Objective
This article helps you require encryption for calls on a SIP domain, so signaling and media are protected in transit or relax that requirement if your endpoints cannot support it.
Product
Programmable Voice
Environment
Twilio Console
User Account Permission/Role(s) Required
Your user must have permission to update Voice SIP domains on the account. Without it, the secure media action is not shown.
Procedure
- In the Twilio Console, select Communications in the left sidebar.
- Select Voice, then SIP domains.
- Select the friendly name of the domain you want to change.
- Find the Secure media section and check its Status.
- Select Enable secure media to require encryption, or Disable secure media to stop requiring it. The button always shows the action available for the current status.
- A Secure media enabled or Secure media disabled confirmation appears and the Status updates.
Additional Information
- Secure media protects communications delivered over the public internet by encrypting signaling with Transport Layer Security and media with Secure Real-time Transport Protocol.
- When secure media is enabled, TLS must be used to encrypt SIP messages and SRTP must be used to encrypt the media packets. Any non-encrypted calls are rejected.
- When secure media is disabled, RTP must be used for media packets, SIP messages may be sent unencrypted or encrypted with TLS, and any SRTP-encrypted calls are rejected.
- Because the setting changes which calls are accepted, confirm your endpoints support the encryption mode you choose before switching.
- If the change cannot be applied, the message "We are unable to update secure media settings at this time." appears and the status is unchanged.
This content was generated by AI and reviewed, edited, and verified by a human.