Troubleshooting SIP 403 Forbidden from a carrier
Verified 2026-09-30 · 58 sources · tier 1–2
The IANA SIP Parameters registry lists response code 403 with the description Forbidden and RFC 3261 as its reference 8. In SIP signaling, carriers use this status code to reject requests across authentication, routing, and policy checks 5636.
Triage and carrier qualifiers
WarmTransfer's reading of the sources is that the bare 403 status does not identify the cause on the carriers examined: Twilio distinguishes causes by reason phrase, Telnyx by a cause code appended to the reason phrase, and Microsoft by a separate Microsoft response code, so triage should start from that qualifier rather than from the number 403 4.
In Teams Direct Routing, a Microsoft response code that starts with 560 means the final SIP response code was generated by the SBC, and the last 3 digits are that SIP code; codes that do not start with 560 were generated by a Microsoft service 14. For Microsoft response code 560403 with SIP 403 (Forbidden; Call rejected), Microsoft's suggested action is to check the SBC logs to find why the call was rejected 15. Furthermore, Microsoft states that when an SBC returns a failure to Teams on an outbound Direct Routing call, a SIP 403 or 404 most likely means the PSTN provider is sending the failure, and the resolution is to contact the PSTN provider 17.
For Cisco Webex Calling, Cisco's Local Gateway configuration article describes a diagnostic signature for registration-based Local Gateways that polls SNMP every 10 minutes to detect abnormal call disconnects with SIP errors 403, 488, and 503 7.
Authentication and trunk configuration
On Twilio Elastic SIP Trunking termination calls, Twilio documents 2 causes for a 403 Forbidden response to an INVITE: the source IP address is not on the trunk's ACL, or the INVITE's authentication digest does not match the trunk's Credentials List 56. Twilio advises checking the received parameter on the Via header of the 403 response to see the IP address from which Twilio received the SIP request 57. Twilio says that if the 403 answers the initial INVITE that carries no digest the problem is most likely the ACL, and if it answers the INVITE carrying an auth digest sent after a 407 the problem is most likely the credentials 58. Twilio suggests temporarily removing the Credentials List from the trunk to test whether the call succeeds with the ACL alone 55.
Telnyx returns 403 with cause code D25 when it cannot locate the account or number from the source IP and username, and with D29 when the INVITE carries an invalid X-Telnyx-Token or IP 38. Telnyx also returns 403 when the outbound profile is disabled (D15), the SIP connection is disabled (D16), or the account is disabled (D17), and when the connection has no outbound profile assigned (D7 and D38) 47. For SIP REGISTER requests, Telnyx returns 403 Forbidden when the authentication username is empty (R14), has invalid characters (R16), is shorter than 4 characters (R17), or does not match the To and From user parts (R18) 48.
For Microsoft response code 510532 with SIP 403 (No trunk config was found), Microsoft says to verify that calls come from the SBC FQDN associated with the tenant and that the FQDN in the Contact header of the SIP INVITE is registered under the tenant 10.
Caller ID and STIR/SHAKEN
RFC 3325 defines P-Asserted-Identity as an Informational RFC header field used among trusted SIP entities to carry the identity of the user sending a SIP message as it was verified by authentication 21. On Teams Direct Routing outbound calls, the caller ID is carried in the From and P-Asserted-Identity headers, and the P-Asserted-Identity header contains the phone number of the user who is billed for the call 16.
Carriers enforce specific rules on caller identity headers:
- Telnyx's caller ID policy lists the headers it reads for caller ID in priority order: P-Preferred-Identity user highest, then P-Asserted-Identity user, then Remote-Party-ID user, then From user lowest 35.
- Telnyx returns 403 with cause code D35 when the caller ID in the INVITE is not valid, and the fix is to send +E.164 numbers in the From, P-Asserted-Identity, or Remote-Party-ID headers 39.
- Telnyx rejects an outbound call with 403 and cause code D51 (Unverified origination number) when the caller ID is a non-Telnyx number that has not been verified 44.
- Telnyx returns 403 with cause code D36 when an outbound call uses another Telnyx user's number as caller ID 40.
- Telnyx returns 403 with cause code D46 when the originating number is listed in a do-not-originate registry, indicating a number meant only to receive inbound calls was used to place an outbound call 43.
