Robocall & Caller-ID Enforcement Tracker
Track the FCC enforcement actions and caller ID authentication rules that shape which providers can carry traffic onto U.S. networks. Each entry links the FCC’s own document and explains what it means for your network, since the order itself rarely tells you what to change.
Last checked against the FCC sources on October 1, 2026.
Enforcement timeline
Listed from most recent to oldest, including proposed FCC rules not yet adopted, so you can see what is coming as well as what already applies.
14 providers removed after failing to fix their filings
The Enforcement Bureau removed 14 companies from the Robocall Mitigation Database (Order DA 26-872). All 14 were among the 35 providers ordered on March 24, 2026 (DA 26-282) to cure deficient certifications or show cause, and none of them responded. They cannot re-file without the consent of the Enforcement Bureau and the Wireline Competition Bureau.
- What it means for you
- Providers downstream had two business days to stop accepting traffic directly from these companies, so check the RMD status of your upstream peers every time a removal order issues.
- Primary source
- FCC Order DA 26-872
- Last checked
- October 1, 2026
FCC proposes stricter entry to, and faster removal from, the RMD (FCC 26-49)
The proposal would clarify who must file in the Robocall Mitigation Database, tighten the accuracy and completeness of filings, screen new filers, expedite removals and prevent unauthorized re-entry. Comments are due October 9, 2026 and reply comments November 9, 2026.
- What it means for you
- If it is adopted, an RMD listing gets harder to obtain and quicker to lose. Treat an upstream peer’s RMD status as something that can change at short notice.
- Primary source
- FCC 26-49, full text (PDF)
- Last checked
- October 1, 2026
Providers ordered to block all traffic from SK Teleco LLC
A Final Determination and Removal Order (DA 26-583) found that SK Teleco LLC originated robocalls impersonating Walmart and did not answer 16 traceback requests. Providers immediately downstream must block all of its traffic within 30 days, and because it was also removed from the RMD, every provider had to stop accepting its calls directly within two business days.
- What it means for you
- Two clocks ran at once: two business days for the RMD removal and 30 days for the blocking order. Ignoring tracebacks was enough to get the provider cut off.
- Primary source
- FCC Order DA 26-583
- Last checked
- October 1, 2026
FCC proposes tougher upstream-provider checks and attestation rules (FCC 26-32)
The proposal would set baseline know-your-upstream-provider duties, codify the attestation levels and define improper attestation, and require providers to block unauthenticated SIP calls sent directly to them, except public safety calls. It would also require intermediate providers to authenticate the unauthenticated non-SIP calls they receive. The comment rounds closed on August 10 and September 8, 2026.
- What it means for you
- If it is adopted, blocking unauthenticated SIP calls becomes an ingress rule on your SBC, and per-call attestation becomes a compliance requirement rather than a configuration choice.
- Primary source
- FCC 26-32, full text (PDF)
- Our explainer
- STIR/SHAKEN attestation levels, explained
- Last checked
- October 1, 2026
SIP 603+ becomes the required response for analytics-based blocking
Under FCC 25-15, adopted February 27, 2025, a provider that blocks a call on an IP network based on reasonable analytics must return SIP code 603+ and must stop using the standard SIP 603, 607 or 608 for that purpose. The matching ISUP code remains 21, and every provider in the call path must pass the code back toward the caller.
- What it means for you
- This lands in your SBC configuration. The blocking response, the SIP-to-ISUP mapping and header pass-through all have to carry 603+ intact, and a transit SBC that rewrites or strips the response breaks the caller’s path to redress.
- Primary source
- Federal Register: FCC 25-15 call blocking rules
- Last checked
- October 1, 2026
Providers ordered to block all traffic from Belthrough LLC
The Enforcement Bureau’s Final Determination Order (DA 26-237) requires every provider immediately downstream of Belthrough LLC to block and stop accepting all traffic it receives directly from Belthrough, other than certain emergency traffic, within 48 hours. In effect, Belthrough was cut off from the U.S. network for failing to comply with the FCC’s robocall rules.
