Stopping Spoofed Calls at the Source: PBXware’s New DNO Support

A talk with Dalibor Bradvic, Product Owner

Dalibor Bradvic

Product Owner

Illegal robocalls almost always follow the same playbook. What happens is a fraudster spoofs a number that was never meant to make outbound calls (a bank’s inbound-only support line, an unassigned number) and uses it to earn a victim’s trust before the con even starts. With PBXware v8.1 (backported to 7.6.4), Bicom Systems is giving partners a native way to shut that down before the call ever leaves the network.

Dalibor Bradvic

Let’s start with what actually happens without this. Walk us through a real failure.

Picture a partner running their own trunks for a regional bank client. Someone outside the network spoofs the bank’s published support line, a number that’s inbound-only, never meant to place a call, and starts robocalling the bank’s own customers, using a number those customers already trust.

The bank finds out when its customers start complaining, or worse, when someone gets defrauded. At that point it’s not the fraudster who takes the reputational hit first but the voice provider whose network the call originated on. That’s the partner.
That’s the scenario DNO checking exists to prevent. It’s a direct fix for a fraud pattern that’s costing real people money right now.

istockdbbd1

PBXware now checks against DNO lists natively. What’s actually different for a partner who’s never had this?

Before this, there was no way to implement DNO support. If protecting outbound caller IDs against Do Not Originate lists was a requirement, it meant finding another way to solve the problem outside the platform.
Now it’s built in. Outbound calls are checked in real time against the Somos RealNumber DNO service, and anything that matches is rejected before it reaches the network.
If a partner uses a different DNO provider, PBXware also supports custom integrations. That requires middleware to check outbound caller IDs against another DNO service or a locally maintained database, while PBXware applies the same call-blocking logic once the lookup is complete.
The result is the same: partners can offer DNO protection as part of their PBXware deployment instead of working around the platform to achieve it.

Customer support agent woman listening to client's inquiries, demonstrating her dedication providing top-notch service

Somos RealNumber DNO versus a custom provider: how should a partner decide?

Somos is the default answer for most partners, and there’s a real reason: their list is sourced directly from the authoritative registries for North American numbering (the NANP and the Toll-Free Number Registry) covering more than 6 billion numbers with global reach. It’s proven, it’s always current, and a partner doesn’t have to manage it.

Custom providers exist for the partners who already have a reason not to use Somos, a regional vendor they’re contractually tied to, an internal fraud database, a locally maintained list outside North America. PBXware points at any API endpoint, authenticates with a bearer key, and handles the rest. Nobody’s locked in either direction.

istockdbbd2

Let’s talk about the commercial side. The discount is a big deal here.

Bicom Systems secured a 30% discount on Somos RealNumber DNO pricing for every Bicom Systems partner.

Here’s why that matters more than it sounds like it should: the single biggest objection to any compliance feature is “this is a new line item.” DNO checking through Somos was already the best list in the industry. Now it’s also priced better than a partner would get negotiating with Somos directly on their own.

That turns the conversation from “do we really need this” into “why would we not take the cheapest, most proven option.” The discount offsets the cost of compliance and it makes the compliant path the obviously correct business decision.

Friendly service agent using computer and talking to customer in call centre.

This sounds like more than a checkbox feature. What’s under the hood that makes it production-grade rather than a demo?

A few things had to be true for this to be usable at real call volumes, not just in a sales deck:

Real-time blocking with caching

Calls are checked against the provider and rejected instantly on a match, with configurable TTL caching so lookups don’t add latency to call setup. A partner running thousands of calls a day can’t afford a feature that slows down every single one.

Emergency calls always go through

DNO checks are skipped entirely for emergency calling, with a safe fallback Caller ID if an extension’s own number happens to be listed. Compliance in one direction can’t create a life-safety problem in the other.

A full audit trail

Every block and every failed lookup is logged (Caller ID, timestamp, call ID, provider, cache status) and retained for the last 10,000 events, available in the GUI and via API. When a regulator or an auditor asks “prove you’re doing this,” there’s a report.

Proactive alerts with throttling

Admins get notified on blocked calls and provider errors, but a burst of issues sends one digest instead of flooding an inbox. Nobody wants an alerting system that trains people to ignore alerts.

API-first configuration

Everything is exposed through PBXware’s API v2, so a partner’s own tooling can configure, monitor, and report on this rather than someone living in a GUI every day.

 

dno-production-grade-protection.png

Why did this ship now specifically, rather than being on a longer roadmap?

Because the deadline wasn’t a roadmap decision but a regulatory one. The FCC’s expanded Do-Not-Originate rule took effect December 15, 2025, and it now covers voice service providers across the entire call path, not just gateway providers. There are real financial penalties attached. Similar requirements are emerging in the UK and elsewhere.

The partners this actually lands on are the ones running their own trunks and their own origination, meaning the regulatory scope now includes them directly, not just the upstream carriers they used to be able to point to.

If we’d shipped this eighteen months from now, a chunk of our own partner base would have been out of compliance in the meantime, with no path forward except building it themselves under time pressure. That’s a much worse position to be in.

 

Diverse Team Meeting in Modern Office Space

What should a partner actually do this week, not eventually?

Turn it on. It’s already live in v8.1, backported to 7.6.4, so being on the latest release isn’t even a prerequisite. Somos and custom provider support, logging, and alerts are all tested and documented. It’s under Settings > DNO > Configuration. The only step that takes a phone call rather than a click is confirming with a Bicom Systems contact that the 30% Somos discount is actually applied to the account and that’s worth doing on day one, not whenever it comes up.

istockdbbd3

Any closing thoughts for a partner still on the fence?

There isn’t much of a fence left. If you originate calls under your own identity, on your own trunks, this stops being optional in a lot of jurisdictions very soon, if it hasn’t already. The part that should make the decision easy is that doing the right thing here isn’t more expensive than doing nothing and with the Somos discount, it’s cheaper than most partners assumed compliance would cost them.

DNO support is available now in PBXware v8.1 and 7.6.4. For setup details, see Settings > DNO > Configuration in the PBXware admin GUI, or reach out to your Bicom Systems contact to confirm your partner discount on Somos RealNumber DNO.

Music, headphones and business woman in office streaming radio or podcast. Break, thinking and happy female employee from Canada on desk with laptop listening to song, audio or sound at workplace.