What Is a Traceback? The TRACED Act 101 for Carriers

At the time of writing this guide, the traceback system has been a mandatory part of doing business as a US voice service provider for a few years now.

Most large carriers already have a process for handling a traceback request when one arrives. A lot of smaller and mid-sized carriers don't. It's either because they've never received one, or because they got one, scrambled to figure out what it meant, and never built a repeatable process afterward.

This article is for both groups. It's also for anyone setting up as a new voice service provider in the US and trying to understand what they're walking into.

This article will walk you through what a traceback actually is, where the system came from, what the law requires, who runs the process day to day, and why it applies to you even if you've never originated an illegal call in your life.

So let's get into it.

What Is a Traceback?

A traceback is a formal request to identify the source of a specific call. Not calls in general, just one specific call, flagged as illegal or unwanted. It is then traced backward through the call path one carrier at a time until it reaches whoever originated it.

That's the whole concept. It's not complicated. What trips carriers up is not knowing what a traceback is not. A traceback is not an accusation. Receiving one doesn't mean the FCC thinks you did something wrong.

A traceback is not an audit. Nobody is combing through your full call records. They only want information on one call.

A traceback is not, by itself, a fine. The traceback and the enforcement action are two separate things, and one doesn't automatically trigger the other.

How a Traceback Actually Moves Through the Call Path

Here's the mechanic, step by step.

The process starts at the terminating carrier, the one that delivered the call to the consumer who complained. They're asked: who handed you this call? They answer with the identity of the carrier one hop upstream. That carrier gets asked the same question. They answer with the carrier one hop upstream from them.

This repeats, carrier by carrier, until the chain reaches the originating provider. They are the one that first put the call onto the network.

Every carrier in that chain has one job: identify the next link up. Nobody in the middle of the chain is expected to know who originated the call. They're only expected to know who they got it from.

Traceback Direction: Follow the Call Upstream

Each carrier identifies only the provider that handed the call to it.

Complaint
Consumer
Received the call
Termination
Carrier C
"Who gave you this call?"
Upstream
Carrier B
"Who handed it to you?"
Originating Provider
Carrier A
First provider on the network
Rule 01
Ask one hop upstream
Rule 02
Record the carrier identity
Rule 03
Repeat until origin
The traceback is a chain of custody, not a hunt for the originator.
Every intermediary only needs reliable evidence of its immediate upstream handoff.

A Real-World Example: How a Traceback Actually Plays Out

It helps to see this in practice rather than as an abstract flow chart.

Say a consumer in Ohio reports an illegal robocall, a spoofed call pretending to be from the IRS. The complaint gets routed to the ITG, which opens a traceback on that specific call, identified by its called number, calling number, and timestamp.

The ITG contacts the terminating carrier, the one whose network delivered the call to that Ohio consumer. That carrier checks its records and identifies the carrier that handed them the call, one hop upstream.

The ITG then contacts that upstream carrier with the same question. That carrier checks their own records and identifies who handed the call to them.

This continues, hop by hop, sometimes across three or four carriers, sometimes across a dozen, until the trail reaches a carrier that can't point further upstream. That is because they originated the call themselves, or because the trail goes cold at a foreign carrier outside US jurisdiction.

Each carrier in that chain only had to answer one question. None of them had to investigate the whole call. None of them had to prove anyone else's guilt. They just had to say, accurately and on time, who they got the call from.

Where the Traceback System Comes From: The TRACED Act

The TRACED Act, formally the Pallone-Thune Telephone Robocall Abuse Criminal Enforcement and Deterrence Act, was signed into law in December 2019. It was a direct response to the sheer volume of illegal robocalls hitting US consumers.

These included spoofed IDs, scam calls, and robocall campaigns that were, at the time, largely outrunning enforcement.

What the Act Actually Changed?

The TRACED Act did three concrete things.

  1. It raised the penalties the FCC could issue for illegal robocalling, giving enforcement actual teeth.
  2. It mandated call authentication. This is where STIR/SHAKEN comes from, if you've read our guide on implementing it.
  3. It formalized traceback as a mandatory enforcement mechanism, rather than a voluntary industry courtesy, by requiring the FCC to designate a single registered consortium to run it.