- Telnyx returns 403 with cause code D54 (Restricted origination number) when the originating caller ID is restricted from placing outbound calls through Telnyx because of reputation concerns and risk validations, with contacting support as the remedy 45.
- Twilio documents a '403 Invalid Caller ID' failure on trunk termination calls tied to Free Trial accounts, which must use a Twilio-verified caller ID for both To and From numbers 53. The listed fixes are sending To and From in E.164 with the plus sign, setting From to a Twilio number or verified caller ID, and making any Remote-Party-ID in the INVITE reference a valid caller ID 51.
Regarding STIR/SHAKEN standards, RFC 8224 allows a STIR verification service to send a 403 response, optionally with the reason phrase Stale Date, when a request's Date header field value is older than local freshness policy permits 28. RFC 8224 allows the same 403 response when the iat value in a full-form PASSporT is older than local freshness policy permits 29. RFC 8224 proposes no authorization policy based on a valid, invalid, absent, or stale Identity header, stating that how a message is handled after verification depends on the implementation and local policy 27. Other verification responses under RFC 8224 include 428 Use Identity Header, 436 Bad Identity Info, 437 Unsupported Credential, and 438 Invalid Identity Header 23242526. The IANA SIP Parameters registry attributes response codes 428, 436, 437, and 438 to RFC 8224, 607 to RFC 8197, and 608 to RFC 8688 9.
RFC 8588 defines the SHAKEN attest claim with 3 values, A, B and C, corresponding to Full Attestation, Partial Attestation and Gateway Attestation 30. RFC 8588 describes attest and origid claims as carrying additional information from the signer to the consumer of the PASSporT, specifying no SIP response code or call rejection behaviour tied to attestation level 31. WarmTransfer's reading of the sources is that a 403 that a carrier attributes to STIR/SHAKEN attestation level is carrier local policy rather than standardised behaviour, because the STIR and SHAKEN RFCs examined define 403 only for stale Date or iat values and define no rejection by attestation level 3.
Additionally, RFC 8197 defines 607 Unwanted so that a called party can indicate that a call or message was unwanted, signalling that the caller's identity rather than the callee's availability caused the rejection 22. RFC 8688 defines 608 Rejected so that a calling party can learn that an intermediary, rather than the called party, rejected the call attempt 32. RFC 8688 requires that a Call-Info header field in a 608 response carry the purpose parameter jwscard and refer to a valid JWS encoding of a jCard, giving a blocked caller a contact for redress 33.
Destination restrictions and account policies
Carriers enforce geographic and regulatory boundaries that trigger 403 responses:
- Twilio documents a '403 No International Authorization' failure that occurs when a trunk call targets a country not enabled in the account's Voice Geographic Permissions 54.
- Twilio documents a '403 Phone number is blocked for verification' failure meaning Twilio has blocked the destination number, with contacting Twilio Support as the remedy if the block is unintended 50.
- Twilio error 32203 means Twilio blocked an outbound Elastic SIP Trunking call before it reached the destination because the destination was judged high fraud risk, regulation prevents the call, or a +1 destination was called without a valid Primary Customer Profile 49.
- Microsoft response code 510563 with SIP 403 means the user is only allowed to make domestic calls and attempted an international call, with the suggested action being to check whether the user is limited to domestic calling 13.
- Microsoft response codes 510560 (user is not Enterprise Voice enabled) and 510562 (user is not allowed to make outbound PSTN calls) both carry SIP 403, and the suggested action for both is to verify the Phone System license and the user's Direct Routing enablement 12.
- For Microsoft response code 510559 with SIP 403 (No viable path), Microsoft says to make sure the dialed number matches a number pattern in a voice route for the user, and notes the error can come from a misdialed number or a customer policy that prevents calls to specific countries, regions or number patterns 11.
- Telnyx states that by default every Outbound Voice Profile allows traffic only to destinations in the United States and Canada 46. Telnyx rejects an outbound call with 403 and cause code D13 when the dialed number is not in a country whitelisted in the outbound voice profile, with the fix being to add the destination country to that profile's whitelist 36.
- Telnyx returns 403 with cause code D41 when the dialed number matches a forbidden prefix used for fraud prevention and with D58 when the destination number is restricted, both directing the customer to Telnyx support 42.
