I Put an IVR Between Spam Callers and My Cell Phone for One Month. Here's What Happened.

120 incoming calls. 101 unwanted. Zero unwanted calls reached my phone.

For years, I did what everyone tells you to do about spam calls. I registered with the National Do Not Call Registry. I used the spam-blocking tools my carrier offers. I ignored unknown numbers. I reported the obvious scams.

None of it solved the problem.

So on August 1, 2026, I tried something different.

I set up a new public-facing phone number, (501) 4-GOBLIN (501-446-2546), and put a simple IVR (that's Interactive Voice Response, the automated menu that says things like "press 1 for...") between the public telephone network and my actual cell phone.

When someone called, they had to make a deliberate choice before the call would ring through to me. Legitimate callers could get through fine. Automated dialers, junk calls, and unwanted callers generally died at the gate.

I left the system running for a full month and kept the records.

This wasn't a sophisticated anti-fraud setup. No artificial intelligence, no giant blacklist of known scam numbers, no need to know whether a caller was "verified" or whether their caller ID was spoofed or whether some carrier had already flagged them as suspicious.

It just asked for one small bit of intentional interaction.

And it worked.

The point of this report is simple: show what happened, show what it cost, and ask a bigger question of the phone companies.

If I can pull this off myself with a cheap VoIP account and a basic IVR, why isn't something this effective already a standard option from the major carriers?


What Happened

Over the month, (501) 4-GOBLIN received 120 actual inbound call attempts.

Only 19 of those came from four callers I knew to be legitimate.

The remaining 101 calls, 84.17% of everything that came in, were unwanted.

But 84.17% isn't the number that matters most here.

The number that matters is:

ZERO


Exactly zero of those 101 unwanted calls reached my cell phone.

The IVR caught every single one before my handset ever rang, while legitimate callers still got through without a hitch.

The Results

  • 120 total incoming call attempts
  • 19 legitimate calls
  • 101 unwanted calls
  • 84.17% of all incoming calls were unwanted
  • 0 unwanted calls reached my cell phone
  • 100% of identified unwanted calls were stopped before the handset

The 19 legitimate calls came from just four known callers: a family member, a friend, an animal clinic, and the University of Kentucky. The other 101 attempts came from numbers I never identified as legitimate during the experiment.

One more scope note that matters for interpreting these numbers: (501) 4-GOBLIN wasn't the only door into this system. My existing, established cell number (859-248-2284), has been permanently set to forward into the same IVR. Any call to either number lands in the same place. I confirmed with my carrier ahead of time that this forwarding setup is a legal, legitimate use case. That's worth flagging because it means this isn't just a clean-slate test on a brand-new number nobody has ever called. Callers who already had an established relationship with my actual, years-old number were passing through the exact same gate.


How I Counted the Calls

VoIP.ms provides a detailed Call Detail Record (CDR) for every transaction the system handles, and there's a distinction worth explaining for anyone who wants to check my math.

VoIP.ms logs the original incoming call as an "Inbound DID" entry. It can also generate a separate "Inbound Call Recording" entry for that same call. Those recording entries aren't additional phone calls; they're just a second record of the same event.

So for this report, I only counted Inbound DID entries as actual incoming call attempts. Recording entries were excluded so I wouldn't double-count a single call, and outbound calls were excluded entirely. Legitimate calls were identified using the four known numbers I mentioned above.

My goal wasn't to inflate the spam statistic as much as possible. It was to land on a number that could actually be checked against the underlying call records.

And after a month, the result was pretty clean:

101 unwanted calls tried to reach me. Not one succeeded.


How the System Worked

The setup was intentionally simple.

Calls to (501) 4-GOBLIN, (501) 446-2546, hit the VoIP.ms system first rather than ringing my cell phone directly. The caller ran into the IVR and had to make a deliberate choice before the call would continue through to me.

The system never tried to figure out whether the incoming number was trustworthy. It didn't check a spam database. It didn't care whether the caller ID was marked "verified." It just required the caller to interact with it.

A legitimate caller could follow the prompt and get through. An automated dialer, a robocaller, or anyone unwilling or unable to interact with the menu never made it past that point.

