Here's something that should worry anyone running inbound call campaigns across multiple states: Virginia, Florida, and Missouri have each introduced their own STIR/SHAKEN and caller ID authentication mandates — and they don't agree with each other.
The federal framework was supposed to be the answer. The FCC mandated STIR/SHAKEN implementation starting in June 2021, established attestation levels (A, B, and C) so providers could cryptographically sign the legitimacy of a call's caller ID, and last September tightened the rules around third-party signing to close a loophole where resellers were outsourcing authentication without actually controlling attestation. The Robocall Mitigation Database recertification deadline of March 1, 2026 just passed. On paper, the system is maturing.
But states aren't waiting for the FCC to finish the job.
Three Bills, Three Different Approaches
Virginia's HB 743 imposes an affirmative "duty of care" on every provider that touches a voice call to or from a Virginia consumer. It requires STIR/SHAKEN on all IP segments and "functionally equivalent" authentication on non-IP segments — without tracking the federal exemption for providers who don't control IP infrastructure. It demands three-year record retention of attestation and traceback data, imposes strict liability (no intent required), and denies any safe harbor for federal compliance. Read that again: being FCC-compliant doesn't protect you in Virginia.
Florida's HB 1299 takes a different tack. By July 2027, every telecom company in the state must either be fully STIR/SHAKEN-verified or running an automated mitigation program, certified to both the FCC and the Florida AG. Civil penalties run up to $250,000 per violation.
Missouri's HB 564 goes criminal. Knowingly using false caller ID is a misdemeanor on first offense and a class E felony on repeat. It also creates a private right of action with punitive damages up to $5,000 per call.
The common thread: states are layering their own technical mandates on top of — and sometimes in conflict with — the federal STIR/SHAKEN framework. For any provider operating across state lines, this means compliance is no longer a single checklist.
What This Means for Call Analytics
If you're in the business of tracking inbound calls and attributing them to marketing campaigns — which is what we do at Dial800 — this matters more than you might think.
STIR/SHAKEN attestation levels directly affect call data quality. A full attestation (Level A) means the originating provider has verified the caller's identity and their right to use that number. Partial attestation (Level B) verifies the origin but not the caller's right to the number. Gateway attestation (Level C) means the provider only knows where the call entered its network. When calls arrive with Level A attestation, your analytics platform can trust the caller ID data. When they arrive with Level B or C — or unsigned — you're working with less reliable data.
Now layer on a patchwork of state-specific authentication requirements. A call originating in Missouri, transiting through Virginia, and terminating in Florida could theoretically need to satisfy three different compliance regimes. If any provider in that chain isn't authenticating to the strictest applicable standard, the attestation metadata that reaches your analytics platform is degraded.
For call tracking specifically, this has practical consequences. Dynamic Number Insertion relies on accurate caller ID data to close the attribution loop. If spoofed or poorly attested calls pollute your dataset, your campaign ROI numbers drift. Worse, if a state mandate causes a carrier to aggressively block calls that don't meet its authentication threshold, you might lose legitimate calls entirely — and never know it.
How Dial800 Handles This
At Dial800, we sit at the intersection of telephony infrastructure and analytics. Our platform processes over 5 billion calls tracked to date across a carrier-grade network with 99.99% uptime. We don't just receive calls — we understand the signaling metadata attached to them.
VoiceInsights AI already analyzes every call for transcription, sentiment, and keyword tagging. But the upstream signal quality matters. We monitor attestation levels on inbound traffic and factor authentication metadata into our routing and analytics pipeline. When a call arrives with full A-level attestation, we can confidently attribute it. When it doesn't, our AI tagging and call scoring systems provide a secondary verification layer — analyzing the actual conversation to determine call quality and intent regardless of what the caller ID claims.
AccuRoute, our advanced routing engine, also plays a role here. Geographic routing rules can be tuned to account for state-specific compliance requirements, ensuring that calls are handled in a way that satisfies the strictest applicable standard in the terminating jurisdiction.
The Bigger Picture
My opinion: the FCC needs to preempt this state patchwork before it becomes unmanageable. Interstate voice traffic is inherently a federal domain. Having fifty different authentication regimes would be like requiring different TLS certificate standards for web traffic depending on which state the server sits in. It's technically absurd and operationally expensive.
But until that happens, businesses and the platforms they rely on need to be paying attention. If you're running multi-state call campaigns and your analytics provider doesn't understand STIR/SHAKEN attestation metadata, you're flying with instruments you can't trust.
The calls are getting more trustworthy. The regulations are getting less so. Plan accordingly.