Channel and spending limits
Telnyx uses 403 for concurrent-call limit violations: D1 for the user channel limit, D2 for the outbound profile channel limit, D3 for the connection channel limit and D22 for any of those channel limits 34. Telnyx returns 403 with cause code D24 when the dialed destination's rate per minute exceeds the maximum rate per minute set on the outbound voice profile 37. Telnyx returns 403 with cause code D39 when the user's daily spend limit for international calls has been reached 41.
See also
- SIP response codes and failure interpretation
- SIP transactions dialogs and call setup
- ITU-T Q.850 call clearing cause values
- SIP capture and analysis with Wireshark and sngrep and HOMER
Applicability
Applies to: IANA SIP, Twilio Elastic SIP Trunking, Telnyx SIP Trunking, SIP trunking, Microsoft Teams Phone Direct Routing, Cisco Webex Calling Local Gateway (IOS XE), IETF SIP, IETF STIR, IETF SHAKEN PASSporT, and IETF STIR SHAKEN. Deployments: multi-tenant, any, and on-premises-gateway. Sources checked 2026-09-30. Microsoft's SIP 403 response code guidance is stated to apply to Teams Direct Routing PSTN calls and not to Microsoft Calling Plan or Operator Connect deployments 18. For Twilio, the primary customer profile rule cited in error 32203 applies to +1 destinations 49, and the '403 Invalid Caller ID' failure applies to Free Trial accounts 53.
What remains uncertain
Twilio's error dictionary pages for 32201, 32202, 32203 and 32205 do not state which SIP response code accompanies the error 52. Whether carriers other than Twilio, Telnyx, and Microsoft Teams utilize custom headers or specific reason phrase formats for 403 responses is not covered by the sources below.
See also
Referenced by
- Troubleshooting SIP 404 Not Found and 484 Address Incomplete call failures — Parallel symptom-led troubleshooting topic for another 4xx rejection; 403 is policy/authorisation while 404/484 are address resolution.
Sources
- 1For US terminating-provider analytics blocking the regulation names 603+ rather than 403, so a 403 on an outbound US call points first to authorization or account policy at the rejecting carrier rather than to analytics-based blocking.inferred47 CFR § 64.1200 - Delivery restrictions · paragraph (k)(9), read together with the carrier 403 cause lists in this packet · Checked 2026-09-30
- 2Vendor use of 403 is broader than the RFC 3261 definition suggests: Twilio sends 403 for a wrong digest password and Telnyx for exceeded channel limits, conditions that a configuration change fixes, so the RFC's advice not to repeat the request is best read as applying to the unchanged request.inferredTroubleshooting your Trunk · Termination Calls > Problem: You are getting '403 Forbidden' responses to your INVITE requests, read against RFC 3261 section 21.4.4 · Checked 2026-09-30
- 3A 403 that a carrier attributes to STIR/SHAKEN attestation level is carrier local policy rather than standardised behaviour, because the STIR and SHAKEN RFCs examined define 403 only for stale Date or iat values and define no rejection by attestation level.inferredRFC 8224: Authenticated Identity Management in the Session Initiation Protocol (SIP) · sections 6.2.1 and 6.2.2 read together with RFC 8588 sections 4 and 9 · Checked 2026-09-30
- 4The bare 403 status does not identify the cause on the carriers examined: Twilio distinguishes causes by reason phrase, Telnyx by a cause code appended to the reason phrase, and Microsoft by a separate Microsoft response code, so triage should start from that qualifier rather than from the number 403.inferredTelnyx SIP Response Codes · 403 list as a whole, compared with the Twilio trunk troubleshooting page and the Microsoft 403 response code page · Checked 2026-09-30
- 547 CFR 64.1200(k)(9) requires a terminating provider that blocks calls based on an analytics program to return SIP code 603+ on IP networks, and requires all voice service providers in the call path to transmit the response code to the origination point.47 CFR § 64.1200 - Delivery restrictions · paragraph (k)(9) and (k)(9)(i) · Checked 2026-09-30
- 647 CFR 64.1200(k)(9) requires ISUP code 21 with cause location user on non-IP networks for analytics-based blocking, and requires SIP 603+ to map to ISUP 21 at IP to non-IP conversion.47 CFR § 64.1200 - Delivery restrictions · paragraphs (k)(9)(ii) to (k)(9)(iv) · Checked 2026-09-30
