LineShield - caller ID reputation for insurance agents
← Back to The Shield
Regulation·July 20, 2026·Insurance Dudes Research Team

FCC KYUP Rules: What Insurance Agency Dialers Need to Know

The FCC's May 2026 KYUP rule reshapes STIR/SHAKEN attestation for outbound dialers. Insurance agencies need A-level attestation to avoid rising spam flags.

Short answer
The FCC's Know Your Upstream Provider rulemaking, adopted May 20, 2026, tightens STIR/SHAKEN attestation across the call path. For insurance agency owners running outbound dialers, calls that cannot trace a verified customer relationship through the provider chain drop to partial or gateway attestation. Carrier analytics engines treat lower attestation as elevated risk.
Vintage telecom console showing attestation routes with cyan A-level and coral-red flagged paths.

Every insurance agency owner I talk to asks the same question: why are my calls still getting flagged as spam when I have done everything right? You registered your CNAM, you scrub against the DNC, you warm your numbers. And yet the "Spam Likely" label keeps showing up.

The answer, as of May 20, 2026, just gained a new regulatory layer. The FCC adopted a Further Notice of Proposed Rulemaking that rewrites the accountability structure for every voice provider in the United States call path. The rulemaking is called Know Your Upstream Provider, or KYUP, and it directly affects the STIR/SHAKEN attestation level your outbound calls carry. Lower attestation means higher suspicion. Higher suspicion means more calls blocked or labeled before your producer ever hears a ring.

TL;DR

The FCC's KYUP FNPRM, adopted May 20, 2026, proposes to require every downstream voice provider to verify the identity and compliance practices of the upstream providers whose traffic they carry. For insurance agencies, this means the attestation level on your outbound calls depends on whether your dialer platform or carrier can demonstrate a verified, documented customer relationship through every hop in the provider chain. Calls that fail that chain drop to partial or gateway attestation, which terminating carriers treat as elevated risk. The practical outcome: agencies that do not ask their dialer and carrier vendors about KYUP readiness are about to see their connection rates get worse for a reason that has nothing to do with their own dialing practices.

What is KYUP and why did the FCC propose it?

KYUP stands for Know Your Upstream Provider. It is a proposed regulatory framework under which downstream voice service providers (VSPs) would be required to verify the identity and vetting practices of the upstream providers they connect to.

Under the current rules, the primary accountability obligation falls on the originating service provider: know your customer before you provision service. KYUP extends that obligation further along the call path. It asks: do you know who your upstream provider is, and are they doing adequate identity verification of their own customers?

The FCC proposed KYUP because bad actors have been exploiting intermediary relationships to introduce illegal call traffic. They work with VSPs that have minimal or nonexistent KYC practices, get their calls onto the network, and then route through unsuspecting downstream providers. Chairman Brendan Carr framed the Commission's intent directly: KYUP aims to "hold providers to a higher accountability measure or to eliminate them from the voice ecosystem if they continue to facilitate illegal robocalls".

The Commission has been signaling this direction for some time. In August 2025, 185 providers were removed from the Robocall Mitigation Database for failing to demonstrate adequate compliance practices. The message is consistent: providers that cannot evidence credible identity and compliance practices risk removal from the ecosystem entirely.

How does KYUP change STIR/SHAKEN attestation for agency outbound calls?

The KYUP FNPRM does not just add paperwork requirements. It rewrites the attestation framework that determines whether your outbound calls carry A-level, B-level, or C-level authentication.

Here is what each attestation level means under the proposed codification. Under the FNPRM, A-level attestation requires both KYC on the customer and verification of the customer's right to use the calling number. B-level still requires customer-side KYC but releases the originator from verifying the calling number. C-level is for traffic without a direct customer relationship, which under the prior regime was the typical default for resold or wholesale traffic.

The operational shift for insurance agencies is this: an originating VSP that has not verified the agency's corporate information, traffic mix, and consent posture cannot assign A-level attestation. An agency that uses DIDs the VSP cannot trace to a number-assignment record will not get the right-to-use check needed for A-level either. Both gaps push the call into B-level or lower.

