Canada Has STIR/SHAKEN. Your Phone Doesn't Know It.
September 26, 2026 · 6 min read
Canada switched on STIR/SHAKEN on November 30, 2021. Big announcement. Canadians were told spam calls were about to get a lot rarer.
Almost five years later, your phone still lights up with a local number that isn't local, a bank that isn't your bank, and a "CRA agent" who'd like to be paid in gift cards.
So what happened?
We deployed the protocol and skipped everything that makes it work.
What STIR/SHAKEN actually is
Strip away the acronyms. STIR/SHAKEN is a digital signature for phone calls.
When a call starts, the originating carrier signs it with a certificate and vouches for the caller ID. It picks one of three attestation levels. "A" means we know this customer and they're allowed to use this number. "B" means we know the customer but can't vouch for the number. "C" means the call came in from somewhere else and we have no idea. The carrier on the receiving end checks the signature and decides what to do.
That's the whole idea. Accountability through cryptography. If a spoofed call gets through, you can trace it back to whoever signed it.
Good design. It only works if the signature survives the trip and someone acts on it.
The mandate looked great on paper
After more than one extension, the CRTC ordered every Canadian phone company to implement STIR/SHAKEN on its IP-based voice networks by November 30, 2021 (Telecom Decision 2021-123). Before that, carriers had already been required to block calls with obviously bogus caller ID, starting in December 2019.
Canada looked like it was right behind the US. The fine print said otherwise.
Read the mandate again. IP-based networks.
The signature dies at the first legacy handoff
STIR/SHAKEN rides on SIP, the protocol modern voice networks use. The moment a call crosses an older TDM link, the kind of legacy switching still buried in plenty of Canadian interconnects, the signature gets dropped. The receiving carrier sees a call with no token at all. Can't verify it. Can't trace it.
The CRTC knows this. In its 2022 appearance before the House Industry committee, the Commission said the framework "will not be effective on some legacy, non-IP networks" and "will not eliminate all spoofed calls" (CRTC testimony).
Fair enough. So how much Canadian traffic actually makes it end to end with the signature intact?
Nobody will say. When CBC asked in 2023, a CRTC spokesperson couldn't give a percentage. Rogers said most calls were IP-based but offered no numbers. Telus didn't respond.
Eighteen months after the mandate took effect, the regulator couldn't tell a national broadcaster how much of the phone network the mandate covered.
The front door is wide open
Most of the calls hurting Canadians don't start on a Canadian network. They come in from offshore call centres through international gateways and cheap wholesale carriers.
The Canadian carrier receiving that call can only sign it "C." Gateway attestation. The carrier is basically saying it came from somewhere, good luck. A legitimate call routed through a discount long-distance provider gets the same C as a scam shop on the other side of the planet. C tells you almost nothing, and C is exactly where the bad traffic lives.
The scammers don't even need to spoof anymore. Tech analyst Ritesh Kotak told CBC that fraudsters buy legitimate Canadian numbers through apps with "no location verification," adding, "All you really need is a credit card." Buy a real 902 number and the signature checks out fine. The system proves the call came from that number. It never asks whether the person behind the number should have it.
We built authentication without identity. Of course it got gamed.
Signing isn't blocking
STIR/SHAKEN has never blocked a single call. All it does is hand out a grade. Somebody still has to act on it.
In Canada, that somebody has mostly been you. As the CBC piece put it, flagged calls still come through and "it's still up to you to decide whether to pick up." Whether you see any verification indicator at all depends on your carrier and your handset.
The actual blocking in Canada is coming from somewhere else. Bell says its suspicious call detection has blocked or labelled more than 500 million calls since May 2025, roughly 113 million of them blocked outright (MobileSyrup). That's Bell's own AI filtering, built on call patterns and traffic reputation. It isn't the framework the CRTC mandated.
Good for Bell. Bad look for the mandate, when one carrier's in-house tool is doing the job the national framework was sold to do.
Then the regulator stopped counting
In December 2025, the CRTC scrapped the semi-annual STIR/SHAKEN status reports for most carriers (Decision 2025-343). The reasoning: the reports didn't "significantly vary from one report to the next," and filing them was "cumbersome and time-consuming." Going forward, the Commission will send targeted requests for information when it decides it needs them.
The numbers weren't moving, so the regulator stopped collecting them.
Four years of flat numbers usually means something stalled. The same decision says carriers authenticate "the vast majority of their IP-based voice calls." No percentage. Nothing on how many calls actually reach a Canadian handset signed and verified. And there's that phrase again. IP-based.
The Americans added consequences
The US has plenty of robocall problems of its own. I'm not holding it up as a success story. But the FCC does one thing Canada won't. It punishes carriers.
US voice providers have to file in the Robocall Mitigation Database, and carriers are only allowed to accept traffic from providers listed there. In August 2025, the FCC pulled more than 1,200 providers out of that database in a single action (Wiley). Removal means you're effectively cut off from the US phone network.
That's a real stick. Sign garbage, or ignore the rules, and you lose access.
Canada has nothing like it. There's no public registry and no real penalty for a wholesale provider that keeps pushing fraud traffic onto Canadian networks. We copied the protocol and left the enforcement on the shelf.
What it's costing
Canadians reported $704 million in fraud losses to the Canadian Anti-Fraud Centre in 2025, a record (Money.ca). Only an estimated 5 to 10 per cent of victims ever report. Do that math and you're into the billions.
Not all of it starts with a phone call. A lot of it does. Bank impersonation, fake CRA agents, the grandson-in-jail call, the investment "advisor" who rings first and emails second. A phone call is still how a huge share of fraud against Canadians starts, and older Canadians take the worst of it.
Every one of those calls rang through a network that has been STIR/SHAKEN compliant since 2021.
What fixing it looks like
None of this needs new technology. It needs a regulator that wants the thing to work.
Start by publishing the numbers, per carrier and per attestation level, every quarter. If they're embarrassing, good.
Then copy the FCC. Canadian carriers should only take traffic from registered providers in good standing, and the CRTC should pull the ones that aren't, in public.
The legacy gap needs a date. "Networks are evolving to IP" isn't a plan.
Fix number assignment too. If anyone with a credit card can grab a Canadian number from an app, attestation is theatre. Banks have to know their customers. Number resellers should as well.
And show people the result. A consistent verified indicator across carriers would let Canadians use what the network already knows.
Bottom line
STIR/SHAKEN isn't broken. Canada's version of it is unfinished, and the regulator has decided unfinished is good enough.
The CRTC mandated the plumbing and then stopped measuring it. The fraudsters found the gaps a long time ago.
Until a carrier loses its network access for carrying fraud traffic, nothing changes. Your phone is going to keep ringing.
Next Step
Ready to strengthen your organization's resilience?
A 30-minute discovery call to discuss your cybersecurity posture, incident readiness, and whether advisory support is the right fit.