- What it means for you
- If you take traffic directly from a provider named in one of these orders, the block is yours to implement, so your SBC’s blocklist has to keep up with EB Docket No. 22-174.
- Primary source
- FCC Final Determination Order DA 26-237
- Last checked
- October 1, 2026
New Robocall Mitigation Database rules take effect (FCC 24-135)
Filers must keep their certifications accurate and current, update them within 10 business days of any change, and recertify every year by March 1, starting March 1, 2026. The order set a base forfeiture of $10,000 for each false or inaccurate filing and $1,000 for failing to update one.
- What it means for you
- Your RMD filing now carries fines of its own, before any removal. A filing that describes controls you no longer run is a liability, so review it whenever your network changes.
- Primary source
- Federal Register: FCC 24-135 RMD rules
- Our explainer
- Robocall mitigation program requirements
- Last checked
- October 1, 2026
Do-not-originate list blocking becomes mandatory
Under FCC 25-15, every domestic voice service provider must block calls that use a number on a reasonable do-not-originate (DNO) list, meaning numbers that should never be used to originate calls.
- What it means for you
- DNO blocking runs on every call, so it belongs in your SBC’s ingress rules next to the mandatory-block list, and someone has to own keeping the list current.
- Primary source
- Federal Register: DNO blocking effective date
- Last checked
- October 1, 2026
12 providers removed for ignoring traceback requests
The Enforcement Bureau removed 12 companies from the Robocall Mitigation Database (Order DA 25-913) because each had failed to respond to one or more traceback requests from the industry traceback consortium, the Industry Traceback Group, contrary to their own certifications.
- What it means for you
- Ignoring a traceback is enough on its own to get you removed. The rules require a full response within 24 hours, counted in business hours, so you need call records you can search quickly.
- Primary source
- FCC Order DA 25-913
- Last checked
- October 1, 2026
Own-certificate rule takes effect (FCC 24-120)
The third-party signing rules from FCC 24-120 took effect. A provider may have a third party sign its calls only if, among other conditions, it makes every attestation-level decision itself, the calls are signed with its own certificate rather than the third party’s, and the agreement is kept in writing for two years after it ends.
- What it means for you
- You can outsource the act of signing, but not the certificate or the attestation decision. If a vendor signs your traffic with its own certificate, that arrangement stopped being compliant on this date.
- Primary source
- Federal Register: Call Authentication Trust Anchor
- Our explainer
- The FCC’s own-certificate rule, explained
- Last checked
- October 1, 2026
1,203 providers removed from the Robocall Mitigation Database
The Enforcement Bureau removed 1,203 voice service providers from the Robocall Mitigation Database (Order DA 25-737) for deficient certifications, effectively disconnecting them from the U.S. phone network. They had been warned earlier in the month, when the first 185 were removed.
- What it means for you
- Removal means providers downstream have to stop accepting your traffic within two business days, which turns a deficient filing into an outage.
- Primary source
- FCC Order DA 25-737
- Last checked
- October 1, 2026
185 providers removed, the final warning to the rest
The Enforcement Bureau removed 185 voice service providers from the Robocall Mitigation Database (Order DA 25-694). All of them had kept deficient certifications after repeated warnings.
- What it means for you
- The sequence is the lesson: warnings, then a first tranche, then mass removal. Providers who treated this action as someone else’s problem were removed 19 days later.
- Primary source
- FCC Order DA 25-694
- Last checked
- October 1, 2026
Eighth Report and Order on caller ID authentication released (FCC 24-120)
The Commission set the rules for providers that rely on third parties to meet their STIR/SHAKEN obligations. The order was adopted on November 21, 2024, released on November 22, 2024, and took effect on September 18, 2025.
- What it means for you
- This is the order that created the own-certificate obligation. If you are evaluating a signing partner, it defines what the arrangement may and may not look like.
