Phantom (Ghost) Calls on VoIP Phones
Phantom calls — also called ghost calls — are unsolicited inbound rings where no one is on the line. They occur when an IP phone’s SIP port is reachable over the internet and targeted by automated port-scanning software or bad actors probing for open VoIP endpoints.
SIPSTACK-provisioned phones are protected against most phantom call sources through hardened firmware settings and server-side filtering. If you are experiencing phantom calls, contact support to verify your device is properly provisioned.
Why Phantom Calls Happen
Section titled “Why Phantom Calls Happen”IP phones listen on SIP port 5060 (or a configurable alternative). Automated scanners continuously probe internet-exposed IP addresses for open SIP ports. When they find one, they send SIP INVITE packets — which appear to the phone as an incoming call.
Common indicators of phantom calls:
- Incoming calls with unusual caller IDs starting with 100, 1000, 1001, or other non-geographic prefixes
- Calls that ring but immediately drop when answered
- Calls occurring late at night or in rapid succession
- Dead silence when answered
If You Are Receiving Phantom Calls
Section titled “If You Are Receiving Phantom Calls”Step 1: Check internet connectivity
Confirm your internet connection is stable. If your connection dropped and reconnected, your router may have received a new public IP address that was previously used by another party.
Step 2: Verify SIPSTACK provisioning
Phones provisioned through SIPSTACK’s configuration server have settings that block direct IP calling and require SIP messages to originate from SIPSTACK’s proxy servers. Confirm your phone is provisioned via the SIPSTACK provisioning server — not manually configured.
Contact SIPSTACK support if you are unsure whether your device is correctly provisioned.
Step 3: Review firewall settings
A properly configured network firewall should not expose port 5060 directly to the internet. Work with your network administrator to:
- Block inbound SIP traffic (port 5060/UDP and TCP) from all sources except SIPSTACK’s known SIP proxy IP ranges
- Enable stateful firewall inspection so only responses to outbound sessions are allowed in
- Disable SIP ALG (Application Layer Gateway) on your router — SIP ALG often breaks SIP traffic and does not improve security
Phone-Level Settings to Block Phantom Calls
Section titled “Phone-Level Settings to Block Phantom Calls”If you have direct access to your phone’s configuration (not managed by SIPSTACK provisioning), apply these settings to reduce phantom call exposure:
| Setting | Recommended value |
|---|---|
| Validate incoming SIP messages | Enabled |
| Check User ID on incoming INVITE | Enabled |
| Accept SIP traffic from SIP proxy only | Enabled |
| Allow direct IP calls | Disabled |
| SIP contact register | LAN address (not WAN) |
Note: Enabling “Check User ID on incoming INVITE” disables direct IP-to-IP calling. This is the correct setting for phones registered to a SIP proxy like SIPSTACK.
Security Risk of Exposed SIP Ports
Section titled “Security Risk of Exposed SIP Ports”An exposed SIP port is not only a nuisance — it is a security risk. Attackers who successfully authenticate to your phone service can:
- Place long-distance calls at your expense
- Use your numbers to conduct toll fraud or spam campaigns
- Access voicemail or call history
If you receive phantom calls and suspect unauthorized access to your account, contact SIPSTACK support immediately.