Robocall Rules, Spoofing, and Why Calls Still Get Through

A call comes in from a number that looks a lot like your own. That resemblance is not a coincidence — it is a technique, and the FCC has a name for it. The rules against it have been on the books for years, and the phone rang anyway.
Federal rules require consent before most robocalls and robotexts, and they ban caller ID falsified with intent to defraud. Carriers must sign and verify caller ID on IP networks. Calls still arrive anyway: the signing system runs only on IP networks, default blocking rests on carriers’ analytics, and a spoofed number is likely to be abandoned within hours.
The Consent the Rules Require
A robocall, in the FCC’s definition, is a phone call made using an autodialer or a prerecorded or artificial voice message. Before a prerecorded telemarketing call reaches a home or wireless number, the caller must have prior written consent — on paper or through electronic means, including a website form or a telephone keypress. For an autodialed or prerecorded call or text to a wireless number, oral or written consent is enough.
Emergency calls about danger to life, safety, or property fall outside these rules. Market research or polling calls, and calls on behalf of tax-exempt non-profit groups, are allowed to landline numbers. So are calls about school closings or flight information.
Consent is not a one-way door. A consumer may opt out of any robocall or robotext at any time and in any reasonable manner, even if consent was given earlier.
Two identification rules sit close together and are easy to blur. A prerecorded telemarketing call must provide an opt-out option at the start of the message. Separately, all prerecorded voice message calls — not only the telemarketing ones — must include the caller’s name, number, and business name at the beginning.
AI-generated voice calls are illegal unless the consumer has agreed to receive them or the caller is exempt. And a telemarketing call resting on an established business relationship is still not permitted to a landline without advance permission.
Political calling has its own carve-outs. Political robocalls, autodialed or prerecorded, are allowed to landlines without prior consent. To a cell phone, political calls, texts, or prerecorded messages require the recipient’s prior permission unless they are sent manually. Autodialed political texts need consent; manually sent ones do not.
Text messages sent to a mobile phone using an autodialer are banned unless the phone’s owner previously consented or the message is sent for emergency purposes. Commercial texts require written consent. For informational texts, consent may be oral.
Consent requirements as stated in the FCC’s robocall and robotext rules
| What consent the rule requires | Lines the source states it applies to |
|---|---|
| Prerecorded telemarketing calls: prior written consent, on paper or electronically, including a website form or a telephone keypress | Home or wireless phone numbers |
| Autodialed or prerecorded calls and texts: oral or written consent | Wireless numbers |
| Political prerecorded calls, autodialed or prerecorded: allowed without prior consent | Landlines |
| Political calls and prerecorded messages: the recipient’s prior permission, unless sent manually | Cell phones |
| Commercial texts: written consent | Mobile phones |
| Informational texts: consent may be oral | Mobile phones |
The Truth in Caller ID Act and Lawful Caller ID Display
Spoofing is when a caller deliberately falsifies the information sent to a caller ID display to disguise their identity. Under the Truth in Caller ID Act, FCC rules prohibit transmitting misleading or inaccurate caller ID information with the intent to defraud, cause harm, or wrongly obtain anything of value. Anyone illegally spoofing can face penalties of up to $10,000 for each violation.
Intent is what splits the two. Spoofing is not always illegal, and the FCC gives its own examples: a doctor calling a patient from her personal mobile phone while displaying the office number, or a business displaying its toll-free call-back number. Blocking the transmission of your own number so it appears as “unknown” is not spoofing either.
Scammers lean on two familiar shapes. Neighbor spoofing displays a number similar to the recipient’s own, which raises the odds the call gets answered. They also spoof a number belonging to a company or a government agency the recipient may already know and trust — the kind of call covered in calls that impersonate a government agency.
The rules also say what a telemarketer’s own caller ID has to show. It must transmit or display its telephone number, or the number on whose behalf the call is being made, and if possible its name or the name of the company whose products or services it is selling. It must also display a telephone number that can be called during regular business hours to ask no longer to be called. That requirement applies even to companies that already have an established business relationship with you.
STIR/SHAKEN and the Authentication Obligation
STIR/SHAKEN is a framework of interconnected standards, and the acronyms unpack as Secure Telephone Identity Revisited and Signature-based Handling of Asserted Information Using toKENs. It lets an originating carrier “sign” a call’s caller ID as legitimate, and lets other carriers validate that signature before the call reaches the person being called. The receiving phone company can verify that a call really is from the number on the display.
In 2020, the FCC adopted rules requiring voice service providers to implement STIR/SHAKEN in the IP portions of their voice networks by June 30, 2021. Since then, the agency has worked to expand that implementation obligation to additional providers.
Gateway providers are named in the rules. The FCC defines them as U.S.-based intermediate providers that receive calls directly from a foreign originating or intermediate provider, and what they are required to do is authenticate the caller ID information for the calls they transmit. Intermediate providers that receive unauthenticated calls directly from originating providers carry the same authentication duty.
Every provider must institute a robocall mitigation program, whether or not it carries a STIR/SHAKEN implementation obligation. Providers file both their compliance certifications and their mitigation plans in the Robocall Mitigation Database, along with the contact for the staff responsible for mitigation issues, the provider’s role in the call chain, and information about any previous or existing robocall-related enforcement actions. Consumers may review those submissions through the public portal.
The Limits Written Into the Framework
The framework is operational only on IP networks. That single technical fact is why Commission rules require providers using older forms of network technology either to upgrade their networks to IP or to actively work on a caller ID authentication solution that runs on non-IP networks. Until that work lands, part of the phone system sits outside the signing scheme.
Blocking sits on a different footing than authentication. The FCC allows phone companies to block robocalls by default based on reasonable analytics, and carriers can also offer white list services that block numbers outside a customer’s contact list. The FCC has encouraged providers who block calls to set up a way for a blocked caller to reach them and fix the problem, and to give consumers information on specific blocked calls plus a way to report a number blocked incorrectly.
Then there are the labels. When a number shows up blocked or tagged “potential scam” or “spam,” the FCC’s page says it is possible that number has been spoofed — the label describes a signal, not a confirmed culprit. Someone whose number is being spoofed may start hearing from strangers returning calls they never made.
The timing favors the scammer. Scammers switch numbers frequently, and the FCC says it is likely that within hours they will no longer be using a given number.
The agency lists disrupting scam calls that originate outside of the United States among its actions. It separately lists mandated blocking of illegal international robocall traffic.
The National Do Not Call Registry and Its Terms
The National Do Not Call Registry is, in the FCC’s own words, a list of landline and wireless phone numbers that legitimate telemarketers agree not to call. The verb is agree.
Registration is free at donotcall.gov or by calling 1-888-382-1222, and it has to be done from the phone number being registered. Telemarketing calls to a home are prohibited before 8 a.m. and after 9 p.m. A do-not-call request made during a call must be honored immediately.
Under FCC rules, a telemarketer calling a home must give its name along with the name, telephone number, and address where its employer or contractor can be reached. Many states also run their own do-not-call lists. The FCC points to a state’s public service commission or consumer protection office as the place that knows whether a given state has one. And the robotext consent rules apply whether or not a mobile number appears on the federal registry.
The gap here is not really a gap in the rules. It runs between the rules and the wiring — one part of the network can sign its own calls, and another part cannot yet.