This post is whimsical. Not to be confused with telecom engineering standards, but the underlying logic is the same as in our social ecology article. Have fun reading it!

Telecom spam filters were supposed to solve a simple problem: stop fraudsters from flooding our phones with garbage calls. Instead, they have produced a surreal outcome: legitimate businesses, fully authenticated and locally registered, see their outbound calls flagged with red spam notices, while fraudulent callers continue to dial with impunity.

This is not a technical failure. It is an ecological filter failure – the same kind we described in dating apps and nightclubs. The filter uses a low‑memory, behaviour‑only heuristic that cannot distinguish the guard dog from the wolf.


The Cast

  • The Legitimate Business: A locally registered company. It has implemented STIR/SHAKEN authentication, a mandatory framework that digitally signs outbound calls. Its caller ID displays the business name. It is contracted with a reputable voice provider.
  • The Fraudulent Spam Caller: Unaffiliated. Spoofs numbers. Rotates through temporary providers. Employs high‑volume, short‑duration call patterns. Has no verifiable identity.

How STIR/SHAKEN Should Work

STIR/SHAKEN gives each call an attestation level:

  • A (Full Attestation): The provider has authenticated the caller and verified they own the number displayed – highest trust.
  • B (Partial Attestation): The provider knows the caller but cannot confirm number ownership.
  • C (Gateway Attestation): The provider merely acts as a gateway; cannot vouch for the caller.

A properly registered business should receive A‑level attestation and sail through the filters. Right?


The Dragnet Failure: The Legitimate Business Catches the Red Notice

In practice, even an A‑attested call from a local business, with caller ID showing the company name, can still be flagged as spam. Industry observers note: “Even with verified caller ID, inconsistent call behaviour can lead to tagging… the system does not know your calls are real. It sees the pattern and applies a label.

Why does this happen?

  • Traffic pattern matching: A sales team using a power dialer generates high call volume, short durations, and low answer rates. Carrier analytics detect this pattern – not intent – and label the number “Spam Likely” regardless of A‑level attestation.
  • Automated power diallers compound the problem. When a business uses a platform like Leaddesk (definitely only licenses the SaaS for legitimate callers) (or any auto‑dialler), the sheer volume explodes. Where a human agent might make 50 calls per hour, an auto‑dialler can push 500 or more, with many abandoned or short‑duration calls as the system cycles through unanswered lines. The filter sees a tsunami of “call, no answer, hang up, next” and flags the number as a spam robot. The legitimate business, trying to reach genuine leads, now looks exactly like a fraud machine. The irony: the dialler was purchased to increase efficiency; it becomes the very evidence used to flag the business.
  • Even an affiliate of the carrier itself – a wholly owned subsidiary selling the carrier’s own products – gets flagged as spam when using the same auto‑dialler. STIR/SHAKEN verifies the affiliate’s identity perfectly (A‑attestation), but the behavioural filter sees the high volume and marks the affiliate’s calls as spam. The carrier flags its own family.
  • User feedback loops: If recipients flag the business’s calls as spam, those complaints feed directly into carrier reputation systems. A handful of complaints on a high‑volume line can trigger a permanent label.
  • Inherited reputation: The phone number may have a damaged reputation from a prior owner. Porting the number can disrupt reputation signals between carriers. The business inherits the sins of strangers.
  • Partial attestation gaps: If the business’s voice provider signs at B rather than A – because they cannot fully verify number ownership – the terminating carrier’s analytics apply reduced trust by default.

The result is absurd: the legitimate business, having invested in authentication, branding, and compliance, sees its outbound calls marked with a red spam notice while the fraud escapes.


How the Fraudulent Caller Escapes

The fraudster operates in a low‑memory environment. They:

  • Rotate through a pool of spoofed numbers, staying just below per‑number detection thresholds.
  • Use providers with weak or no STIR/SHAKEN implementation, ensuring their calls are never associated with a traceable identity.
  • Exploit the fact that carrier analytics have no memory of their past activity across numbers.

Because the dragnet relies on reputation and pattern matching across static numbers, the fraudster’s ephemeral strategy makes them invisible. Victims report spam; the fraudster moves to a fresh number. The legitimate business, meanwhile, remains tethered to its single, traceable, now‑tainted number.


The Ecological Diagnosis

This is not a moral story about “evil fraudsters vs. good businesses.” It is an ecological story about information architecture.

  • Homophily in behaviour: Legitimate cold calls and spam calls look the same – high volume, low reply rate, short duration (McPherson, Smith‑Lovin & Cook, 2001, on behavioural similarity).
  • Low memory: The filter only sees recent activity, not contractual status, training records, or long‑term reputation. It has no memory of who owns the number (Axelrod & Hamilton, 1981, on the necessity of repeated interaction for cooperation).
  • No mutual observation: The filter does not share data across carriers or across time. The fraud exploits this fragmentation (Ostrom, 1990, on common‑pool resource governance requiring shared information).

The filter punishes the visible, consistent actor and rewards the ephemeral, deceptive one. The legitimate business is the guard dog on patrol – visible, traceable, accountable. The fraud is the wolf in the feedlot – invisible, ephemeral, unaccountable. The low‑memory heuristic cannot tell them apart.


What Would an Ecological Fix Look Like?

Drawing from the original article’s prescriptions:

  1. Increase memory: Whitelist numbers that belong to contracted, locally registered businesses. Integrate CRM data (“this number is calling leads from our own database, not random numbers”). Use long‑term reputation scores that persist across months.
  2. Restore context: Do not rely on behavioural heuristics alone. Add a feedback loop: if a called party complains, weight that complaint by the complainant’s own history (e.g., chronic complainers get lower weight). This is analogous to “joint patrol” in third places – mutual observation over time.
  3. Cross‑carrier reputation sharing: Fraudsters rotate across carriers. Filters must do the same. A shared ledger of attested numbers and their long‑term behaviour would close the fragmentation gap.
  4. Remove the perverse incentive: Do not penalise businesses for being visible. The current filter is structured so that fraud wins by being invisible, while the legitimate actor loses by being visible. That is a design flaw, not a moral failing.

The Humorous, Ironic Punch

The telecom’s spam filter marks as spam the very number it issued to its own contracted business – especially when that business uses a legitimate auto‑dialler like Leaddesk to reach customers efficiently – while the fraud who has no contract, no training, and no relationship with the company calls with impunity. The system is so low‑memory that it does not recognise its own family.

The same logic applies to dating apps marking genuine users as “bots” while predators swipe freely; to nightclubs that ban awkward young men while charming satellites orbit unbothered; to any environment that replaces memory with crude heuristics.

He he.


Citations (Yes, We Cite)