scored model alongside signals that actually reflect behavior — call duration, conversation outcome, whether the caller ever appears in a transcript asking a real question. Combine attestation with what happened on the call and it earns its place. Alone, it predicts almost nothing.
As a longitudinal media-quality signal. This is the use almost nobody exploits. Track the attestation distribution per tracking number and per campaign over time. A lead source whose inbound calls shift from mostly-A to 40% C-attested over three weeks is telling you something about the buy — traffic sourced through a different aggregator, a different origination path, possibly a different kind of caller entirely. That's a media conversation, not a security conversation, and it's invisible unless attestation lives on the same call record as campaign data.
The FCC is about to make this your problem
In June 2026 the Commission adopted an FNPRM that would codify the A/B/C framework in the rules, establish five mandatory know-your-upstream-provider baseline categories, expand vetting for Service Provider Code tokens, add penalties for improper attestations, and push toward blocking unauthenticated SIP calls at all points in the call path. One proposal deserves specific attention from anyone reading this: it would require retail voice service providers to determine attestation levels for SIP calls, and the item explicitly names resellers and contact center service platforms among the affected parties.
If that lands, attestation stops being a field you passively observe and becomes one you are accountable for assigning. Platforms that never plumbed it into their data model will be retrofitting under a deadline.
Where this fits at Dial800
Our position is straightforward: attestation is call metadata, and call metadata belongs on the call record next to everything else — source, campaign, keyword, routing decisions, transcript, sentiment, outcome. One system, one call record. When authentication data and attribution data live in the same row, the questions above are queries rather than integration projects.
The nuance we won't paper over: we don't recommend using attestation as a standalone basis for rejecting inbound calls, and any vendor who sells you that as a fraud product is selling you a lead-loss machine. With 54% of traffic still arriving unsigned, the honest engineering answer is to record it, join carefully around it, monitor its distribution, and let behavior do the actual scoring. That's the same posture we take across the rest of the security and privacy surface: concrete controls and auditable records, not badges.
Here's the test for your own stack. Pull last month's calls, group by attestation level, and look at close rate. If the A-attested cohort doesn't convert measurably better than the unsigned cohort — and on most inbound books it won't — then whatever your platform is doing with that badge, it isn't analytics.