- 7Cisco's Local Gateway configuration article for Webex Calling describes a diagnostic signature for registration-based Local Gateways that polls SNMP every 10 minutes to detect abnormal call disconnects with SIP errors 403, 488 and 503.Configure Local Gateway on Cisco IOS XE for Webex Calling · Monitor and troubleshoot Registration based Local Gateway with diagnostic signatures · Checked 2026-09-30
- 8The IANA SIP Parameters registry lists response code 403 with the description Forbidden and RFC 3261 as its reference.Session Initiation Protocol (SIP) Parameters · Response Codes registry, row 403 · Checked 2026-09-30
- 9The IANA SIP Parameters registry attributes response codes 428, 436, 437 and 438 to RFC 8224, 607 to RFC 8197 and 608 to RFC 8688.Session Initiation Protocol (SIP) Parameters · Response Codes registry, rows 428 436 437 438 607 608 · Checked 2026-09-30
- 10For Microsoft response code 510532 with SIP 403 (No trunk config was found), Microsoft says to verify that calls come from the SBC FQDN associated with the tenant and that the FQDN in the Contact header of the SIP INVITE is registered under the tenant.SIP 403 and Microsoft response codes - Microsoft Teams · 510532 403 No trunk config was found · Checked 2026-09-30
- 11For Microsoft response code 510559 with SIP 403 (No viable path), Microsoft says to make sure the dialed number matches a number pattern in a voice route for the user, and notes the error can come from a misdialed number or a customer policy that prevents calls to specific countries, regions or number patterns.SIP 403 and Microsoft response codes - Microsoft Teams · 510559 403 Get Outbound routing - No viable path (Forbidden) · Checked 2026-09-30
- 12Microsoft response codes 510560 (user is not Enterprise Voice enabled) and 510562 (user is not allowed to make outbound PSTN calls) both carry SIP 403, and the suggested action for both is to verify the Phone System license and the user's Direct Routing enablement.SIP 403 and Microsoft response codes - Microsoft Teams · 510560 403 User is not Enterprise Voice enabled; 510562 403 User is not allowed to make outbound PSTN Calls · Checked 2026-09-30
- 13Microsoft response code 510563 with SIP 403 means the user is only allowed to make domestic calls and attempted an international call; the suggested action is to check whether the user is limited to domestic calling.SIP 403 and Microsoft response codes - Microsoft Teams · 510563 403 User is only allowed to make domestic calls. This is an international call · Checked 2026-09-30
- 14In Teams Direct Routing a Microsoft response code that starts with 560 means the final SIP response code was generated by the SBC, and the last three digits are that SIP code; codes that do not start with 560 were generated by a Microsoft service.Microsoft and SIP response codes · Direct Routing error codes · Checked 2026-09-30
- 15For Microsoft response code 560403 with SIP 403 (Forbidden; Call rejected), Microsoft's suggested action is to check the SBC logs to find why the call was rejected.SIP 403 and Microsoft response codes - Microsoft Teams · 560403 403 Forbidden; Call rejected · Checked 2026-09-30
- 16On Teams Direct Routing outbound calls the caller ID is carried in the From and P-Asserted-Identity headers, and the P-Asserted-Identity header contains the phone number of the user who is billed for the call.Issues with outbound calls - Microsoft Teams · Incorrect caller ID displayed to the recipient · Checked 2026-09-30
- 17Microsoft states that when an SBC returns a failure to Teams on an outbound Direct Routing call, a SIP 403 or 404 most likely means the PSTN provider is sending the failure, and the resolution is to contact the PSTN provider.Issues with outbound calls - Microsoft Teams · Connection to the SBC not established > Cause 2 and Resolution 2 · Checked 2026-09-30
- 18Microsoft's SIP 403 response code guidance is stated to apply to Teams Direct Routing PSTN calls and not to Microsoft Calling Plan or Operator Connect deployments.SIP 403 and Microsoft response codes - Microsoft Teams · Note at top of article · Checked 2026-09-30
- 19RFC 3261 defines 403 Forbidden as a response where the server understood the request but refuses to fulfil it, states that authorization will not help, and says the request should not be repeated.RFC 3261 — SIP: Session Initiation Protocol · section 21.4.4 (403 Forbidden) · Checked 2026-09-30
