# Residential proxy detection when every IP looks like a real home

Source: https://kavralab.com/detect/residential-proxies/

A **residential proxy** routes traffic through a real household internet connection, and a **mobile proxy** through a real phone on a carrier network, so a bot or fraudster appears as an ordinary local customer. IP blocklists rarely catch them. Kavra measures the real exit IPs of commercial proxy networks itself and checks every connection for mismatches.

- **What it hides:** The real location, network and scale of an actor
- **Where IPs come from:** Home devices, phones and SIM farms
- **Attacks it enables:** Credential stuffing, scraping, multi-accounting
- **Why blocklists fail:** IPs rotate and are shared with real users

## What are residential and mobile proxies?

A proxy is a middleman: your site sees the proxy's IP address instead of the visitor's. A [residential proxy](https://kavralab.com/glossary/residential-proxy/) uses the connection of a real home, assigned by a consumer internet provider. A [mobile proxy](https://kavralab.com/glossary/mobile-proxy/) uses a phone or SIM card on a mobile carrier. To an IP lookup, traffic from either one looks exactly like a customer on home broadband or a phone.

Commercial proxy networks sell access to large pools of these addresses by the gigabyte or by the port. Buyers pick a country, city or carrier, and choose between rotating sessions, which get a new IP on every request or every few minutes, and sticky sessions, which keep one IP for a while so a login or checkout does not break halfway.

## Where proxy IPs come from

Not all proxies are equal. The source of the IP decides how normal it looks to your site.

| Type | Where the IP comes from | How it looks to an IP check | Typical abuse |
|---|---|---|---|
| [Datacenter proxy](https://kavralab.com/glossary/datacenter-proxy/) | Servers rented from hosting and cloud providers | Easy to spot: the network belongs to a hosting company | High-volume scraping, cheap bots |
| Residential proxy | Home devices running bandwidth-sharing apps, free-app SDKs, browser extensions, or infected machines | A normal home broadband customer | Account takeover, multi-accounting, scraping behind logins |
| Static residential (ISP) proxy | Addresses registered to consumer providers but hosted on servers | A home user whose IP never changes | Long-lived fake accounts, sneaker and ticket bots |
| Mobile proxy | Phones and SIM cards on carrier networks, often racks of modems | A phone user who shares an IP with many real people | Signup fraud, bonus abuse, app abuse |

## How a request travels through a residential proxy

The visitor you see is never the one sending the request.

1. **The operator connects to a gateway**: A bot, script or [antidetect browser](https://kavralab.com/detect/antidetect-browsers/) sends its traffic to the proxy provider's gateway, with a username that picks the country, city and session type.
2. **The gateway picks a peer**: The provider forwards the request to one device in its pool: a laptop in a home, a smart TV, or a phone on a carrier network.
3. **The peer makes the request**: That device sends the request to your site from its own home or mobile IP address, then passes the response back.
4. **The next request uses another home**: With rotation on, the next request exits from a different household, so rate limits and IP bans never build up.

## Attacks that run on residential proxies

Proxies are rarely the attack itself. They are what lets an attack run at scale without tripping IP-based defenses.

| Attack | Why the attacker needs a residential IP |
|---|---|
| [Credential stuffing](https://kavralab.com/solutions/credential-stuffing/) | Spread millions of login attempts across homes so no single IP trips a limit |
| Multi-accounting and bonus abuse | Give each fake account its own clean, local IP in the promo's target country |
| [Web scraping](https://kavralab.com/solutions/web-scraping/) | Pull prices and listings without the hosting-network IPs that sites already block |
| Scalping and inventory hoarding | Place many checkout attempts that look like separate local shoppers |
| Card testing | Test stolen cards from IPs that match the card's billing country |
| Geo-restricted offers | Appear to be inside a licensed market or a local pricing region |

## Why IP blocklists fail against residential proxies

IP blocklists were built for a world where attacks came from servers. Residential proxies turned that around: the IP belongs to a real household, and tomorrow it may belong to a different one. Classic IP reputation, covered in our [IP reputation](https://kavralab.com/glossary/ip-reputation/) guide, cannot keep up for several reasons.

- Rotation: an attacker can use a fresh address for every request, so by the time an IP is listed it has moved on.
- Shared addresses: the same IP carries a real family's traffic the rest of the day. Blocking it blocks them.
- Carrier sharing: mobile carriers put many phone users behind one public IP, so a block can hit a whole neighborhood of real customers.
- Public feeds lag: most lists are built from abuse reports after the fact, and proxy pools churn faster than reports arrive.
- Right country, right provider: the IP passes geolocation and "is this a hosting network" checks by design.

## Measure proxy exits, do not guess them

The only reliable way to know which home IPs are proxy exits right now is to look. Kavra runs its own proxy intelligence: it continuously connects through commercial residential and mobile proxy networks and records the real exit IPs they hand out, then combines that with 30+ public reputation feeds. Because an exit is measured, not inferred from complaints, it is known while the pool is still using it.

