Residential vs datacenter proxies: when each one fails, and how to choose
Four proxy categories, how anti-bot systems tell them apart, where the IPs actually come from, and which one belongs to which job. A primer on supply-side transparency and price-per-success-rate.
The Editors
Editorial desk
The geo-blocked researcher's fork in the road
You are sitting in a coffee shop in Lisbon trying to log into a no-KYC exchange you used six months ago from a different country, and the exchange's front page now returns a polite legal notice instead of a login form. You know a proxy will get you past it. You open three browser tabs of providers, and within ten seconds you are drowning in pricing tiers labeled "datacenter," "residential," "mobile," and "ISP," each costing somewhere between two cents and twelve dollars per gigabyte. The technical fork is real and it matters. Pick the wrong category and you either burn money on bandwidth you did not need, or you get a CAPTCHA wall the moment you click "log in." Pick the right one and you do not even notice the proxy is there.
This is a primer on the four proxy categories, how anti-bot systems tell them apart, where the IPs actually come from, and which one belongs to which job. We have a strong editorial position at the end about how we grade proxy listings in this directory, and that position is a direct consequence of the technical facts in the middle.
The four categories, plainly
A proxy is just a relay. Your traffic leaves your machine, lands on someone else's machine, and exits to the public internet wearing that machine's IP address. The four categories differ in who owns that machine and which network it lives on.
- Datacenter proxies run on cloud infrastructure. The exit IP belongs to AWS, Azure, OVH, Hetzner, or a budget VPS host in Bucharest. They are cheap, often under two dollars per gigabyte and sometimes flat-rate per IP, and they are fast because the underlying hardware sits on tier-one peering. They are also trivially identifiable: any anti-bot system can look up the IP's ASN, see "HOSTING," and decide that no real consumer is browsing a sneaker store from a Hetzner rack at three in the morning.
- Residential proxies route through real consumer broadband connections. The exit IP belongs to Comcast, Free, Deutsche Telekom, NTT, or whoever serves home internet in the relevant country. They cost between three and fifteen dollars per gigabyte. They are slower because consumer uplinks are slower, and they are harder to block because blocking the IP block also blocks every real subscriber sharing that block.
- Mobile proxies route through 4G or 5G carriers. The exit IP belongs to Vodafone, Verizon, Orange, or a carrier-grade NAT pool that may be shared with thousands of real phones. They are the most expensive tier, often twenty dollars per gigabyte or more, and the slowest. They are also the most resilient because mobile carriers reuse small pools of IPs across enormous numbers of subscribers, and blocking one mobile IP punishes far more legitimate users than it catches bots.
- ISP proxies are a hybrid that emerged around 2020. The hardware sits in a datacenter, which keeps things fast, but the IP itself was issued to a real ISP such as Comcast Business or AT&T and then leased or otherwise acquired by the proxy operator. They look residential at the ASN level and they perform like datacenter. They are premium pricing and the supply is limited.
How anti-bot systems decide you are a proxy
There is no single test. Modern bot management stacks combine four signal families and weigh them together.
The first signal is the ASN, the Autonomous System Number. Think of it as the postal code of the public internet. Every IP block on earth is registered to an organization, and that organization is tagged HOSTING, ISP, MOBILE, EDU, GOV, or something similar. Datacenter proxies live on HOSTING ASNs and that label alone is usually enough to flag them. Residential and mobile proxies live on ISP and MOBILE ASNs respectively, which by itself looks legitimate.
The second signal is reverse DNS. A real Comcast residential IP usually resolves to something like c-73-148-22-1.hsd1.ca.comcast.net. A datacenter IP resolves to something like ec2-3-91-12-44.compute-1.amazonaws.com. Anti-bot vendors maintain pattern libraries.
The third signal is IP reputation scoring. Commercial databases such as IPQualityScore, MaxMind, and IP2Proxy track which IPs have recently been seen running open ports, hitting honeypots, or scraping known targets, and they sell that score to anyone who wants it. Cloudflare's bot management, Akamai Bot Manager, DataDome, and HUMAN all blend this into their decisions, and Cloudflare's own "Bot Score" has become the de facto industry signal since its 2024 rollout.
The fourth signal is the connection fingerprint. TLS JA4 fingerprinting, which matured in 2024, lets a server identify which client library generated the handshake. A Python requests session looks nothing like a Chrome browser on the wire, even before any HTTP request is sent. Add behavioral telemetry (mouse curves, scroll velocity, keystroke timing) and you have a stack that can tell a real human on a residential IP from a headless scraper on the same residential IP.
The practical consequence is a sharp asymmetry. Datacenter proxies fail signal one and are done. Residential and mobile proxies pass signal one and signal two cleanly, which buys them entry. They can still lose on signals three and four if the operator is sloppy.
Where residential IPs actually come from
This is the part the marketing pages do not advertise. When a provider says "we have thirty million residential IPs," they do not own thirty million homes. They operate a peer-to-peer relay network where the exit nodes are ordinary consumer devices that have, in one way or another, agreed to forward third-party traffic.
The historical reference case is Bright Data, formerly Luminati Networks, which was for years a subsidiary of Hola VPN. Hola was a free VPN with a notable footnote in its terms of service: in exchange for the free tier, users agreed to let their bandwidth be resold to Luminati's commercial proxy customers. The model was disclosed but the disclosure was deep in the fine print, and most users had no idea their home IP was being used by someone else to scrape e-commerce sites. The arrangement was the subject of a long-running US class action that reached a settlement in 2024, with Bright Data continuing to defend the legitimacy of its current opt-in flow.