That distinction matters. Traditional spam filtering is generally trying to answer: "Is this number bad?" My system asked something different: "Is this caller actually, intentionally trying to reach me?"

For my purposes, that second question turned out to be far more useful. Spam callers change numbers constantly. They spoof local area codes. They call from numbers that have never accumulated a single complaint yet. A blacklist can only react to what it already knows about, and it never knows about the new numbers in time.

The IVR didn't need to recognize any of them. Every unknown caller faced the exact same small hurdle. Clear it, and the call goes through. Don't, and my phone never rings.

That's the whole mechanism. No AI, no custom hardware, no enormous database, no special access to the telephone network. Just an ordinary VoIP service and an automated phone menu. Over one month, that simple gate kept all 101 unwanted calls in the dataset from ever reaching my handset.


What It Cost

One obvious question is whether this is actually practical for a regular person to run, and in my case, it very much was.

My normal cell service through US Mobile runs $17 a month, and I didn't touch that. The VoIP system just sits in front of it as a screening layer.

I opened the VoIP.ms account with a $20 prepaid balance. The first month broke down like this:

  • $3.00 — one-time cost to get the phone number
  • $1.10 — monthly charge for the number and IVR service

That left $15.50 in the account at month's end. So the entire first month, setup charge included, cost me $4.50 total.

No expensive phone system, no business telecom contract, no specialized anti-spam hardware. Just an ordinary cell plan and a cheap VoIP account. For $4.50, 101 unwanted callers tried to reach me, and exactly zero of them succeeded.


So Why Aren't the Phone Companies Doing This?

After watching this run for a month, this is the question I couldn't shake.

The major carriers all say they're fighting spam calls. They offer spam labels, scam warnings, reporting tools, caller verification, and various flavors of selective blocking. But most of that is trying to answer some version of: "Do we think this caller is bad?"

That's a considerably harder problem than the one my IVR was solving: "Is this caller willing to make one deliberate choice before interrupting me?"

Those really are different problems. Spam filtering has to identify bad actors, which means leaning on complaint databases, reputation scores, calling patterns, past reports, or caller authentication. If the spammer switches numbers, spoofs something local, or just hasn't racked up enough complaints yet, the call still gets through.

My system didn't care who was calling. A brand-new number got the same treatment as an old one. A local number got the same treatment as an out-of-state one. Even a number the network had authenticated still had to clear the IVR. It wasn't trying to prove a caller was trustworthy; it was just requiring them to show they were intentionally trying to reach me.

It's not that nothing like this exists at all. Google's Call Screen does something similar on Pixel phones, and Apple's Live Voicemail does something similar on iPhones. But I don't actually know anyone who uses either one day to day, and there's a reason for that: both are locked to a single manufacturer's hardware. Call Screen only lives on Pixel devices. Live Voicemail only lives on iPhones. Neither is something your carrier turns on for you regardless of what phone you happen to be carrying. Right now, the closest thing to solving this problem sits behind premium hardware lock-in, not behind a carrier account anyone can activate on any device. That's arguably worse than having no solution at all: the people most likely to already be fed up with unwanted calls are not guaranteed to own the specific flagship phone that happens to include some version of the fix, while everyone else is still stuck with spam labels and after-the-fact reporting forms.

And to be clear, this isn't a problem regulators and industry have ignored. Congress passed the TRACED Act, and the FCC has required providers to implement STIR/SHAKEN caller-ID authentication, run robocall-mitigation programs, participate in traceback efforts, and comply with an increasingly detailed set of call-blocking and provider-vetting rules, requirements the FCC keeps expanding. (FCC Docs)

The money involved isn't trivial either. When the FCC mandated STIR/SHAKEN, it estimated that roughly 2,600 voice providers combined could spend between $39 million and $780 million every year in recurring costs, with up-front implementation costs for the largest providers potentially reaching tens of millions of dollars. Those are industry implementation costs, not a subsidy paid to carriers. (FCC Docs)

Meanwhile, the FCC estimates illegal and unwanted calls cost American consumers at least $13.5 billion a year in fraud, wasted time, and general aggravation. (FCC Docs)

So this isn't a problem lacking regulation, engineering effort, money, or attention. It's had all four. And the consumer is still the one left handling the final failure at the handset.