An exit IP alone is not a verdict, since a real person may use that connection later the same day. So Kavra also checks the connection itself. Its own edge network sees the real connection, not only what the browser claims, and compares it with the rest of the visit.

## Signals that expose proxy traffic

Each signal is weak alone. Together they separate a proxy exit from the household behind it.

- **Measured exit**: The IP was recently seen handing out traffic for a commercial proxy network.
- **Timezone and language drift**: The browser's clock and language belong to one region, the IP to another.
- **Device and connection disagree**: The browser claims to be an iPhone, but the connection looks like a desktop system or a server.
- **Longer path than a home line**: Response timing shows an extra hop that a direct home connection would not have.
- **Same device, new IP each visit**: One returning device appears from a different city or carrier on every session.
- **Many actors, one exit**: Unrelated new accounts cluster on the same short-lived exit range within minutes.

## Checklist: handling residential proxy traffic

Proxy traffic calls for a different response than a plain IP ban. Use this list to adjust your rules.

- Treat a proxy exit as evidence to weigh, not as a block on its own.
- Rate-limit by device and actor, not only by IP address, so rotation stops helping.
- Check proxy status on the actions that matter: signup, login, promo claim, checkout and payout.
- Compare the IP location with the device's timezone, language and account history.
- Step up with a one-time code or an invisible challenge when a known account arrives through a proxy on a new device.
- Link accounts that share exits and devices, since proxy pools make each account look separate.
- Review your blocklists: remove broad ranges that also carry real home and mobile customers.

## Same IP, two very different visitors

**The household on that IP**

- Device, timezone and language match the IP's region
- Direct connection with normal home timing
- Same devices return from the same few networks
- Long, consistent account history

**A proxy customer on that IP**

- Device or timezone belong somewhere else
- Extra hop and a connection that does not fit the device
- New IP, new city or new carrier every session
- Fresh accounts or unfamiliar devices on known accounts

> **Key takeaway:** Residential and mobile proxies make an IP address meaningless as an identity. Stop relying on blocklists alone: know which exits belong to proxy pools by measuring them, check whether the connection fits the device, and decide on the actor, not the IP. Proxies usually come paired with spoofed devices and [VPNs](https://kavralab.com/detect/vpn-and-tor/), so check them together.

## How Kavra detects residential and mobile proxies

Kavra treats the network as one layer of evidence and checks it against the device, the behavior and the account's history.

- **Own proxy intelligence**: Kavra continuously measures real exit IPs of commercial residential and mobile proxy networks, on top of 30+ public feeds.
- **Own edge network**: Kavra sees the real connection, not only what the browser claims, and flags connections that do not fit the device.
- **Contradictions across layers**: IP location, timezone, language, device and connection are compared, so a clean home IP with a mismatched story stands out.
- **Actors, not addresses**: Returning devices are recognized across rotating IPs, so one operator stays one actor however often the exit changes.
- **Step up, do not punish**: Mixed evidence triggers an invisible challenge or your own verification, so real customers on shared IPs keep going.
- **Explained network context**: Every assessment shows the network type, proxy status and why it mattered, so your team can tune rules with confidence.

## FAQ

### Can residential proxies be detected?

Yes, but rarely by IP reputation alone. Reliable detection combines measured proxy exits, meaning IPs actually observed serving a proxy network, with checks on the connection itself: does it fit the claimed device, does the timezone match the location, and does the same device keep appearing from new IPs. Together these catch proxies that blocklists miss.

### Where do residential proxy IPs come from?

Mostly from real consumer devices. Some owners opt in through bandwidth-sharing apps in exchange for payment, others agree to it inside the terms of free apps, games or browser extensions, and some devices are infected with malware. Mobile proxies often come from racks of phones or modems with SIM cards on carrier networks.

### Why not just block all proxy IPs?

Because the same address serves real people. A home IP used as a proxy exit this morning may carry a family's shopping tonight, and a mobile carrier IP can be shared by many phone users at once. Blanket blocks cause false positives. It is safer to weigh the proxy signal with device and account evidence.

### What is the difference between a residential proxy and a VPN?

A VPN usually sends traffic through servers in data centers, so its exit IPs belong to hosting networks and are easy to classify. A residential proxy exits through a real home or phone connection, so it looks like an ordinary customer. People use VPNs mostly for privacy; residential proxies are mostly bought to look like many different local users.

### Are mobile proxies harder to detect than residential proxies?

Often, yes. Carriers put many real phone users behind the same public IP, so an address that carries proxy traffic also carries genuine customers, and blocking it is costly. Detection has to rely more on the device and connection: whether the browser really is a phone and whether the session fits that phone's history.

### Is using a residential proxy illegal?

Buying or using proxy access is legal in most countries, and companies use proxies for ad verification, price monitoring and testing. It becomes a problem when used to break a site's terms, take over accounts or commit fraud. Sourcing matters too: IPs from infected devices are used without the owner's knowledge.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
