Detection

Residential proxy detection when every IP looks like a real home

A residential proxy routes traffic through a real household internet connection, and a mobile proxy through a real phone on a carrier network, so a bot or fraudster appears as an ordinary local customer. IP blocklists rarely catch them. Kavra measures the real exit IPs of commercial proxy networks itself and checks every connection for mismatches.

POST /loginVerify

Known account, mobile proxy, new device

  • Exit IP in a mobile proxy pool
  • First time on this device
  • No automation found
Risk71
Your actionStep up with one-time code
What it hides
The real location, network and scale of an actor
Where IPs come from
Home devices, phones and SIM farms
Attacks it enables
Credential stuffing, scraping, multi-accounting
Why blocklists fail
IPs rotate and are shared with real users

What are residential and mobile proxies?

A proxy is a middleman: your site sees the proxy's IP address instead of the visitor's. A residential proxy uses the connection of a real home, assigned by a consumer internet provider. A mobile proxy uses a phone or SIM card on a mobile carrier. To an IP lookup, traffic from either one looks exactly like a customer on home broadband or a phone.

Commercial proxy networks sell access to large pools of these addresses by the gigabyte or by the port. Buyers pick a country, city or carrier, and choose between rotating sessions, which get a new IP on every request or every few minutes, and sticky sessions, which keep one IP for a while so a login or checkout does not break halfway.

Where proxy IPs come from

Not all proxies are equal. The source of the IP decides how normal it looks to your site.

TypeWhere the IP comes fromHow it looks to an IP checkTypical abuse
Datacenter proxyServers rented from hosting and cloud providersEasy to spot: the network belongs to a hosting companyHigh-volume scraping, cheap bots
Residential proxyHome devices running bandwidth-sharing apps, free-app SDKs, browser extensions, or infected machinesA normal home broadband customerAccount takeover, multi-accounting, scraping behind logins
Static residential (ISP) proxyAddresses registered to consumer providers but hosted on serversA home user whose IP never changesLong-lived fake accounts, sneaker and ticket bots
Mobile proxyPhones and SIM cards on carrier networks, often racks of modemsA phone user who shares an IP with many real peopleSignup fraud, bonus abuse, app abuse

How a request travels through a residential proxy

The visitor you see is never the one sending the request.

  1. 01

    The operator connects to a gateway

    A bot, script or antidetect browser sends its traffic to the proxy provider's gateway, with a username that picks the country, city and session type.

  2. 02

    The gateway picks a peer

    The provider forwards the request to one device in its pool: a laptop in a home, a smart TV, or a phone on a carrier network.

  3. 03

    The peer makes the request

    That device sends the request to your site from its own home or mobile IP address, then passes the response back.

  4. 04

    The next request uses another home

    With rotation on, the next request exits from a different household, so rate limits and IP bans never build up.

Attacks that run on residential proxies

Proxies are rarely the attack itself. They are what lets an attack run at scale without tripping IP-based defenses.

AttackWhy the attacker needs a residential IP
Credential stuffingSpread millions of login attempts across homes so no single IP trips a limit
Multi-accounting and bonus abuseGive each fake account its own clean, local IP in the promo's target country
Web scrapingPull prices and listings without the hosting-network IPs that sites already block
Scalping and inventory hoardingPlace many checkout attempts that look like separate local shoppers
Card testingTest stolen cards from IPs that match the card's billing country
Geo-restricted offersAppear to be inside a licensed market or a local pricing region

Why IP blocklists fail against residential proxies

IP blocklists were built for a world where attacks came from servers. Residential proxies turned that around: the IP belongs to a real household, and tomorrow it may belong to a different one. Classic IP reputation, covered in our IP reputation guide, cannot keep up for several reasons.

  • Rotation: an attacker can use a fresh address for every request, so by the time an IP is listed it has moved on.
  • Shared addresses: the same IP carries a real family's traffic the rest of the day. Blocking it blocks them.
  • Carrier sharing: mobile carriers put many phone users behind one public IP, so a block can hit a whole neighborhood of real customers.
  • Public feeds lag: most lists are built from abuse reports after the fact, and proxy pools churn faster than reports arrive.
  • Right country, right provider: the IP passes geolocation and "is this a hosting network" checks by design.

Measure proxy exits, do not guess them

The only reliable way to know which home IPs are proxy exits right now is to look. Kavra runs its own proxy intelligence: it continuously connects through commercial residential and mobile proxy networks and records the real exit IPs they hand out, then combines that with 30+ public reputation feeds. Because an exit is measured, not inferred from complaints, it is known while the pool is still using it.

An exit IP alone is not a verdict, since a real person may use that connection later the same day. So Kavra also checks the connection itself. Its own edge network sees the real connection, not only what the browser claims, and compares it with the rest of the visit.