"Verified" Doesn't Mean "Wanted"

Modern networks use authentication systems like STIR/SHAKEN to give carriers more confidence in the caller ID attached to a call, which is genuinely useful. But it solves a different problem than the one I care about.

On my own cell service, I've repeatedly seen calls labeled "Verified by T-Mobile" or "Verified by Verizon." In my experience, that reassuring label has never meant the call was wanted. Authentication answers a narrow question about the caller-ID data attached to a call. It doesn't answer the question I actually care about: do I want this person interrupting me?

A properly authenticated telemarketer is still a telemarketer. A technically valid caller ID doesn't make a call useful. Verification and desirability are two different things, and my IVR never confused them.


The Burden Is Still on the Customer

A lot of existing anti-spam tools also expect the customer to act after an unwanted call has already happened. Report the number. Block the number. Open an app. Fill out a form. Wait for the carrier's system to decide there's enough evidence to classify the caller.

That approach is a poor match for a problem where unwanted callers can just move to a different number tomorrow. Blocking yesterday's spam number does very little to stop today's call from a new one.

Even the FTC acknowledges this limitation directly. It describes the National Do Not Call Registry as a list that tells law-abiding telemarketers whom not to call; it doesn't actually block calls, and scammers making illegal calls can simply ignore it. (Consumer Advice) The FTC's own advice says call blocking and labeling are the best practical defense against unwanted calls, while also admitting that not every scam call gets caught. (Consumer Advice)

My IVR flipped that relationship. I didn't have to identify every bad caller. Every unknown caller had to demonstrate they deserved access to my phone. That's a much easier problem to solve, and after a month, 101 unwanted callers ran into the system and not one of them reached my handset.


An Odd Observation About the Do Not Call Registry

One more thing caught my attention.

Just after midnight Eastern on August 12, I added (501) 446-2546 to the National Do Not Call Registry. That same day, the number got six incoming calls, all six unwanted. On August 13, it got nine more calls, three legitimate and six unwanted. So in the first two days after registering the number, it picked up 12 unwanted calls. None of them reached my phone.

I've noticed this pattern before: registering or updating a number with the Do Not Call system seems to be followed by more unwanted-call traffic, not less. But I want to be careful about what I'm actually claiming here.

This experiment doesn't establish that registration caused those calls. I don't know how those callers got the number, and nothing in these records shows the Registry supplied it to scammers. Timing alone isn't causation. There's also a real timing wrinkle: the FTC says a number should appear on the Registry by the next day, but legitimate telemarketers can have up to 31 days to update their own calling lists. (Consumer Advice)

So I'm not presenting those first two days as proof the Registry failed to take effect. What the observation does show is simpler: adding the number to the Registry didn't stop unwanted callers from trying it. The FTC itself says that's expected from scammers and illegal callers, since the Registry is a compliance mechanism, not a technical call-blocking system. (Consumer Advice)

During this experiment, the Do Not Call Registry didn't make unwanted calls disappear. The IVR is what made them stop bothering me.


What About Legitimate Automated Calls?

There's an obvious tradeoff here worth naming honestly: not every automated call is unwanted. Doctors' offices send appointment reminders. Pharmacies call about prescriptions. Schools send notifications. Delivery services reach out. A system that requires deliberate interaction could catch some of those calls too, and that's a real limitation.

But in the system I used, failing the challenge doesn't necessarily mean losing the call. VoIP.ms can record the caller while they're still inside the IVR, before my phone ever rings, and email me that recording much like a voicemail. That gives me a second layer of review: if it was a scammer, I ignore it; if it was a legitimate caller who just couldn't navigate the menu, I listen, recognize what happened, and call them back.

So it's not really a binary choice between letting every unknown caller interrupt me and risking every legitimate automated call. It works more like: unknown caller hits the IVR, doesn't complete it, and a recording gets delivered for later review instead. Known numbers can also be whitelisted, specific organizations can be allowed to bypass the challenge entirely, and different rules can apply at different times. The goal isn't one rigid setup everyone has to use. It's giving the subscriber control.


What This Experiment Does Not Prove

This wasn't a lab study. It was one person, one phone number, one month, one specific configuration.