- 20RFC 3261 has a registrar answer a REGISTER with 403 Forbidden when the authenticated user is not authorized to modify the bindings of the address-of-record.RFC 3261 — SIP: Session Initiation Protocol · section 10.3 (Processing REGISTER Requests), authorization step · Checked 2026-09-30
- 21RFC 3325, an Informational RFC, defines P-Asserted-Identity as a header field used among trusted SIP entities to carry the identity of the user sending a SIP message as it was verified by authentication.RFC 3325: Private Extensions to the Session Initiation Protocol (SIP) for Asserted Identity within Trusted Networks · section 9.1 · Checked 2026-09-30
- 22RFC 8197 defines 607 Unwanted so that a called party can indicate that a call or message was unwanted, signalling that the caller's identity rather than the callee's availability caused the rejection.RFC 8197: A SIP Response Code for Unwanted Calls · abstract; section 3; section 4 · Checked 2026-09-30
- 23RFC 8224 has a verification service send 428 Use Identity Header when an Identity header field is required but none was received without a ppt parameter or with a supported ppt value.RFC 8224: Authenticated Identity Management in the Session Initiation Protocol (SIP) · section 6.2.2 · Checked 2026-09-30
- 24RFC 8224 defines 436 Bad Identity Info as indicating that the verification service could not acquire the credentials needed to validate the signature in an Identity header field.RFC 8224: Authenticated Identity Management in the Session Initiation Protocol (SIP) · section 6.2.2 · Checked 2026-09-30
- 25RFC 8224 defines 437 Unsupported Credential as sent when the verification service can acquire or already holds the credential named by the info parameter but does not support it.RFC 8224: Authenticated Identity Management in the Session Initiation Protocol (SIP) · section 6.2.2 · Checked 2026-09-30
- 26RFC 8224 defines 438 Invalid Identity Header as indicating that no Identity header field in the request carried a valid and supported PASSporT object.RFC 8224: Authenticated Identity Management in the Session Initiation Protocol (SIP) · section 6.2.2 · Checked 2026-09-30
- 27RFC 8224 proposes no authorization policy based on a valid, invalid, absent or stale Identity header; how a message is handled after verification depends on the implementation and local policy.RFC 8224: Authenticated Identity Management in the Session Initiation Protocol (SIP) · section 6.2.1 · Checked 2026-09-30
- 28RFC 8224 allows a STIR verification service to send a 403 response, optionally with the reason phrase Stale Date, when a request's Date header field value is older than local freshness policy permits.RFC 8224: Authenticated Identity Management in the Session Initiation Protocol (SIP) · section 6.2.2 (Failure Response Codes Sent by a Verification Service), final paragraph · Checked 2026-09-30
- 29RFC 8224 allows the same 403 response when the iat value in a full-form PASSporT is older than local freshness policy permits.RFC 8224: Authenticated Identity Management in the Session Initiation Protocol (SIP) · section 6.2.2, final paragraph · Checked 2026-09-30
- 30RFC 8588 defines the SHAKEN attest claim with three values, A, B and C, corresponding to Full Attestation, Partial Attestation and Gateway Attestation.RFC 8588: Personal Assertion Token (PaSSporT) Extension for Signature-based Handling of Asserted information using toKENs (SHAKEN) · section 4 · Checked 2026-09-30
- 31RFC 8588 describes the attest and origid claims as carrying additional information from the signer to the consumer of the PASSporT, and it specifies no SIP response code or call rejection behaviour tied to attestation level.RFC 8588: Personal Assertion Token (PaSSporT) Extension for Signature-based Handling of Asserted information using toKENs (SHAKEN) · section 9 · Checked 2026-09-30
- 32RFC 8688 defines 608 Rejected so that a calling party can learn that an intermediary, rather than the called party, rejected the call attempt.RFC 8688: A Session Initiation Protocol (SIP) Response Code for Rejected Calls · abstract; section 3.1 · Checked 2026-09-30
- 33RFC 8688 requires that a Call-Info header field in a 608 response carry the purpose parameter jwscard and refer to a valid JWS encoding of a jCard, giving a blocked caller a contact for redress.RFC 8688: A Session Initiation Protocol (SIP) Response Code for Rejected Calls · section 3.1 · Checked 2026-09-30