That third point is the one carriers most often miss. Traceback existed before the TRACED Act, informally. The TRACED Act didn't invent traceback. It made cooperation mandatory and gave the FCC legal authority to enforce it.

Before the Law Required It: How Industry-Led Traceback Actually Started

This part surprises a lot of carriers: the traceback process predates the TRACED Act by four years.

USTelecom formed a robocall engineering working group back in 2015, well before Congress got involved. It aimed at improving and simplifying the process of tracing illegal calls back to their source.

Early successes with that informal, voluntary effort convinced the industry to build something more structured. A governance framework with broader carrier participation.

By 2019, that voluntary effort had already produced real results. In its first annual progress report, the group, by then operating as the Industry Traceback Group, reported that more than 100 companies had participated in tracebacks.

They succeeded in identifying the source of over 10 million illegal calls through more than 1,000 individual traceback investigations. All of that happened before the TRACED Act existed. What the TRACED Act did was take a working voluntary system and make participation mandatory for everyone, not just the carriers who'd opted in.

Section 13(d) of the Act required the FCC to formally designate a single registered consortium to run private-led traceback efforts. USTelecom's ITG filed its letter of intent in May 2020 and was named the official registered consortium two months later.

The FCC has re-selected the ITG as the incumbent consortium in the years since, most recently reaffirming its role in 2024.

Two rules do the heavy lifting here. Neither one is long and both are well worth knowing thoroughly. This helps you explain it to your compliance team or your legal counsel without having to look them up every time.

What Each Rule Requires of You

47 CFR § 64.6305 covers robocall mitigation obligations. This is the rule tied to your Robocall Mitigation Database (RMD) certification. RMD is the filing that tells the FCC what steps you're taking to prevent illegal robocalls from originating on your network.

We'll go deeper on how your RMD status connects to traceback response time in the next article in this series.

47 CFR § 64.1200(n)(1) is the traceback cooperation requirement itself. This is the rule that says a voice service provider has to respond to a traceback request, and it's the rule that sets the clock running once a request comes in. We'll cover exactly how tight that clock is, and what counts as a valid response, in the next article.

For now, the point to take away is this: these aren't guidelines. They're binding rules with a defined response obligation attached. The FCC also has to report annually to Congress on how well the whole system is functioning.

Your response record doesn't just sit in a file somewhere after all. It feeds into a public accounting of industry cooperation.

Two Rules, Two Different Compliance Functions

The distinction matters because certification and traceback cooperation address different points in the compliance chain.

Rule 01
PREVENT
47 CFR § 64.6305
Robocall mitigation
Establishes the obligation connected to your Robocall Mitigation Database certification and the measures used to reduce illegal robocall origination.
Compliance question: What controls are you operating to mitigate illegal traffic?
Rule 02
RESPOND
47 CFR § 64.1200(n)(1)
Traceback cooperation
Establishes the obligation to cooperate with traceback requests and creates a defined response requirement once a request reaches the provider.
Compliance question: Can you produce a timely, defensible response when asked?
The operational connection
Your RMD establishes the mitigation framework. Your traceback process demonstrates whether that framework can support an accountable response when the FCC or an authorized traceback party comes knocking.
Think of compliance as a chain, not a filing.
Mitigation measures → RMD certification → Traceback request → Provider response → Industry accountability

Who Runs It? The Industry Traceback Group

The FCC doesn't personally send out most traceback requests. That job belongs to the Industry Traceback Group, or ITG. It is a consortium the FCC has formally designated to run the traceback process on its behalf.

The ITG is administered by USTelecom, the Broadband Association. The FCC delegated the operational side of traceback to them for a practical reason: tracing calls across dozens of carriers, day after day, is a high-volume operational task.

The ITG is built to do exactly that at scale. What started as 21 founding members has grown to well over 30, spanning wireline, wireless, VoIP, and cable providers.

One distinction worth understanding clearly: the ITG is not a law enforcement agency, and by the terms of the TRACED Act, it can't be. It has to remain a private entity. It works closely with the FCC, the FTC, and state attorneys general, sharing information about non-cooperative providers.

However, it doesn't have subpoena power or the authority to prosecute. Its leverage comes from something more practical: its findings feed directly into the enforcement actions those agencies do have the authority to bring.

