Skip to content

Inbound Permissions

Inbound Permissions let you accept or reject incoming calls based on the caller’s number, before any Inbound Routing or IVR logic runs. This is the platform’s first line of defense against nuisance and abusive callers: you can block a specific harassing number, block spoofed or invalid caller IDs, or - conversely - build an allow-list so that only known numbers get through to a sensitive line. Because the check happens up front, blocked calls never consume queue slots, ring phones, or reach voicemail.

Enabling Inbound Permissions

Inbound Permissions checking is disabled by default to avoid unnecessary overhead during call processing. When disabled, a notice is displayed on the Inbound Permissions screen.

Use the Enable Checking button above the grid, or set the Dialplan Variable TL_CHECK_INBOUND_PERMISSIONS to 1 by hand. Setting it to 0 or removing the variable disables checking. The variable is global, so the button appears only for administrators who can edit Dialplan Variables.

Create/Edit Inbound Permissions

Description. A short description of the rule.

Caller ID Pattern(s). A number or pattern to match inbound caller IDs. Accepts multiple values separated by a comma. Prefix a pattern with _ to use dialplan pattern matching:

  • X — matches any digit 0-9
  • Z — matches any digit 1-9
  • N — matches any digit 2-9
  • [13-5] — matches any digit in the brackets
  • . — matches one or more characters

Action. What to do when a caller ID matches the pattern:

  • Deny — reject the call
  • Allow — let the call through

Examples

  • Block one harassing number. Caller ID Pattern 14155550199, Action Deny.
  • Block calls with no/anonymous caller ID. Match the empty or literal anonymous value your carrier delivers and set Action Deny (verify the exact value your carrier sends first).
  • Allow-list a private line. For a line only known contacts should reach, add Allow rules for the permitted numbers and a final broad Deny (_.) to reject everything else. Order matters: define specific allows before the catch-all deny.

Best practices

  • Turn checking on deliberately. With TL_CHECK_INBOUND_PERMISSIONS off (the default), rules are ignored. Define your rules first, then enable it, so a partial policy doesn’t unexpectedly drop calls.
  • Use deny-lists for known bad callers and allow-lists only where truly needed - a broad allow-list plus catch-all deny will silently reject every legitimate caller you forgot to add.
  • Remember caller ID can be spoofed. Blocking a number stops that displayed number, but a determined caller can change it. Treat this as one layer among several.
  • Test after enabling by placing a call from a number you expect to pass and one you expect to be blocked.