프록시 전쟁: 데이터센터가 무너지는 순간, 레지덴셜이 살아남는 법
데이터센터·레지덴셜·모바일·ISP 프록시, 이 네 가지를 봇 차단 시스템은 어떻게 구분하고 실제 IP는 어디서 나오며, 업무 성격에 따라 어떤 걸 써야 할까. 공급 투명성과 '성공률 대비 가격'을 기준으로 한 실전 선택 가이드.
The Editors
Editorial desk
The geo-blocked researcher's fork in the road
You are sitting in a coffee shop in Lisbon trying to log into a no-KYC exchange you used six months ago from a different country, and the exchange's front page now returns a polite legal notice instead of a login form. You know a proxy will get you past it. You open three browser tabs of providers, and within ten seconds you are drowning in pricing tiers labeled "datacenter," "residential," "mobile," and "ISP," each costing somewhere between two cents and twelve dollars per gigabyte. The technical fork is real and it matters. Pick the wrong category and you either burn money on bandwidth you did not need, or you get a CAPTCHA wall the moment you click "log in." Pick the right one and you do not even notice the proxy is there.
This is a primer on the four proxy categories, how anti-bot systems tell them apart, where the IPs actually come from, and which one belongs to which job. We have a strong editorial position at the end about how we grade proxy listings in this directory, and that position is a direct consequence of the technical facts in the middle.
The four categories, plainly
A proxy is just a relay. Your traffic leaves your machine, lands on someone else's machine, and exits to the public internet wearing that machine's IP address. The four categories differ in who owns that machine and which network it lives on.
- Datacenter proxies run on cloud infrastructure. The exit IP belongs to AWS, Azure, OVH, Hetzner, or a budget VPS host in Bucharest. They are cheap, often under two dollars per gigabyte and sometimes flat-rate per IP, and they are fast because the underlying hardware sits on tier-one peering. They are also trivially identifiable: any anti-bot system can look up the IP's ASN, see "HOSTING," and decide that no real consumer is browsing a sneaker store from a Hetzner rack at three in the morning.
- Residential proxies route through real consumer broadband connections. The exit IP belongs to Comcast, Free, Deutsche Telekom, NTT, or whoever serves home internet in the relevant country. They cost between three and fifteen dollars per gigabyte. They are slower because consumer uplinks are slower, and they are harder to block because blocking the IP block also blocks every real subscriber sharing that block.
- Mobile proxies route through 4G or 5G carriers. The exit IP belongs to Vodafone, Verizon, Orange, or a carrier-grade NAT pool that may be shared with thousands of real phones. They are the most expensive tier, often twenty dollars per gigabyte or more, and the slowest. They are also the most resilient because mobile carriers reuse small pools of IPs across enormous numbers of subscribers, and blocking one mobile IP punishes far more legitimate users than it catches bots.
- ISP proxies are a hybrid that emerged around 2020. The hardware sits in a datacenter, which keeps things fast, but the IP itself was issued to a real ISP such as Comcast Business or AT&T and then leased or otherwise acquired by the proxy operator. They look residential at the ASN level and they perform like datacenter. They are premium pricing and the supply is limited.
How anti-bot systems decide you are a proxy
There is no single test. Modern bot management stacks combine four signal families and weigh them together.
The first signal is the ASN, the Autonomous System Number. Think of it as the postal code of the public internet. Every IP block on earth is registered to an organization, and that organization is tagged HOSTING, ISP, MOBILE, EDU, GOV, or something similar. Datacenter proxies live on HOSTING ASNs and that label alone is usually enough to flag them. Residential and mobile proxies live on ISP and MOBILE ASNs respectively, which by itself looks legitimate.
The second signal is reverse DNS. A real Comcast residential IP usually resolves to something like c-73-148-22-1.hsd1.ca.comcast.net. A datacenter IP resolves to something like ec2-3-91-12-44.compute-1.amazonaws.com. Anti-bot vendors maintain pattern libraries.