Signals that expose proxy traffic

Each signal is weak alone. Together they separate a proxy exit from the household behind it.

  • Measured exit

    The IP was recently seen handing out traffic for a commercial proxy network.

  • Timezone and language drift

    The browser's clock and language belong to one region, the IP to another.

  • Device and connection disagree

    The browser claims to be an iPhone, but the connection looks like a desktop system or a server.

  • Longer path than a home line

    Response timing shows an extra hop that a direct home connection would not have.

  • Same device, new IP each visit

    One returning device appears from a different city or carrier on every session.

  • Many actors, one exit

    Unrelated new accounts cluster on the same short-lived exit range within minutes.

Checklist: handling residential proxy traffic

Proxy traffic calls for a different response than a plain IP ban. Use this list to adjust your rules.

  • Treat a proxy exit as evidence to weigh, not as a block on its own.
  • Rate-limit by device and actor, not only by IP address, so rotation stops helping.
  • Check proxy status on the actions that matter: signup, login, promo claim, checkout and payout.
  • Compare the IP location with the device's timezone, language and account history.
  • Step up with a one-time code or an invisible challenge when a known account arrives through a proxy on a new device.
  • Link accounts that share exits and devices, since proxy pools make each account look separate.
  • Review your blocklists: remove broad ranges that also carry real home and mobile customers.

Same IP, two very different visitors

The household on that IP

  • Device, timezone and language match the IP's region
  • Direct connection with normal home timing
  • Same devices return from the same few networks
  • Long, consistent account history

A proxy customer on that IP

  • Device or timezone belong somewhere else
  • Extra hop and a connection that does not fit the device
  • New IP, new city or new carrier every session
  • Fresh accounts or unfamiliar devices on known accounts

Sources

  1. Mi et al., IEEE S&P 2019: Resident Evil: Understanding Residential IP Proxy as a Dark Service
  2. FBI IC3 public service announcement on home devices used as residential proxies (June 5, 2025)
  3. IETF RFC 6888: Common Requirements for Carrier-Grade NATs
  4. RIPE NCC: Autonomous System (AS) Numbers

How Kavra helps

How Kavra detects residential and mobile proxies

Kavra treats the network as one layer of evidence and checks it against the device, the behavior and the account's history.

  • Own proxy intelligence

    Kavra continuously measures real exit IPs of commercial residential and mobile proxy networks, on top of 30+ public feeds.

  • Own edge network

    Kavra sees the real connection, not only what the browser claims, and flags connections that do not fit the device.

  • Contradictions across layers

    IP location, timezone, language, device and connection are compared, so a clean home IP with a mismatched story stands out.

  • Actors, not addresses

    Returning devices are recognized across rotating IPs, so one operator stays one actor however often the exit changes.

  • Step up, do not punish

    Mixed evidence triggers an invisible challenge or your own verification, so real customers on shared IPs keep going.

  • Explained network context

    Every assessment shows the network type, proxy status and why it mattered, so your team can tune rules with confidence.

FAQ

Frequently asked questions

Something else? Talk to our team.

Can residential proxies be detected?

Yes, but rarely by IP reputation alone. Reliable detection combines measured proxy exits, meaning IPs actually observed serving a proxy network, with checks on the connection itself: does it fit the claimed device, does the timezone match the location, and does the same device keep appearing from new IPs. Together these catch proxies that blocklists miss.

Where do residential proxy IPs come from?

Mostly from real consumer devices. Some owners opt in through bandwidth-sharing apps in exchange for payment, others agree to it inside the terms of free apps, games or browser extensions, and some devices are infected with malware. Mobile proxies often come from racks of phones or modems with SIM cards on carrier networks.

Why not just block all proxy IPs?

Because the same address serves real people. A home IP used as a proxy exit this morning may carry a family's shopping tonight, and a mobile carrier IP can be shared by many phone users at once. Blanket blocks cause false positives. It is safer to weigh the proxy signal with device and account evidence.

What is the difference between a residential proxy and a VPN?

A VPN usually sends traffic through servers in data centers, so its exit IPs belong to hosting networks and are easy to classify. A residential proxy exits through a real home or phone connection, so it looks like an ordinary customer. People use VPNs mostly for privacy; residential proxies are mostly bought to look like many different local users.

Are mobile proxies harder to detect than residential proxies?

Often, yes. Carriers put many real phone users behind the same public IP, so an address that carries proxy traffic also carries genuine customers, and blocking it is costly. Detection has to rely more on the device and connection: whether the browser really is a phone and whether the session fits that phone's history.

Is using a residential proxy illegal?

Buying or using proxy access is legal in most countries, and companies use proxies for ad verification, price monitoring and testing. It becomes a problem when used to break a site's terms, take over accounts or commit fraud. Sourcing matters too: IPs from infected devices are used without the owner's knowledge.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.