DEV Community

Tahir Almas
Tahir Almas

Posted on • Originally published at ictbroadcast.com

Your Upstream Carrier Just Became Your Problem: The FCC's Next Robocall Move

Originally published at ictbroadcast.com

The FCC's robocall strategy has quietly changed shape. Instead of chasing the people placing bad calls, it is putting pressure on the providers who carry them, and asking those providers to look at whoever handed them the traffic in the first place. If you run outbound campaigns on your own call center software, that shift reaches you through your carrier, not through a new rule aimed at you.

Reply comments on the numbering proceeding closed on 7 July 2026, so this is live policy rather than speculation. The direction is clear enough to plan around even before the final text lands.

What the FCC is proposing

The core idea is that a voice service provider should know the upstream providers it accepts traffic from, in a specific and documented way. The proposal spells out what that looks like: confirm the upstream provider has a filing in the Robocall Mitigation Database, actually read that filing and its mitigation plan for completeness, confirm the provider holds a Service Provider Code token where it claims full or partial STIR/SHAKEN implementation, and check whether the provider appears on certain national security or enforcement related lists.

Read that list again and notice what it is not. It is not a technical standard. It is a due diligence obligation, closer to what a bank does before opening an account than anything in a SIP specification.

Signing your own traffic was the old bar. Vetting who hands you traffic is the new one.

Why this reaches your call center software even though it targets carriers

Most outbound teams read "provider obligation" and assume it is somebody else's paperwork. That assumption held for a few years. It is getting weaker.

Carriers that are told to vet upstream sources will pass that scrutiny down, because the cheapest way to satisfy a regulator is to tighten who you accept. Wholesale voice is a chain, and every link that gets squeezed squeezes the next one. In practice that means the questions on your next carrier onboarding form get longer, and the tolerance for vague answers gets shorter.

The other reason it reaches you is that the Commission has been willing to cut providers off entirely rather than fine them. Losing a route with no notice is an operational problem, not a legal one, and no compliance budget fixes a dialer that suddenly cannot complete calls. If your campaigns run through a single upstream, that is concentration risk you can measure today.

Teams running a self-hosted stack have a real advantage here, because the call detail records and campaign logs sit on hardware you control. Producing six months of evidence is a query rather than a support ticket. That is not a small thing when someone asks you to prove what you sent and when.

The four checks, and the part people skip

If you resell, aggregate, or hand traffic to anyone downstream of you, the four checks below are the ones the proposal describes. Even if you only buy termination and never sell it, running them on your own carrier is a reasonable way to judge whether that carrier is about to have a bad year.

Four checks, four artefacts. The artefact is the half people forget.

The part people skip is the evidence. Checking the Robocall Mitigation Database takes two minutes and leaves no trace unless you deliberately keep one. A dated screenshot and a three line review note, filed somewhere you can find it in eighteen months, is the difference between having done the work and being able to show it. I would treat that filing habit as the actual deliverable here.

One honest caveat: none of this is a substitute for the consent and suppression work you already owe. Vetting your carrier does nothing for a campaign calling numbers it should not. Our guide to autodialer laws and regulations covers that side, and it has not become less important.

What to do in the next month

Start by writing down which upstream providers your traffic actually touches. A surprising number of operators cannot answer that quickly, especially where a reseller sits in the middle. You cannot vet a chain you have not drawn.

Then check your own filing. If you appear in the Robocall Mitigation Database, reread what you filed. Plans written two or three years ago often describe a system that no longer matches how the business runs, and an out of date plan reads worse than a modest one that is accurate.

After that, look at attestation levels on your own outbound. If your calls are going out with anything less than full attestation, find out why. Sometimes the answer is a number the carrier does not believe you own, which is fixable in an afternoon and quietly costs you answer rate every day it stays broken.

Finally, add a second termination route if you only have one. Not because your current carrier is doing anything wrong, but because enforcement in this area is fast and does not care about your campaign calendar.

Where this is heading

My read is that STIR/SHAKEN has stopped being a caller ID feature and become the paperwork trail for an accountability regime. The signature was never the point on its own. The point is that a signature ties a call to a provider, and a provider to a filing, and a filing to a name somebody can act against.

For legitimate outbound operations that is mostly good news, because the traffic it squeezes is the traffic that has been degrading answer rates for everyone. The cost is a bit more diligence and a lot more record keeping. That is a trade most serious teams should take, and the ones who set up the record keeping early will find the next rule change much less disruptive than the ones who wait for a carrier to demand it.

Frequently asked questions

Does this apply to me if I am not a carrier?

The obligations described in the proposal sit with voice service providers. If you only originate your own campaigns, you are not the direct target, but your carrier's new diligence will show up as tougher onboarding and faster disconnection for accounts that look risky.

What is the Robocall Mitigation Database in plain terms?

It is the FCC's public register where providers state how far they have implemented caller ID authentication and describe the steps they take to prevent illegal robocalls on their networks. Anyone can look up an entry, which is what makes it usable as a vetting tool.

What is a Service Provider Code token?

It is the credential a provider needs in order to sign calls under STIR/SHAKEN. Claiming implementation without holding one is exactly the mismatch the FCC wants downstream providers to catch, which is why confirming the token appears as a separate check.

Will full attestation stop my calls being labelled as spam?

Not by itself. Attestation tells the terminating carrier who vouched for the call, but analytics engines also weigh complaint rates, call duration patterns and how many numbers you rotate through. Good attestation with bad calling behaviour still gets labelled.

How long should I keep vetting records?

Longer than feels necessary. Investigations look backwards, and the useful answer is usually about a relationship that ended a year ago. Keeping dated evidence for the life of the relationship plus a couple of years is a sane default.

Related resources

Compliance gets easier when the records live on your own server instead of a vendor's. ICTBroadcast is an Asterisk based auto dialer you host yourself, with campaign and call detail data you can query directly. Have a look at the available editions if you are weighing a move off a hosted platform.

Top comments (0)