Every call that crosses a US IP network now carries — or is conspicuously missing — an Identity header. Inside it sits a single letter of attestation: A, B, or C. Because that letter increasingly influences whether a call is delivered with a verified indicator, sent silently to voicemail, or blocked, it is tempting to treat it as a trust score handed down about the call. It is not. Attestation is a precise, narrow statement about what the signing provider knew at the exact moment it signed. Read it that way and it stops being a mystery and becomes one of the most useful diagnostics in wholesale voice.
The three levels, precisely
Under the STIR/SHAKEN framework, the originating provider chooses an attestation level based on what it can genuinely assert about the call. The distinctions are specific.
- Full attestation (A): the provider authenticated the customer originating the call and confirmed that customer has the right to use the calling number. This is the strongest assertion — the provider is standing behind both who is calling and the number they are calling from.
- Partial attestation (B): the provider authenticated the customer, but cannot confirm that the customer is authorised to use the specific calling number. The provider knows who its customer is; it cannot vouch for the number.
- Gateway attestation (C): the provider is passing along a call it received from another network and can only vouch for the point at which the call entered. It is not asserting anything about the original caller or number.
Why the distinction matters commercially
Attestation is not a compliance formality that lives in a header and never affects anything. Terminating carriers and the analytics partners they rely on use attestation, alongside calling patterns and reputation data, as an input to delivery decisions. A steady stream of fully-attested traffic from a known, verified originator earns the benefit of the doubt. A wall of gateway-attested traffic of unknown provenance does not. Over time, as analytics systems learn, that difference compounds into measurably different answer rates.
This is why attestation should be read as a signal, not a verdict. A block of C-attested traffic from an upstream is not automatically illegitimate — gateway attestation is exactly correct for genuine transit traffic — but it is a fact worth knowing, worth documenting, and worth watching. Attestation tells you how much the network upstream of you was able to assert, which is precisely the information you need when something goes wrong.
Reading attestation as a diagnostic
When a trouble ticket lands — a customer disputing a call, a traceback request, a number getting flagged — the attestation captured on the call record is often the fastest way to reconstruct what happened. It tells you whether the call was signed, at what level, and by whom. Combined with the origination ID and the originating OCN, it lets you trace a specific call back to the customer of record rather than guessing. The difference between having that data and not having it is frequently the difference between a same-day answer and a week of back-and-forth email.
This is why serious platforms capture attestation on every call detail record rather than treating it as ephemeral header data. Attestation level, origination ID, originating telephone number, and originating OCN, recorded per call, turn STIR/SHAKEN from a box-ticking obligation into an investigative tool.
The 2025 rule change worth remembering
One development gives attestation extra weight. As of the FCC Eighth Report and Order on call authentication, the loose third-party signing practices that once let calls be signed with an unaffiliated provider certificate are prohibited. A provider with the signing obligation must make the attestation decision itself and, where it outsources the technical act of signing, the vendor must use the provider own certificate and follow the provider own attestation decisions. In practice that means an attestation level is now a more honest reflection of what the responsible provider actually knows — which makes reading it correctly more valuable, not less.
The practical takeaway
Do not treat attestation as a grade on the call. Treat it as a statement about the knowledge of the network that signed it, and use it accordingly: as a routing signal, as a fraud and quality indicator, and as the first thing you reach for when you need to reconstruct what happened to a specific call. On Hadlo’s network, attestation level, origination ID, and originating OCN are captured on every CDR, so when a question arises we can answer it from the record rather than from memory. If traceability and clean, verified originators matter to your traffic, talk to us.