The 60-second answer
Caller ID attestation is signed by the carrier that originates your call, because attestation is a claim about who owns the number. A bring-your-own-trunk PBX migration leaves your carrier and numbers untouched, so your attestation level does not change. Porting numbers to a new carrier is the move that resets caller reputation.
The fear is reasonable. The risk is misplaced.
Any business that has spent months getting its outbound calls to stop being labelled “Scam Likely” treats the phone system as something to be left alone. That instinct is right about the risk and wrong about where it lives.
Caller identity in modern telephony is a chain of assertions, and each link is made by a specific party. Understanding which party makes which assertion tells you exactly what a PBX migration can and cannot break. The short version: your PBX does not make the assertion that matters.
Who signs what
The framework works like this. When a call originates, the originating network acts as an authentication service: it inserts a signed identity header into the call signalling [1]. The thing it signs is a token — a Personal Assertion Token, or PASSporT — which is cryptographically signed specifically so that the destination can verify the originator's identity claim rather than take it on trust [2].
The SHAKEN extension to that token adds the part everyone actually argues about: a set of levels of confidence in the correctness of the originating identity [3]. Informally:
| Confidence level | What the originating network is saying |
|---|---|
| Full | This is my customer, and I confirmed this number is theirs to use. |
| Partial | This is my customer, but I cannot confirm the number they are displaying. |
| Gateway | I am passing this call through. I do not know the originator. |
Now ask the operative question: which party is in a position to say “I confirmed this number belongs to this customer”? Only the party that assigned the number. Under the Telecommunications Act, the carrier is defined as the person who owns or operates the transmission facility used to provide service [5] — and it is that relationship, between a carrier and the numbers it has assigned to a customer, that makes an ownership claim meaningful. A PBX has no standing to make that claim about itself.
Your PBX writes the calling number into the signalling. Your carrier decides how much confidence to attest to it. Replacing the first does not change the second.
What a BYOT migration touches
| Element | Owned by | Changes in a BYOT migration? |
|---|---|---|
| Number assignment | Your carrier | No |
| Attestation signing | Your carrier | No |
| Signing certificate | Your carrier | No |
| Trunk and route | Your carrier | No |
| Displayed caller name | Receiving carrier's directory lookup | No |
| Third-party spam scoring | Receiving side analytics | No |
| Which extension a call comes from | Your PBX | Yes |
| Which number that extension presents | Your PBX | Yes — configurable |
Only the last two rows move, and both are things you control deliberately. In fact the second-to-last row is where a migration can improve matters, which is the part vendors never mention.
The one real hazard, and how to avoid it
There is a way to damage your caller ID during a PBX migration, and it is worth naming precisely because it is easy to avoid.
A PBX populates the calling party number in outbound signalling [4]. If it is configured to present a number your carrier has not assigned to you — a main line you no longer own, a number belonging to a sister company, a number picked up from an old configuration — your carrier cannot confirm ownership, and the call goes out with a lower confidence level than it would otherwise carry. Repeat that across every outbound call and you have manufactured exactly the problem you were trying to avoid.
The prevention is a checklist item, not an engineering project:
- List every number your carrier has assigned to you.
- List the outbound caller ID configured on each extension, department and call flow.
- Confirm every entry in list two appears in list one.
- Test outbound calls from each department to a mobile on more than one carrier before cutover completes.
Done as part of provisioning, this takes under an hour. Skipped, it is the single most common cause of “our caller ID broke after we changed phone systems”.
What actually gets numbers flagged
Attestation is one input to how a call is treated. It is not the main one. Receiving-side analytics score numbers on behaviour, and the behavioural signals that matter are:
- High volumes of very short outbound calls.
- Calls to numbers that never call back.
- Calls to disconnected or reassigned numbers.
- Recipient complaints and manual spam reports.
- Sudden changes in calling volume from a previously quiet number.
A well-behaved number with a modest attestation level routinely displays cleanly, while a heavily complained-about number with full attestation gets flagged anyway. If your calls are being labelled, the diagnosis usually lies in this list rather than in the signing chain — and no PBX change, in either direction, will fix it.
Where porting is different
This is the distinction the whole article rests on. Porting a number moves its assignment from one carrier to another. Afterwards, the attesting party is a carrier that has just acquired the number, operating under a new certificate, with no history on the receiving side. Reputation attached to the old routing does not automatically follow, and re-establishing a clean profile can take weeks.
Porting is often the right decision for other reasons. But it is a genuinely different risk category from changing call control, and quotes that bundle the two make it hard to see that you are being asked to accept the second risk in order to obtain the first benefit. A bring-your-own-trunk arrangement separates them: numbers, trunk and carrier stay put, and only the routing logic is replaced.
Three questions to put to your carrier
Because attestation stays on the carrier side, the useful diligence before a migration is directed at your carrier rather than at the PBX vendor. Three questions cover it:
- Which numbers are assigned to my account? Ask for the list in writing. This is the authoritative set of numbers you may legitimately present as outbound caller ID, and it is frequently different from the set an old PBX has been configured to use.
- What confidence level do my outbound calls currently carry? Most carriers can tell you, and it is worth having the answer recorded before a migration so that any later change is measurable rather than a matter of impression.
- What is your process if a number gets flagged? Every carrier has one. Knowing the process in advance turns a flagged number from a crisis into a ticket.
None of these questions involve the PBX, which is the point. If a prospective PBX provider offers to “fix your caller ID” as part of a migration, ask precisely what they intend to change. The honest answer is that they can correct which of your own numbers each department presents, and nothing more.
The privacy footnote
One thing that does move with a PBX migration is where call detail records live. Records of who called, when, and for how long are personal information when they identify individuals, and the ten fair information principles governing commercial handling of personal information apply to them [6]. Where those records are stored, how long they are kept, and who can access them should be settled in writing during provisioning rather than discovered later.
Bottom line
Attestation is a carrier function by design, because only the carrier can vouch for number ownership [1][2][3][5]. Keep your carrier and your numbers, and your outbound calls keep the confidence level they already had. The one avoidable hazard is presenting an outbound caller ID your carrier has not assigned to you, which a provisioning audit catches in under an hour. Everything else that flags business numbers is behavioural, and it was there before you changed anything.