ITG-Initiated vs. FCC/Law-Enforcement-Initiated Tracebacks

Most of the traceback requests you'll ever receive will come from the ITG directly. But they're not the only ones with the authority to request one. The FCC itself and law enforcement agencies can also initiate a traceback, and the obligation to respond is identical no matter who sent it.

We cover exactly who can request a traceback, and the different rules that apply depending on the requester, in the next article in this series.

Common Misconceptions About Traceback Requests

A few misunderstandings show up often enough among carriers that they're worth addressing directly, before they cost you a missed deadline.

Two Compliance Questions That Get Confused

The fastest way to separate the concepts is to ask when the control operates and what it is trying to establish.

Real-time control
STIR/SHAKEN
Call initiated
Identity authenticated
Call evaluated
Primary question: Can the presented caller identity be trusted?
Post-call investigation
Traceback
Call occurred
Call identified
Source traced
Primary question: Which provider handed this specific call to the next hop?
Key distinction
Authentication does not eliminate investigation.
A call can carry authentication information and still become the subject of a traceback request. One establishes trust at call time. The other reconstructs the path after the event.
Misconception
“STIR/SHAKEN means no traceback.”
False. Authentication and traceback answer different questions.
Misconception
“Small carrier means small obligation.”
False. The relevant factor is your role in the call path, not the size of your business.
The practical test is simple: Did your network touch the call?
If yes, carrier size does not change the traceback question.

Traceback and STIR/SHAKEN Are Not the Same Thing

These two get conflated constantly, because both came out of the same piece of legislation and both deal with illegal robocalls. But they solve different problems.

STIR/SHAKEN authenticates a call in real time, as it's happening. So a terminating carrier can judge whether the caller ID is trustworthy before the call even connects.

Traceback happens after the fact. It's an investigation into a specific call that already occurred and already caused harm. You can have STIR/SHAKEN fully implemented and still receive traceback requests.

While authentication reduces spoofing, it doesn't eliminate illegal calling, and it doesn't replace the need to identify where a specific bad call actually came from.

"We're a Small Carrier" Doesn't Exempt You

Carrier size has no bearing on whether the traceback obligation applies to you. The rule is written around your role in a specific call's path, not your revenue, your subscriber count, or how long you've been operating. A five-person VoIP reseller and a national carrier are held to the identical response obligation if they touched the same illegal call.

Why This Applies to You, Not Just "Bad" Carriers

Here's the myth that causes the most confusion, and the most missed deadlines: "We didn't originate the call, so this isn't our problem."

It's not true, and it's worth being direct about why.

Any carrier in the call path can be asked to respond to a traceback, be it originating, intermediate, gateway, or terminating. The obligation isn't limited to whoever first put the call on the network. If you touched that call at any point, you can be asked who handed it to you.

This isn't an FCC overreach. It's how the system has to work.

A traceback is only as useful as its weakest link. If one carrier in a ten-hop chain doesn't respond, the trace stops dead at that point, and the originator never gets identified. The entire design depends on every single carrier in the path cooperating, every single time.

A traceback succeeds only when every carrier can identify its immediate upstream provider.

Carrier A
Responds
Carrier B
Responds
Carrier C
Responds
Carrier D
No Response
Carrier E
Unknown
Traceback Progress Stops Here
Everything beyond the non-responsive carrier becomes invisible to investigators.
100%
Participation Required
Every carrier must identify its upstream handoff.
1
Broken Link
One non-response can terminate the entire investigation.
0
Blame Assigned
The objective is continuity of evidence, not collective liability.
Why Roles Matter
Originating
Intermediate
Gateway
Terminating
Different carrier roles have different operational obligations, but every role shares the same responsibility to preserve the traceback chain.

That's why the obligation is written the way it is. It's not about assigning blame to every carrier in the chain. It's about making sure the chain can't be broken.

We go into exactly what your role in the call path means for your specific obligations. Because originating, intermediate, gateway, and terminating providers don't all have the same responsibilities.

What's Next in This Series

Now that you know what a traceback is, where it came from, and why the obligation reaches every carrier in the call path. The next logical question is who can actually send you one, and why not having received one yet doesn't mean you're in the clear.

That's exactly what we cover in who can request a traceback — and who has to respond.