The KYUP FNPRM also proposes to make improper attestation a violation in its own right, not just a defect in the authentication chain. Assigning A-level without performing the underlying KYC, attaching A-level to numbers the originator cannot verify, or using attestation as a rubber-stamp workflow would all become enforceable wrongs. For originating providers that use third-party signing services, the responsibility for the attestation claim remains with the originator. The third party can mechanize the signing, but it cannot mechanize the KYC.

The Commission also proposes to repeal the last two undue-hardship extensions for STIR/SHAKEN implementation, including for certain satellite service categories. The exemptions window is closing.

Does KYUP affect the "Spam Likely" flag on my dialer numbers?

Yes, indirectly but materially. The "Spam Likely" label is not assigned by the FCC. It is assigned by carrier analytics platforms like Hiya, TNS, and First Orion, which analyze call patterns, complaint ratios, and attestation levels in real time. The attestation level your calls carry is a direct input into those analytics engines.

When the analytics platform sees a call with B-level or C-level attestation, it assigns higher risk. When the terminating carrier sees elevated risk, it labels or blocks. The math is not complicated: 86 percent of unknown calls now go unanswered. If your attestation drops from A to B because your dialer platform cannot trace the full KYUP chain, your connection rate drops with it.

The context makes this more urgent. YouMail reports that U.S. consumers received just over 4.25 billion robocalls in June 2026, up 3.4 percent month-over-month. Total robocalls over the past twelve months reached 48.7 billion.

Consumer trust in the voice channel is eroding, and the analytics engines are getting more aggressive, not less. In the 2026 Hiya State of the Call report, one in three consumers reported receiving AI deepfake calls, and the carriers are under pressure to filter harder.

What happens if my carrier or dialer platform cannot get A-level attestation?

If your provider chain cannot support A-level attestation after KYUP takes effect, your calls carry B-level or C-level. Downstream carriers are not required to block B-level calls, but many do. Some annotate, some throttle. The outcome is the same: fewer connections.

The specific risk for insurance agencies running dialer-heavy outbound is the cascade effect. Agencies are not VSPs. They do not file in the Robocall Mitigation Database, and they do not hold SPC tokens. They sit one or two hops upstream of an entity that does.

The FNPRM's new KYC posture forces that entity to underwrite them. If the dialer platform cannot provide the originating carrier with verified KYC on the agency, the carrier cannot assign A-level. If the carrier cannot assign A-level, the agency's calls travel at B-level or C-level, and the downstream analytics engines treat them accordingly.

This is not theoretical. Under the KYUP FNPRM, downstream VSPs must collect general business information, financial information, internet and commercial presence data, ownership and affiliate relationships, operational information, and service information from their upstream providers. They must evaluate whether those upstream providers conduct meaningful identity vetting of their own customers. They must take affirmative action with respect to potentially illegal traffic, and they must retain records for four years.

The Wiley Rein law firm frames KYUP as "a significant expansion" of the existing regime. For the agency owner running fifty lines through a hosted dialer, that translates to one practical question: does my dialer vendor have a KYUP compliance plan?

When do the KYUP rules take effect and what should agencies do now?

The May 20 FCC vote advanced the FNPRM into the formal public comment process. Comments are due 30 days after publication in the Federal Register, and reply comments are due 60 days after publication. From the comment period to a final Report and Order carrying the force of law, the typical timeline spans twelve months or more. The rules are not in effect today.

But waiting until they are in effect is the mistake. The carrier analytics engines are already weighting attestation in their scoring models. Connection rates are already declining. The direction of travel is set. Agency owners who verify their provider chain now will keep their numbers clean while peers scramble.

Three steps every agency owner should take this quarter. First, ask your dialer platform directly whether their carrier relationships support A-level attestation and whether they have a KYUP readiness program. A vendor that cannot answer is a vendor that has not started.