- 34Telnyx uses 403 for concurrent-call limit violations: D1 for the user channel limit, D2 for the outbound profile channel limit, D3 for the connection channel limit and D22 for any of those channel limits.Telnyx SIP Response Codes · 403 list, cause codes D1 D2 D3 D22 · Checked 2026-09-30
- 35Telnyx's caller ID policy lists the headers it reads for caller ID in priority order: P-Preferred-Identity user highest, then P-Asserted-Identity user, then Remote-Party-ID user, then From user lowest.Caller ID Number Policy · header priority list (heading not captured) · Checked 2026-09-30
- 36Telnyx rejects an outbound call with 403 and cause code D13 when the dialed number is not in a country whitelisted in the outbound voice profile; the fix is to add the destination country to that profile's whitelist.Telnyx SIP Response Codes · 403 list, cause code D13 · Checked 2026-09-30
- 37Telnyx returns 403 with cause code D24 when the dialed destination's rate per minute exceeds the maximum rate per minute set on the outbound voice profile.Telnyx SIP Response Codes · 403 list, cause code D24 · Checked 2026-09-30
- 38Telnyx returns 403 with cause code D25 when it cannot locate the account or number from the source IP and username, and with D29 when the INVITE carries an invalid X-Telnyx-Token or IP.Telnyx SIP Response Codes · 403 list, cause codes D25 and D29 · Checked 2026-09-30
- 39Telnyx rejects an outbound call with 403 and cause code D35 when the caller ID in the INVITE is not valid; the fix is to send +E.164 numbers in the From, P-Asserted-Identity or Remote-Party-ID headers.Telnyx SIP Response Codes · 403 list, cause code D35 · Checked 2026-09-30
- 40Telnyx returns 403 Forbidden with cause code D36 when an outbound call uses another Telnyx user's number as caller ID.Telnyx SIP Response Codes · 403 list, cause code D36 · Checked 2026-09-30
- 41Telnyx returns 403 with cause code D39 when the user's daily spend limit for international calls has been reached.Telnyx SIP Response Codes · 403 list, cause code D39 · Checked 2026-09-30
- 42Telnyx returns 403 with cause code D41 when the dialed number matches a forbidden prefix used for fraud prevention and with D58 when the destination number is restricted; both direct the customer to Telnyx support.Telnyx SIP Response Codes · 403 list, cause codes D41 and D58 · Checked 2026-09-30
- 43Telnyx returns 403 with cause code D46 when the originating number is listed in a do-not-originate registry, meaning a number meant only to receive inbound calls was used to place an outbound call.Telnyx SIP Response Codes · 403 list, cause code D46 · Checked 2026-09-30
- 44Telnyx rejects an outbound call with 403 and cause code D51 (Unverified origination number) when the caller ID is a non-Telnyx number that has not been verified.Telnyx SIP Response Codes · 403 list, cause code D51 · Checked 2026-09-30
- 45Telnyx returns 403 with cause code D54 (Restricted origination number) when the originating caller ID is restricted from placing outbound calls through Telnyx because of reputation concerns and risk validations; the remedy is to contact support.Telnyx SIP Response Codes · 403 list, cause code D54 · Checked 2026-09-30
- 46Telnyx states that by default every Outbound Voice Profile allows traffic only to destinations in the United States and Canada.Troubleshooting Call Completion · outbound calls section on whitelisted destinations (heading not captured) · Checked 2026-09-30
- 47Telnyx returns 403 when the outbound profile is disabled (D15), the SIP connection is disabled (D16) or the account is disabled (D17), and when the connection has no outbound profile assigned (D7 and D38).Telnyx SIP Response Codes · 403 list, cause codes D7 D15 D16 D17 D38 · Checked 2026-09-30
- 48Telnyx returns 403 Forbidden to a REGISTER whose authentication username is empty (R14), has invalid characters (R16), is shorter than four characters (R17) or does not match the To and From user parts (R18).Telnyx SIP Response Codes · 403 list, cause codes R14 R16 R17 R18 · Checked 2026-09-30
- 49Twilio error 32203 means Twilio blocked an outbound Elastic SIP Trunking call before it reached the destination because the destination was judged high fraud risk, regulation prevents the call, or a +1 destination was called without a valid Primary Customer Profile.32203: SIP: Call blocked by Twilio · Description; Possible causes · Checked 2026-09-30
