POST /loginVerifyKnown account, mobile proxy, new device
- Exit IP in a mobile proxy pool
- First time on this device
- No automation found
Detection
A residential proxy routes traffic through a real household internet connection, and a mobile proxy through a real phone on a carrier network, so a bot or fraudster appears as an ordinary local customer. IP blocklists rarely catch them. Kavra measures the real exit IPs of commercial proxy networks itself and checks every connection for mismatches.
POST /loginVerifyKnown account, mobile proxy, new device
A proxy is a middleman: your site sees the proxy's IP address instead of the visitor's. A residential proxy uses the connection of a real home, assigned by a consumer internet provider. A mobile proxy uses a phone or SIM card on a mobile carrier. To an IP lookup, traffic from either one looks exactly like a customer on home broadband or a phone.
Commercial proxy networks sell access to large pools of these addresses by the gigabyte or by the port. Buyers pick a country, city or carrier, and choose between rotating sessions, which get a new IP on every request or every few minutes, and sticky sessions, which keep one IP for a while so a login or checkout does not break halfway.
Not all proxies are equal. The source of the IP decides how normal it looks to your site.
| Type | Where the IP comes from | How it looks to an IP check | Typical abuse |
|---|---|---|---|
| Datacenter proxy | Servers rented from hosting and cloud providers | Easy to spot: the network belongs to a hosting company | High-volume scraping, cheap bots |
| Residential proxy | Home devices running bandwidth-sharing apps, free-app SDKs, browser extensions, or infected machines | A normal home broadband customer | Account takeover, multi-accounting, scraping behind logins |
| Static residential (ISP) proxy | Addresses registered to consumer providers but hosted on servers | A home user whose IP never changes | Long-lived fake accounts, sneaker and ticket bots |
| Mobile proxy | Phones and SIM cards on carrier networks, often racks of modems | A phone user who shares an IP with many real people | Signup fraud, bonus abuse, app abuse |
The visitor you see is never the one sending the request.
A bot, script or antidetect browser sends its traffic to the proxy provider's gateway, with a username that picks the country, city and session type.
The provider forwards the request to one device in its pool: a laptop in a home, a smart TV, or a phone on a carrier network.
That device sends the request to your site from its own home or mobile IP address, then passes the response back.
With rotation on, the next request exits from a different household, so rate limits and IP bans never build up.
Proxies are rarely the attack itself. They are what lets an attack run at scale without tripping IP-based defenses.
| Attack | Why the attacker needs a residential IP |
|---|---|
| Credential stuffing | Spread millions of login attempts across homes so no single IP trips a limit |
| Multi-accounting and bonus abuse | Give each fake account its own clean, local IP in the promo's target country |
| Web scraping | Pull prices and listings without the hosting-network IPs that sites already block |
| Scalping and inventory hoarding | Place many checkout attempts that look like separate local shoppers |
| Card testing | Test stolen cards from IPs that match the card's billing country |
| Geo-restricted offers | Appear to be inside a licensed market or a local pricing region |
IP blocklists were built for a world where attacks came from servers. Residential proxies turned that around: the IP belongs to a real household, and tomorrow it may belong to a different one. Classic IP reputation, covered in our IP reputation guide, cannot keep up for several reasons.
The only reliable way to know which home IPs are proxy exits right now is to look. Kavra runs its own proxy intelligence: it continuously connects through commercial residential and mobile proxy networks and records the real exit IPs they hand out, then combines that with 30+ public reputation feeds. Because an exit is measured, not inferred from complaints, it is known while the pool is still using it.
An exit IP alone is not a verdict, since a real person may use that connection later the same day. So Kavra also checks the connection itself. Its own edge network sees the real connection, not only what the browser claims, and compares it with the rest of the visit.
Each signal is weak alone. Together they separate a proxy exit from the household behind it.
The IP was recently seen handing out traffic for a commercial proxy network.
The browser's clock and language belong to one region, the IP to another.
The browser claims to be an iPhone, but the connection looks like a desktop system or a server.
Response timing shows an extra hop that a direct home connection would not have.
One returning device appears from a different city or carrier on every session.
Unrelated new accounts cluster on the same short-lived exit range within minutes.
Proxy traffic calls for a different response than a plain IP ban. Use this list to adjust your rules.
How Kavra helps
Kavra treats the network as one layer of evidence and checks it against the device, the behavior and the account's history.
Kavra continuously measures real exit IPs of commercial residential and mobile proxy networks, on top of 30+ public feeds.
Kavra sees the real connection, not only what the browser claims, and flags connections that do not fit the device.
IP location, timezone, language, device and connection are compared, so a clean home IP with a mismatched story stands out.
Returning devices are recognized across rotating IPs, so one operator stays one actor however often the exit changes.
Mixed evidence triggers an invisible challenge or your own verification, so real customers on shared IPs keep going.
Every assessment shows the network type, proxy status and why it mattered, so your team can tune rules with confidence.
FAQ
Something else? Talk to our team.
Yes, but rarely by IP reputation alone. Reliable detection combines measured proxy exits, meaning IPs actually observed serving a proxy network, with checks on the connection itself: does it fit the claimed device, does the timezone match the location, and does the same device keep appearing from new IPs. Together these catch proxies that blocklists miss.
Mostly from real consumer devices. Some owners opt in through bandwidth-sharing apps in exchange for payment, others agree to it inside the terms of free apps, games or browser extensions, and some devices are infected with malware. Mobile proxies often come from racks of phones or modems with SIM cards on carrier networks.
Because the same address serves real people. A home IP used as a proxy exit this morning may carry a family's shopping tonight, and a mobile carrier IP can be shared by many phone users at once. Blanket blocks cause false positives. It is safer to weigh the proxy signal with device and account evidence.
A VPN usually sends traffic through servers in data centers, so its exit IPs belong to hosting networks and are easy to classify. A residential proxy exits through a real home or phone connection, so it looks like an ordinary customer. People use VPNs mostly for privacy; residential proxies are mostly bought to look like many different local users.
Often, yes. Carriers put many real phone users behind the same public IP, so an address that carries proxy traffic also carries genuine customers, and blocking it is costly. Detection has to rely more on the device and connection: whether the browser really is a phone and whether the session fits that phone's history.
Buying or using proxy access is legal in most countries, and companies use proxies for ad verification, price monitoring and testing. It becomes a problem when used to break a site's terms, take over accounts or commit fraud. Sourcing matters too: IPs from infected devices are used without the owner's knowledge.
Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.