Second, audit your DIDs. Verify each number is registered with the correct CNAM and that your dialer platform can trace every DID to a number-assignment record the originating carrier recognizes.

Third, centralize your carrier relationships. Agencies that route traffic through multiple resellers with opaque upstream chains are the first to lose attestation quality when KYUP enforcement tightens.

Sources cited in this analysis?

  1. FCC, "FCC Proposes Enhanced Know-Your-Upstream-Provider Requirements" (May 21, 2026) - https://www.fcc.gov/document/fcc-proposes-enhanced-know-your-upstream-provider-requirements
  2. TransNexus, "FCC Know-Your-Upstream-Provider and SHAKEN Rules Adopted" (May 28, 2026) - https://transnexus.com/blog/2026/fcc-kyup-and-shaken-rules-adopted/
  3. Numeracle, "FCC's KYUP Proposal Explained" (May 28, 2026) - https://www.numeracle.com/insights/fcc-kyup-know-your-upstream-provider
  4. LeadGen Economy, "FCC STIR/SHAKEN KYUP FNPRM: Lead-Gen Call Centers" (June 2026) - https://www.leadgen-economy.com/blog/fcc-stir-shaken-know-your-upstream-provider-fnprm/
  5. Wiley Rein LLP, "FCC Proposes Significant Expansion of KYUP and STIR/SHAKEN Requirements" (May 26, 2026) - https://www.wiley.law/alert-FCC-Proposes-Significant-Expansion-of-Know-Your-Upstream-Provider-and-STIR-SHAKEN-Requirements
  6. Hiya, "2026 State of the Call Report" - https://www.hiya.com/state-of-the-call
  7. YouMail Robocall Index, "June 2026 Nationwide Robocall Data" - https://robocallindex.com/

Frequently Asked Questions

What is the FCC KYUP rulemaking?

KYUP (Know Your Upstream Provider) is a May 2026 FCC proposal requiring downstream providers to verify the identity and vetting of every upstream provider whose traffic they carry. It extends KYC obligations one step backward, closing the gap bad actors use to inject illegal calls.

Does KYUP apply to my insurance agency directly?

No. Insurance agencies are not voice service providers and do not file in the Robocall Mitigation Database. But your dialer platform and its originating carrier are subject to KYUP, and their compliance posture determines the STIR/SHAKEN attestation level your calls carry. Lower attestation means higher risk scoring by carrier analytics engines.

Will my calls get blocked if I do not have A-level attestation?

Not automatically, but the risk is real. B-level and C-level attestation signals are weighted as elevated risk by Hiya, TNS, and First Orion analytics platforms. Terminating carriers use that scoring to decide whether to label a call or block it. With 86 percent of unknown calls going unanswered, lower attestation directly costs you connection rate.

When do I need to act on KYUP?

The rules are in the public comment phase and are not yet final. A final Report and Order is typically twelve months or more from a May 2026 FNPRM adoption. But the analytics weighting of attestation is already active. Agencies that verify their provider chain now will maintain cleaner numbers through the transition.

What should I ask my dialer vendor about KYUP?

Ask three questions. Does your carrier infrastructure support A-level STIR/SHAKEN attestation for outbound calls? Do you have a KYUP readiness program documenting the provider chain from agency to terminating carrier? Can you trace every DID in your pool to a number-assignment record your carrier recognizes? A vendor that cannot answer these is a vendor whose attestation quality is at risk.

By ·Updated

LineShield is operated by licensed P&C insurance agency owners, serving captive and independent agents across the U.S. Read more about our team.

How we review: every guide is drafted from carrier and analytics-partner documentation, then fact-checked against live dialer data, because reputation rules shift constantly. Additionally, we re-verify each guide when carrier behavior changes.

Corrections: if you spot an error, contact us at customerservice@theidudes.com and we will fix it promptly.

Published by
Insurance Dudes Research Team
Phone reputation research for insurance agents · July 20, 2026

Topics

Related research