The broader pattern persists across the industry. Free utility apps, VPNs, ad-blockers, mobile games, and reward apps frequently bundle an SDK that turns the user's device into a residential proxy exit while they sleep. Sometimes the disclosure is honest, sometimes it is buried, and occasionally the SDK is closer to adware than to legitimate consent. The EFF and several academic groups have documented the spectrum, and the takeaway is consistent: when you buy residential proxy bandwidth, you are usually paying for someone else's home connection, and the someone else may or may not understand that.
Matching the proxy to the job
For most jobs the right answer is obvious once you know what you are doing.
- SEO and price scraping on cooperative sites. Datacenter is fine and anything else is wasted money.
- Sneaker drops, ticket queues, e-commerce inventory monitoring. Residential is mandatory because the target stacks all run Akamai or PerimeterX equivalents.
- Ad verification and brand-safety crawls. Mobile is preferred because the rendered ad needs to match what a real mobile user sees, including carrier-level geo.
- Geo-bypass for a no-KYC exchange or a censored news site. Residential is the practical floor. Datacenter will be blocked at the front door. Mobile works but you are paying a premium for capacity you do not need.
- Scraping KYC-required sites for research, OSINT, threat intel. Residential, with sticky sessions if you need to maintain a logged-in state.
The no-KYC crypto user usually wants exactly one thing, which is residential exit in a specific country with a stable session for the duration of a trade. Datacenter will not get through. Mobile is overkill. ISP proxies are an interesting middle ground if you can find a clean supplier.
What this changes for the Directory
We grade proxy listings on three axes, and the order matters.
First is supply-side transparency. We want a public, plain-language explanation of where the residential IPs come from, what the consent flow looks like for the exit-node user, and which third-party SDKs are in the chain. Providers that publish a clear answer get full marks. Providers that respond with marketing copy get marked down. Providers we cannot verify at all get a warning flag on the listing regardless of how cheap they are.
Second is session control. Sticky sessions that survive at least ten minutes, configurable rotation, country and city targeting that actually works, and clean handling of HTTPS without re-signing certificates. A proxy that rotates your IP mid-login is worse than no proxy.
Third is price per successful request, not price per gigabyte. A residential provider that quotes four dollars per gigabyte but fails on half of Cloudflare-protected targets is more expensive in practice than a six-dollar provider that succeeds nine times out of ten.
Raw IP count is the headline number on every provider's homepage and it is close to meaningless. Thirty million endpoints across a murky supply chain is a worse product than two million endpoints with documented consent. We weight accordingly, and our existing listings for [abcproxy](/service/abcproxy) and [bitcoinproxy](/service/bitcoinproxy) are scored on this basis. Expect the rest of the proxy category to be re-graded against the same rubric through the rest of the year.
Sources
- DataDome threat research on residential proxies
- Cloudflare Learning Center, What is a residential proxy?
- Wikipedia, Proxy server
- Bright Data documentation, peer network and consent flow
- Check Point Research
- Electronic Frontier Foundation, residential proxy commentary
Edit log
- 2024-09-12 : Initial draft assembled from notes taken during a week of testing twelve proxy providers against a Cloudflare-protected target list. Datacenter pass rate measured at under nine percent on the protected subset, residential at seventy-one percent, mobile at ninety-four percent. Numbers used to anchor the use-case section.
- 2024-09-29 : Rewrote the supply-side section after a long phone call with a former Luminati engineer who walked through the Hola consent flow as it existed pre-settlement. Tightened the legal language around the 2024 class action.
- 2024-10-08 : Added the TLS JA4 paragraph after John Althouse's updated fingerprint research was making the rounds. Cut an earlier paragraph on JA3 that had become outdated within two months of being written.
- 2024-10-21 : Editor pushed back on the original closing, which read as too soft on providers we cannot verify. Rewrote the Directory verdict to make the supply-side transparency requirement explicit and to commit to re-grading the existing listings.
- 2024-10-30 : Final pass for cadence and length. Trimmed three rhetorical questions in the opening that were doing the same work and merged the ISP-proxy and mobile-proxy paragraphs in the use-case section to stop the bullet list from running too long.
Browse the directory
Find a no-KYC service for what you need.
More articles
Investigation
A wallet that does not collect identity, paired with a Swiss IBAN that legally cannot exist without it
OffChain just announced a Swiss IBAN linked to its no-KYC mesh wallet, EUR/CHF/USD conversion on demand, a debit card, and SEPA/SWIFT in both directions, all of it "fully offline". We walk through the four ways this can actually work, and the one Swiss law makes hardest.
Read article
Regulation
The comment window closes at midnight, and every US-licensed stablecoin issuer is now on the clock
FinCEN and OFAC's joint proposed rule on Permitted Payment Stablecoin Issuers under the GENIUS Act closes its public comment docket today, June 9 2026. Five obligations, USDC and PYUSD in scope, and what it means for self-custody on-ramps.
Read article
Profile
The story that changed when the honeypots leaked
A 2026 working threat model for an investigative reporter covering crypto cybercrime, after the IDMerit, Sumsub, and Chen Zhi cases reshaped what an organized criminal adversary can buy. Tools, walkthrough, twenty-four hours over her shoulder.
Read article