eTollFree is fully compliant with the FCC’s Know Your Customer requirements, the TRACED Act, and STIR/SHAKEN caller ID authentication standards — protecting your business and the public from illegal robocalls and phone fraud.
The FCC mandates that all telecommunications carriers implement Know Your Customer practices as part of their legally required Robocall Mitigation Programs. Here is what that means for us — and for you.
We are required to verify the identity of every customer before providing voice services. This includes confirming business registration, authorized contacts, and legitimate intended use cases for telephone services.
KYC rules require carriers to take affirmative steps to prevent their networks from being used for illegal robocalling, caller ID spoofing, telemarketing violations, and other fraudulent activities prohibited by federal law.
Under the TRACED Act, carriers must respond to FCC-authorized traceback requests within 24 hours, providing call origin records to help investigators identify the source of illegal robocall campaigns.
Every voice carrier must file a formal Robocall Mitigation Program with the FCC detailing how they implement STIR/SHAKEN and what additional steps they take to prevent illegal calls originating from their network.
FCC rules allow — and in some cases require — downstream carriers to block calls from providers not registered in the Robocall Mitigation Database. KYC compliance protects your calls from being blocked.
Carriers must maintain detailed records of customer onboarding, identity verification, and any violations detected. These records are subject to FCC audit and must be retained for a minimum of two years.
STIR/SHAKEN is the FCC-mandated system that lets phone carriers prove a call really came from the number it claims. Every outbound call gets a digital signature; the carrier on the other end checks that signature before deciding how much to trust the caller ID it shows your customer.
The names are unhelpfully technical — Secure Telephone Identity Revisited, and Signature-Based Handling of Asserted Information Using toKENs — but the idea is simple. It is a passport check for phone calls, run automatically between carriers in the fraction of a second before the phone rings.
How it works, in four steps: your provider verifies who you are (that is the KYC part) → when you place a call, they attach a signed token saying how confident they are in your right to use that number → the receiving carrier validates the signature → the recipient's phone shows the call as verified, unverified, or possible spam.
That third-party confidence level is called attestation, and it comes in three grades. Which one your calls carry is decided almost entirely by how thoroughly your provider has verified you — which is why the registration form on this page matters to whether your calls get answered.
eTollFree holds a valid STI (Secure Telephone Identity) certificate issued by an FCC-approved Certificate Authority, and we are registered in the publicly accessible FCC Robocall Mitigation Database.
eTollFree holds a valid STI (Secure Telephone Identity) certificate issued by an FCC-approved Certificate Authority, and we are registered in the publicly accessible FCC Robocall Mitigation Database.
Want help getting registered, or want your business calls to show as verified? Request a callback and we'll walk you through it.
We have verified the customer’s identity and confirmed they are authorized to use the originating telephone number. Highest trust level. Most calls from verified eTollFree customers carry A-level attestation.
We have authenticated the call originator on our network but cannot fully verify the customer’s right to use the specific number presented. Typically applies during number porting transitions or indirect routing scenarios.
The call entered our network from an upstream provider and we are acting as a gateway. We can authenticate the point of entry but cannot verify the original caller. We flag these calls appropriately and report suspicious patterns.
Every eTollFree customer goes through a structured verification process before full service activation. Here is how we fulfill our FCC obligations while keeping onboarding fast and friction-free.
We collect and verify the legal name, business registration, and authorized contact information for every account. Business accounts require EIN verification or equivalent documentation.
We review your intended use of telephone services to confirm it is lawful and consistent with FCC regulations. Outbound calling campaigns, auto-dialers, and IVR systems receive additional review.
We verify that each telephone number assigned to your account is properly authorized for your use case. This is what allows us to grant the highest STIR/SHAKEN attestation (A-level) on your outbound calls.
We continuously monitor traffic patterns for unusual call volumes, spoofing indicators, and TCPA violation patterns. Anomalies trigger immediate account review and, if needed, service suspension pending investigation.
The Robocall Mitigation Database (RMD) is the FCC's public register of voice service providers and the steps each one takes to keep illegal robocalls off its network. Every provider files a certification describing its robocall mitigation program and its STIR/SHAKEN status, and anyone can look up any provider in it.
It exists because of the TRACED Act, and it has real teeth: carriers are required to check the database before accepting traffic from another provider. A provider that is not listed — or that is removed — finds its calls refused across the network rather than merely flagged.
Voice service providers — the companies that originate, carry or terminate calls. Ordinary businesses that simply make calls do not file their own RMD entry; what matters to you is that the provider carrying your calls is properly registered, because their standing determines whether your traffic is accepted downstream.
It gets blocked. Downstream carriers must refuse calls from providers absent from the database, so an unregistered or delisted provider's customers can lose the ability to complete calls with little warning — a genuine business-continuity risk that has nothing to do with anything those customers did.
Our Robocall Mitigation Program has been filed with the Federal Communications Commission and is publicly accessible in the FCC Robocall Mitigation Database. This registration is required for all voice service providers under the TRACED Act and confirms our commitment to full STIR/SHAKEN implementation and ongoing call authentication. Downstream carriers are required to check this database before accepting traffic from any provider.
Want help getting registered, or want your business calls to show as verified? Request a callback and we'll walk you through it.
A checkmark — or wording like "Verified by carrier" — means the receiving carrier checked the call's STIR/SHAKEN signature and it passed at the highest attestation level. The carrier is telling the person you are calling: this number really is who it says it is.
It is not a rating of your business, and no one sells it as a badge. It is the visible end of the chain described above: your provider verified your identity and your right to use the number, signed the call A-level, and the receiving network validated that signature.
Three things decide it: the attestation level your provider signs with (A, B or C), whether the receiving carrier displays verification at all — handset and network support still varies — and whether the number is genuinely registered to you. Numbers used through an unverified account, or mid-port, commonly drop to B-level, and the checkmark disappears.
Completing KYC is what moves your calls to A-level attestation here, which is the part you control. If your problem is different — your number already being labelled "Spam Likely" or "Scam Likely" and needing remediation — that is a separate job, covered on our caller ID reputation page.
Want help getting registered, or want your business calls to show as verified? Request a callback and we'll walk you through it.
Verifying you is what puts A-level attestation on your calls — verified, rather than suspected spam.
Answers to the most common questions about FCC Know Your Customer requirements, STIR/SHAKEN call authentication, and how eTollFree maintains compliance.
Still have a question about registration or caller ID? Request a callback and we'll walk you through it — or start the form above and we'll pick it up from there.
Our compliance team is available to answer questions about FCC requirements, STIR/SHAKEN implementation, or your KYC registration status.