It doesn't prove every subscriber would see the same percentage of unwanted calls. It doesn't prove every legitimate caller would successfully navigate an IVR. It doesn't prove this exact setup is the best design for everyone. And it doesn't prove IVR screening can tell whether a caller is fraudulent, that was never the point.

The system was built to answer one narrower question: can requiring a small amount of deliberate interaction keep unwanted calls from reaching my phone?

Over a month, the answer was yes. My number got 120 actual inbound call attempts. 101 were unwanted. None of those 101 reached my cell phone.

That's a narrow result, but it's a meaningful one. A simple, inexpensive caller-interaction gate stopped every unwanted call in this experiment from ever interrupting me, and that alone seems like reason enough to ask why comparable subscriber-controlled screening isn't routinely offered by the major carriers.


What I'm Actually Asking For

I'm not suggesting every phone subscriber should be forced onto an automated menu. I'm not asking carriers to auto-block every unknown number. And I'm not suggesting IVR screening should replace existing anti-spam tech.

What I am asking is why subscribers aren't routinely offered a simple, optional form of network-level call admission control. Something that could:

  • let known callers ring through normally,
  • challenge unknown callers before the handset rings,
  • let legitimate callers identify themselves,
  • record callers who fail the challenge for later review,
  • whitelist specific people or organizations,
  • and put the subscriber in charge of the rules.

This experiment shows those pieces are technically possible right now. A legitimate caller who gets caught by the filter doesn't have to just disappear; their attempt can be recorded and delivered afterward, without ever interrupting the subscriber in the first place.

The underlying idea is simple: the subscriber, not the caller, should decide what level of access an unknown caller gets. The technology exists. The cost is low. The concept isn't complicated. So why does an individual customer have to assemble this themselves instead of just switching it on through their carrier?


The Question for the Carriers

For one month, I put a simple screening system between the public telephone network and my cell phone.

120 calls tried to reach me. 101 were unwanted. Zero unwanted calls reached my handset.

No artificial intelligence. No blacklist of thousands or millions of numbers. No need to determine whether every caller was trustworthy. Just a requirement that unknown callers show a small amount of intentional interaction before they were allowed to interrupt me.

And it worked.

Meanwhile, Congress has legislated. The FCC has regulated. Carriers have built out a national caller-authentication framework whose recurring industry costs the FCC estimated at $39 million to $780 million a year. The FCC maintains robocall-mitigation requirements, provider databases, blocking rules, traceback obligations, and more, all aimed at closing the remaining gaps. (FCC Docs) And the underlying problem still costs American consumers an estimated $13.5 billion or more annually. (FCC Docs)

Consumers are still routinely left to handle the final failure themselves.

So my question for the major carriers, the regulators, and the telecom industry as a whole is simple:

Why isn't this already a standard, optional feature?

For years, consumers have gotten spam labels, reporting systems, caller authentication, blocking apps, complaint forms, and instructions for reporting numbers after they've already called us. Yet a consumer with a cheap VoIP account can take a completely different approach: don't try to identify every bad caller, just make unknown callers earn access to the subscriber.

That single shift eliminated every unwanted interruption in my month-long experiment. I'm not claiming to have solved telephone spam for the entire country. I'm asking why the companies that operate the phone networks aren't giving their customers access to a tool this simple.

Because after a month of running it myself, one conclusion is hard to avoid:

The ability to stop unwanted calls from ringing a subscriber's phone already exists.

The remaining question is why subscribers aren't routinely allowed to use it.


Methodology Note

The test number used throughout was (501) 4-GOBLIN, (501) 446-2546. My existing cell number, (859) 248-2284, was permanently forwarded into the same IVR for the duration of the test, so both numbers fed the same call data reflected in this report.

The figures in this report were calculated from the VoIP.ms Call Detail Record for the test period. Only entries recorded as Inbound DID were treated as actual incoming call attempts; separate call-recording transactions and outbound calls were excluded. Legitimate calls were identified using four known phone numbers belonging to callers with valid reasons to contact me. All remaining inbound attempts were classified as unwanted for the purposes of this experiment.

The underlying records can be made available for review, with unrelated personal information redacted.