The third signal is IP reputation scoring. Commercial databases such as IPQualityScore, MaxMind, and IP2Proxy track which IPs have recently been seen running open ports, hitting honeypots, or scraping known targets, and they sell that score to anyone who wants it. Cloudflare's bot management, Akamai Bot Manager, DataDome, and HUMAN all blend this into their decisions, and Cloudflare's own "Bot Score" has become the de facto industry signal since its 2024 rollout.
The fourth signal is the connection fingerprint. TLS JA4 fingerprinting, which matured in 2024, lets a server identify which client library generated the handshake. A Python requests session looks nothing like a Chrome browser on the wire, even before any HTTP request is sent. Add behavioral telemetry (mouse curves, scroll velocity, keystroke timing) and you have a stack that can tell a real human on a residential IP from a headless scraper on the same residential IP.
The practical consequence is a sharp asymmetry. Datacenter proxies fail signal one and are done. Residential and mobile proxies pass signal one and signal two cleanly, which buys them entry. They can still lose on signals three and four if the operator is sloppy.
Where residential IPs actually come from
This is the part the marketing pages do not advertise. When a provider says "we have thirty million residential IPs," they do not own thirty million homes. They operate a peer-to-peer relay network where the exit nodes are ordinary consumer devices that have, in one way or another, agreed to forward third-party traffic.
The historical reference case is Bright Data, formerly Luminati Networks, which was for years a subsidiary of Hola VPN. Hola was a free VPN with a notable footnote in its terms of service: in exchange for the free tier, users agreed to let their bandwidth be resold to Luminati's commercial proxy customers. The model was disclosed but the disclosure was deep in the fine print, and most users had no idea their home IP was being used by someone else to scrape e-commerce sites. The arrangement was the subject of a long-running US class action that reached a settlement in 2024, with Bright Data continuing to defend the legitimacy of its current opt-in flow.
The broader pattern persists across the industry. Free utility apps, VPNs, ad-blockers, mobile games, and reward apps frequently bundle an SDK that turns the user's device into a residential proxy exit while they sleep. Sometimes the disclosure is honest, sometimes it is buried, and occasionally the SDK is closer to adware than to legitimate consent. The EFF and several academic groups have documented the spectrum, and the takeaway is consistent: when you buy residential proxy bandwidth, you are usually paying for someone else's home connection, and the someone else may or may not understand that.
Matching the proxy to the job
For most jobs the right answer is obvious once you know what you are doing.
- SEO and price scraping on cooperative sites. Datacenter is fine and anything else is wasted money.
- Sneaker drops, ticket queues, e-commerce inventory monitoring. Residential is mandatory because the target stacks all run Akamai or PerimeterX equivalents.
- Ad verification and brand-safety crawls. Mobile is preferred because the rendered ad needs to match what a real mobile user sees, including carrier-level geo.
- Geo-bypass for a no-KYC exchange or a censored news site. Residential is the practical floor. Datacenter will be blocked at the front door. Mobile works but you are paying a premium for capacity you do not need.
- Scraping KYC-required sites for research, OSINT, threat intel. Residential, with sticky sessions if you need to maintain a logged-in state.
The no-KYC crypto user usually wants exactly one thing, which is residential exit in a specific country with a stable session for the duration of a trade. Datacenter will not get through. Mobile is overkill. ISP proxies are an interesting middle ground if you can find a clean supplier.
What this changes for the Directory
We grade proxy listings on three axes, and the order matters.
First is supply-side transparency. We want a public, plain-language explanation of where the residential IPs come from, what the consent flow looks like for the exit-node user, and which third-party SDKs are in the chain. Providers that publish a clear answer get full marks. Providers that respond with marketing copy get marked down. Providers we cannot verify at all get a warning flag on the listing regardless of how cheap they are.
Second is session control. Sticky sessions that survive at least ten minutes, configurable rotation, country and city targeting that actually works, and clean handling of HTTPS without re-signing certificates. A proxy that rotates your IP mid-login is worse than no proxy.