- 50Twilio documents a '403 Phone number is blocked for verification' failure meaning Twilio has blocked the destination number, with contacting Twilio Support as the remedy if the block is unintended.Troubleshooting your Trunk · Termination Calls > Problem: The call fails with a '403 Phone number is blocked for verification' error · Checked 2026-09-30
- 51For the '403 Invalid Caller ID' failure Twilio's listed fixes are to send To and From in E.164 with the plus sign, to set From to a Twilio number or verified caller ID, and to make any Remote-Party-ID in the INVITE reference a valid caller ID.Troubleshooting your Trunk · Termination Calls > Problem: The call fails with a '403 Invalid Caller ID' or a '400 the number is unverified' · Checked 2026-09-30
- 52Twilio's error dictionary pages for 32201, 32202, 32203 and 32205 do not state which SIP response code accompanies the error.32203: SIP: Call blocked by Twilio · whole page (no SIP response code named); same observation on the 32201 32202 and 32205 pages · Checked 2026-09-30
- 53Twilio documents a '403 Invalid Caller ID' failure on trunk termination calls and ties it to Free Trial accounts, which must use a Twilio-verified caller ID for both the To and From numbers.Troubleshooting your Trunk · Termination Calls > Problem: The call fails with a '403 Invalid Caller ID' or a '400 the number is unverified' · Checked 2026-09-30
- 54Twilio documents a '403 No International Authorization' failure that occurs when a trunk call targets a country not enabled in the account's Voice Geographic Permissions.Troubleshooting your Trunk · Termination Calls > Problem: The call fails with a '403 No International Authorization' error · Checked 2026-09-30
- 55Twilio suggests temporarily removing the Credentials List from the trunk to test whether the call succeeds with the ACL alone.Troubleshooting your Trunk · Termination Calls > Problem: You are getting '403 Forbidden' responses to your INVITE requests · Checked 2026-09-30
- 56Twilio documents two causes for a 403 Forbidden response to an INVITE on an Elastic SIP Trunking termination call: the source IP address is not on the trunk's ACL, or the INVITE's authentication digest does not match the trunk's Credentials List.Troubleshooting your Trunk · Termination Calls > Problem: You are getting '403 Forbidden' responses to your INVITE requests · Checked 2026-09-30
- 57Twilio advises checking the received parameter on the Via header of the 403 response to see the IP address from which Twilio received the SIP request.Troubleshooting your Trunk · Termination Calls > Problem: You are getting '403 Forbidden' responses to your INVITE requests · Checked 2026-09-30
- 58Twilio says that if the 403 answers the initial INVITE that carries no digest the problem is most likely the ACL, and if it answers the INVITE carrying an auth digest sent after a 407 the problem is most likely the credentials.Troubleshooting your Trunk · Termination Calls > Problem: You are getting '403 Forbidden' responses to your INVITE requests · Checked 2026-09-30
Documents
47 CFR § 64.1200 - Delivery restrictions
RFC 3261 — SIP: Session Initiation Protocol
RFC 3325: Private Extensions to the Session Initiation Protocol (SIP) for Asserted Identity within Trusted Networks
RFC 8197: A SIP Response Code for Unwanted Calls
RFC 8224: Authenticated Identity Management in the Session Initiation Protocol (SIP)
RFC 8588: Personal Assertion Token (PaSSporT) Extension for Signature-based Handling of Asserted information using toKENs (SHAKEN)
RFC 8688: A Session Initiation Protocol (SIP) Response Code for Rejected Calls
Session Initiation Protocol (SIP) Parameters
32203: SIP: Call blocked by Twilio
Caller ID Number Policy
Configure Local Gateway on Cisco IOS XE for Webex Calling
Issues with outbound calls - Microsoft Teams
Microsoft and SIP response codes
SIP 403 and Microsoft response codes - Microsoft Teams
Telnyx SIP Response Codes
Troubleshooting Call Completion
Troubleshooting your Trunk
Cite this page
APA
WarmTransfer. (2026, September 30). Troubleshooting SIP 403 Forbidden from a carrier. WarmTransfer. https://warmtransfer.net/knowledge/sip-403-forbidden-troubleshooting
BibTeX
@misc{warmtransfer-sip-403-forbidden-troubleshooting,
title = {Troubleshooting SIP 403 Forbidden from a carrier},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sip-403-forbidden-troubleshooting},
note = {Verified 2026-09-30}
}