- Primary source
- FCC 24-120, full order (PDF)
- Our explainer
- The FCC’s own-certificate rule, explained
- Last checked
- October 1, 2026
Standing obligations
Most of the enforcement actions in the timeline trace back to a lapse in one of these ongoing obligations. For each one, the table shows who it applies to, where your SBC comes in, and the rule behind it.
| Obligation | Who it applies to | What it requires | Where the SBC comes in | Source |
|---|---|---|---|---|
| Robocall Mitigation Database certification | Voice service providers, gateway providers and non-gateway intermediate providers | File and keep an accurate certification describing your robocall mitigation program, recertify every year by March 1, and update the filing within 10 business days of any change. Deficient certifications were the basis for the 185 and 1,203 removals in August 2025. | The plan has to describe your call analytics, your know-your-customer measures and how you vet upstream providers. Much of that runs on the SBC, so the filing should describe controls you actually operate there. | 47 CFR 64.6305 |
| Traceback response | All providers in the call path | Respond fully to traceback requests from the Commission, law enforcement and the industry traceback consortium (currently the Industry Traceback Group) within 24 hours. The clock only runs in business hours. Failing to respond has, by itself, led to removal from the RMD. | You cannot answer a traceback without call records. Keep CDRs and per-call SIP traces long enough to identify the upstream source of a flagged call. | 47 CFR 64.1200(n)(1) |
| STIR/SHAKEN signing with your own certificate | Providers with a STIR/SHAKEN implementation obligation | Every call you are required to authenticate must be signed with a certificate you obtained from a STIR/SHAKEN certificate authority using your own SPC token, and every attestation decision must be yours. If a third party does the signing, keep the written agreement for two years after it ends. | Attestation is a per-call decision. An SBC that can only apply one attestation level per trunk cannot correctly serve mixed retail, wholesale and gateway traffic. To see what a real call was signed with, paste its Identity header into our PASSporT decoder. | 47 CFR 64.6301 |
| Mandatory blocking of named providers | Providers immediately downstream of the named provider | Begin blocking a named provider’s traffic no later than 30 days after the Enforcement Bureau’s Final Determination Order, and check each order for its own deadline: the Belthrough order required it within 48 hours. Separately, once a provider is removed from the RMD you must stop accepting its traffic within two business days, with 911 calls exempt. | Requires a blocklist the SBC enforces at ingress, plus someone watching EB Docket No. 22-174 so entries go in when orders issue. | 47 CFR 64.1200(n)(3) |
| Do-not-originate list blocking | All domestic voice service providers | Block calls that use a number on a reasonable do-not-originate list. | Runs on every call at ingress, so the list has to be loaded into the SBC’s blocking rules and kept current. | Federal Register: FCC 25-15 (DNO) |
| SIP 603+ for analytics-based blocking | Providers that block on reasonable analytics, and every provider in the call path | Return SIP code 603+ (ISUP code 21) when you block a call based on reasonable analytics, and pass the code back toward the caller when you sit in the middle of the path. | The SBC generates the response and handles the SIP-to-ISUP mapping, so check both your blocking responses and your interworking tables. | Federal Register: FCC 25-15 (603+) |
Every entry links a primary source on fcc.gov, docs.fcc.gov, federalregister.gov or ecfr.gov. Trade-press reporting can point us to an action, but it never puts one on this page, and where a detail could not be confirmed in the FCC’s own document we left it out rather than paraphrase around the gap. Each entry shows the date it was last checked against its source, so you can judge for yourself how fresh it is.
This tracker is an operational reference maintained by an SBC vendor, not legal advice. Which obligations apply to you depends on how your company is classified (voice service provider, gateway provider or intermediate provider) and on the traffic you carry, so it’s worth confirming your position with regulatory counsel before acting on anything here.
Most of these obligations land on your SBC
Tracebacks, attestation and mandatory blocks are all handled at the network edge. Tell us about your network and we’ll show you how ProSBC fits your compliance setup.
By submitting this form, your information will be processed in accordance with our Privacy Policy.
Prefer to get hands-on first? Build a free ProSBC lab and test it yourself.