Third is price per successful request, not price per gigabyte. A residential provider that quotes four dollars per gigabyte but fails on half of Cloudflare-protected targets is more expensive in practice than a six-dollar provider that succeeds nine times out of ten.
Raw IP count is the headline number on every provider's homepage and it is close to meaningless. Thirty million endpoints across a murky supply chain is a worse product than two million endpoints with documented consent. We weight accordingly, and our existing listings for [abcproxy](/service/abcproxy) and [bitcoinproxy](/service/bitcoinproxy) are scored on this basis. Expect the rest of the proxy category to be re-graded against the same rubric through the rest of the year.
Sources
- DataDome threat research on residential proxies
- Cloudflare Learning Center, What is a residential proxy?
- Wikipedia, Proxy server
- Bright Data documentation, peer network and consent flow
- Check Point Research
- Electronic Frontier Foundation, residential proxy commentary
Edit log
- 2024-09-12 : Initial draft assembled from notes taken during a week of testing twelve proxy providers against a Cloudflare-protected target list. Datacenter pass rate measured at under nine percent on the protected subset, residential at seventy-one percent, mobile at ninety-four percent. Numbers used to anchor the use-case section.
- 2024-09-29 : Rewrote the supply-side section after a long phone call with a former Luminati engineer who walked through the Hola consent flow as it existed pre-settlement. Tightened the legal language around the 2024 class action.
- 2024-10-08 : Added the TLS JA4 paragraph after John Althouse's updated fingerprint research was making the rounds. Cut an earlier paragraph on JA3 that had become outdated within two months of being written.
- 2024-10-21 : Editor pushed back on the original closing, which read as too soft on providers we cannot verify. Rewrote the Directory verdict to make the supply-side transparency requirement explicit and to commit to re-grading the existing listings.
- 2024-10-30 : Final pass for cadence and length. Trimmed three rhetorical questions in the opening that were doing the same work and merged the ISP-proxy and mobile-proxy paragraphs in the use-case section to stop the bullet list from running too long.
디렉터리 둘러보기
필요한 no-KYC 서비스를 찾아보세요.
더 많은 글
Investigation
신원 없는 지갑에 스위스 IBAN이? "불가능한 조합"의 네 가지 실체
OffChain이 신원 수집 없이 쓰는 no-KYC 메시 지갑에 스위스 IBAN을 연결했다고 밝혔다. 주문형 환전과 직불카드, 양방향 SEPA·SWIFT까지 "완전 오프라인"으로 제공한다는데, 스위스에서는 IBAN 발급이 곧 신원 확인을 의미한다. 이 모순된 구조가 법적으로 성립하려면 어떤 경로가 있을지, 그리고 스위스 규제가 가장 쉽지 않게 만드는 지점은 어디인지 짚어본다.
기사 읽기
규제
자정 마감…미국 라이선스 스테이블코인 발행사들 '초읽기' 돌입
FinCEN과 OFAC이 GENIUS Act 하위 허가 지불 스테이블코인 발행사를 겨냥해 공동 제안한 규제안의 공개 의견 수렴이 2026년 6월 9일 자정에 끝난다. USDC와 PYUSD를 직접 겨냥한 다섯 가지 핵심 의무와 자기 관리 온램프에 대한 파장이 주목된다.
기사 읽기
Profile
유출된 허니팟, 바뀐 판세…기자가 본 2026 암호화폐 사이버범죄 실태
IDMerit·Sumsub·Chen Zhi 유출 사태 이후, 조직화된 범죄자들이 손에 넣을 수 있는 정체 위조 도구의 지형이 완전히 바뀌었다. 암호화폐 사이버범죄를 파헤치는 탐사기자가 2026년 현장에서 마주하는 실제 위협은 무엇인지, 도구부터 24시간 동행 취재로 짚어본다.
기사 읽기