1. Verdicts
CallerAPI Documentation
  • Quickstart
  • Use cases
    • For carriers (MNOs/MVNOs)
    • CPaaS platforms
    • Cloud communications providers
    • SIP trunking providers
    • PBX/Cloud PBX
    • UCaaS vendors
  • Account
    • Balance and email
      GET
  • Spam protection
    • Voice firewall
      • Get started
      • Quickstart
        • What you get
        • Before you start
        • Test with a recording
        • Connect your switch
        • Switch notes
        • Twilio and Telnyx
        • Send text instead of audio
      • Verdicts
        • Read a verdict
        • What to do with a verdict
        • Block a caller
        • Events and webhooks
      • Honeypot
        • Hand a call over
        • Audio, events, and limits
      • Reference
        • Endpoints
        • Errors
        • Limits and thresholds
        • Production checklist
      • REST
        • What this deployment can do
        • List the verdict categories
        • List the honeypot personas
        • Score a transcript or a recording
        • List your recent sessions
        • Get one session with verdict and intel
        • Twilio voice URL for a screened number
        • Preview the Twilio TwiML
        • Telnyx voice URL for a screened number
        • Twilio voice URL for a honeypot number
        • Telnyx voice URL for a honeypot number
      • WebSocket
        • Live scam filter stream
        • Honeypot stream
    • Daily spam reports
      • Webhook
        • Subscribe to daily reports
        • Unsubscribe from daily reports
        • List webhook subscriptions
        • Manual dispatch of reports
        • Test webhook
      • REST
        • Fetch daily spam reports
    • 15 days spam CSV snapshot
      GET
    • Spam score + HLR
      GET
  • Mobile SDK
    • Get started
    • Quickstart
      • What you get
      • Get your keys
      • Android
      • iOS
      • Flutter
      • React Native
      • Check it works
    • Call screening
      • What each platform can do
      • Android call screening
      • iOS prerequisites
      • iOS add the extension
      • iOS test on device
    • Reference
      • Methods
      • Errors
      • Limits and billing
      • Troubleshooting
  • Data partners
    • Partner tems & docs
    • Upload spam reports
    • Upload contacts
  • Fraud prevention
    • Ported date
    • Porting history
    • Online presence
    • KYC user identity
  • Schemas
    • Spam protection
      • Spam score request
      • Business info
      • Carrier info
      • Complaint (without number)
      • Daily spam reports request
      • Complaint (with phone)
  1. Verdicts

What to do with a verdict

The filter tells you. Your switch acts. This page is the playbook.

Two checks, two moments#

The voice firewall works in the call. The first verdict arrives after the caller has spoken a sentence or two. It cannot stop the phone from ringing.
Use two checks together:
1.
Before ring: Spam score + HLR returns the spam score and reputation of the calling number. Known spam numbers never ring.
2.
In the call: the voice firewall scores what the caller says. New numbers and spoofed numbers are caught here, and each scam verdict with report=true feeds the first check for everyone.

One action per level#

LevelScoreActionHow
cleanbelow 0.3Nothing.No event is sent.
suspicious0.3 to 0.59Tag the CDR.Write session_id, score, and category to the call record. Do not touch the call.
likely_scam0.6 to 0.84Warn the called party.Play a tone or a short prompt on the callee leg. Start recording if your policy allows it.
scam0.85 and aboveWarn or drop.Play a short message and hang up, or transfer the call to the honeypot.
Rules:
Act on level, not on score.
Act on the latest event. A later verdict replaces an earlier one.
Never drop on likely_scam alone. Drop on scam, and only after the observation period below.
Tag every action with session_id. When a subscriber asks why a call was cut, Get one session has the transcript, the verdict, and the evidence.

Where to put the logic#

You have three places to act. Pick one.
PlaceGood forNote
The socket clientMedia servers and bridges that read the socketLowest latency. Read verdict events as they arrive.
Your webhook backendFreeSWITCH forks, SBCs, Twilio, TelnyxSet webhook on the socket URL. Act from the webhook and send a hangup or transfer to the switch over its own API.
After the callCDR tagging, analyst review, blockingRead session.ended or Get one session. No live action.

The first 30 days#

Start in observe mode. Enforce later. The verdict is a probability, and your traffic is not the traffic the thresholds were tuned on.
1.
Week 1: connect the switch with report=false. Tag CDRs with the level. Do not warn and do not drop. Pull List your recent sessions with limit=200 daily and read the scam and likely_scam transcripts.
2.
Week 2: turn on the warning for likely_scam and scam. Keep drops off. Count complaints from called parties.
3.
Week 3: turn on drop or honeypot transfer for scam on consumer lines. Keep enterprise trunks on warn.
4.
Week 4: set report=true. From now on a scam caller is filed and blocked across CallerAPI, before ring, for you and for every other customer. See Block a caller.
If the scam transcripts you read in week 1 are not scams, stop and contact us before you go to week 3.
Modified at 2026-09-18 16:56:56
Previous
Read a verdict
Next
Block a caller
Built with