Quick answer: Do-Not-Originate (DNO) is a screening practice built around one simple fact: some phone numbers exist only to receive calls. Inbound hotlines, government agency numbers, bank support lines, hospital switchboards — those numbers should never appear as the presenting caller ID on an outbound call. When a number is entered on a DNO registry, carriers and downstream providers screen outbound calls against that list and block any call whose caller ID matches. The guard cuts both ways: register your inbound-only numbers on a DNO list so spoofers get cut when they forge your identity, and check every outbound caller ID against the same lists so a launchable campaign does not die at the carrier edge on day one.
This explainer sits alongside the 10DLC sanction-sweep roundup and the deepfake-voice fraud breakdown — the third head of the same problem: outbound identity. Registration drift gets campaigns suspended; synthetic voice gets the other end deceived; forged caller ID gets your legitimate numbers impersonated. DNO is the part of the answer that lives before the call is even placed.
What a Do-Not-Originate registry actually is
Caller ID is an assertion, not a credential. By default, an originating network can present almost any number as the caller ID of an outbound call, and nothing in the legacy call path forced that number to be one the caller had the right to use. STIR/SHAKEN attests whether the signing carrier is allowed to use the number; DNO attacks the complementary case: even a technically-unchallengeable attestation means nothing if the number itself should never originate calls at all.
A DNO registry is therefore a negative list: numbers that service providers have marked inbound-only, on behalf of the customers who own them. The operating rule:
- The number's owner (or its carrier) states that the number is receive-only.
- The number lands on one or more DNO lists maintained by carriers and industry working groups.
- Calls presenting that number as their caller ID are treated as spoofed by construction and can be blocked by carriers downstream of the originating network.
A typical DNO candidate set: toll-free customer-care numbers, government and financial-institution lines, hospital and emergency-services switchboards, and any number an enterprise advertises as an inbound contact point. The common trait — callers are taught to trust these numbers, so they are also the numbers spoofers forge most.
Where the screening happens in the call path
DNO screening is not one check at one point. It is a defense layered over three stages:
- Originating provider check. A responsible carrier or softswitch screens the caller IDs it accepts before routing. An outbound request presenting a DNO-listed number it does not own gets refused at the edge, or flagged for review. This is the cheapest place to stop a spoof, and the stage an outbound platform controls directly.
- Transit and wholesale screening. Intermediate carriers in the call path run their own analytics — including DNO matching — on wholesale traffic. A forged number that slips past a careless originator can still be killed in transit, with the originating route's reputation taking the hit.
- Terminating analytics. The called party's carrier runs its blocking logic before the phone rings. DNO lists are one of the high-confidence inputs there: an inbound-only number originating calls is close to a definitive spoof signal, so it survives even conservative blocking thresholds.
The practical consequence: a caller ID that sits on a DNO registry is radioactive anywhere in the path. Even if the first hop passes it, a later hop often will not — and every hop that blocks it counts against the route that carried it.
Why an outbound caller ID on a DNO list fails — and what to do about it
The failure mode operators actually meet is subtler than spoofing. It usually looks like this: a company provisions a number for inbound service, then months later uses the same number as the caller ID for an outbound campaign. If that number was DNO-registered — by the company itself, or by a carrier on its behalf — the outbound traffic starts failing in ways that look like coverage problems: calls that never connect, blocking concentrated on certain destination carriers, answer rates collapsing without a clear error.
Three rules prevent it:
- Separate inbound and outbound inventory. Advertised inbound lines and outbound caller IDs serve opposite jobs; treat a DNO registration as a one-way door. If a number might ever be registered inbound-only, never use it as an outbound caller ID.
- Screen caller IDs before campaign launch. A launch checklist that checks DNO status once beats a reputation repair that runs all quarter. Add the check to the same pre-launch pass that validates consent lists and quiet-hours enforcement — for AI-driven outbound that check gates the whole dial plan, as covered in the AI-assisted outbound guide.
- Register your own inbound lines. The other half of the guard: every number your customers are told to call is a number spoofers can forge. Registering it as inbound-only means forged outbound calls presenting your number get blocked at carrier analytics before your customers pick up — which is also the strongest caller-identity statement you can make while the call-recording consent gates handle the recording side of lawful telephony.
How to build a DNO guard into outbound calling
- Inventory outbound caller IDs. List every number any campaign, dialer, or AI agent presents as caller ID. Numbers with no owner in the inventory should not originate.
- Screen each caller ID against DNO registries. Check with the carrier that provisioned each number, and re-check on a schedule — registry membership changes as owners submit and remove numbers.
- Register inbound-only lines on DNO. Request inbound-only status on every advertised contact number through the carrier holding it, and confirm the registration took effect.
- Gate launch on the check. Make DNO status a launch-blocking item for every new caller ID, the same way consent and quiet-hours checks gate sends.
Frequently asked questions
How do I add my inbound-only numbers to a Do-Not-Originate registry?
Through the carrier or service provider that holds the number. DNO registrations are carrier-mediated — the owner of the number asks its provider to mark the number receive-only, and the provider syndicates that to the lists it screens against. Keep a record of which numbers you registered and when, so a later outbound inventory audit does not trip over them.
Does DNO screening replace STIR/SHAKEN?
No. The two answer different questions. STIR/SHAKEN attests whether the carrier signing the call has the right to use the caller ID it presents. DNO says the presented number should never originate calls at all, whatever the attestation claims. Terminating-carrier analytics weigh both — a strong SHAKEN attestation does not rescue a DNO-listed number, and an unknown number does not need a DNO entry to be blocked.
My outbound caller ID is being blocked — how do I check whether it is DNO-listed?
Start with the carrier that provisioned the number; it can confirm whether the number sits on an inbound-only registry. If it does, either request removal — appropriate only if the number genuinely originates outbound and was registered by mistake — or move the campaign's caller ID to a number provisioned for outbound use. Treat a DNO hit as a launch-gate finding, not a post-launch production incident.
Does DNO apply to SMS sender IDs?
No — DNO is a voice concept that screens the presented caller ID on calls. The messaging analog lives elsewhere: A2P registration regimes like 10DLC vet the sender identity of message traffic, and the sanction-sweep explainer covers how carriers enforce it. The shared lesson is the same one this guard teaches: identity that is never screened is identity that will eventually be forged.