CGNAT explained for proxy buyers: why shared carrier IPs are the point
A CGNAT proxy exits from a carrier IPv4 shared by hundreds of subscribers. How the sharing works, how to check for it, and why it makes blocks costly.
Quick summary · TL;DR
- CGNAT means you are never alone on the IP. Carriers ran out of IPv4 and now put hundreds of subscribers behind one public address. A mobile proxy exits from that shared address, which is why the IP looks like a crowd rather than a machine.
- The sharing is the defence. Blocking a CGNAT address means blocking every real customer behind it, so platforms usually escalate to challenges instead of bans.
- Platforms infer CGNAT from evidence. There is no header that says "this is a shared carrier IP". Platforms read the carrier ASN, port-mapping behaviour, the absence of inbound reachability, and how many distinct sessions the address has carried.
- It costs you control. No inbound connections, no stable port, session lifetimes decided by the carrier's mapping timer rather than by you. If your job needs a fixed identity, this is the wrong tier.
A CGNAT proxy is a proxy that exits through a mobile carrier connection sitting behind Carrier-Grade NAT, so the target sees a public IPv4 address the carrier shares among many subscribers at the same moment. The address is never exclusively yours. That sharing is what makes a mobile pool expensive for a platform to block, and it is also what takes control of the address away from you.
A mobile proxy buys you a seat behind a carrier’s shared address, alongside a few hundred people checking their email. That crowd is why CGNAT proxies behave differently from every other tier, and it is what a pool should be judged on.
What CGNAT proxies are
Carrier-Grade NAT is the translation layer a mobile operator runs between its subscribers and the public internet. Your handset gets a private address from the operator, and the operator maps many of those private addresses onto one public IPv4 address on the way out. CGNAT proxies are proxies whose exit point sits inside that arrangement, so the address the target site records belongs to the carrier and is being used by many subscribers at the same moment.
The reserved range for this is defined in
RFC 6598, published by the IETF
in 2012, which set aside 100.64.0.0/10 (the 4,194,304 addresses from
100.64.0.0 to 100.127.255.255) as shared address space for carrier use. It exists because the alternative had run out: the IANA
handed out its final blocks of public IPv4,
as the Number Resource Organization announced on 3 February 2011, and every
regional registry has been rationing since.
How the mapping works. The translator keeps a table of address and port
pairs. A handset on 100.88.12.7 opens a connection from one of its ports; the
carrier rewrites the source to a public address and a free port from its own
pool, then sends replies for that public pair back to the handset. The shared
range is deliberately separate from the home-network ranges such as
192.168.0.0/16, so a home router and the carrier never hand out colliding
addresses. A fixed line behind CGNAT stacks two translations, the home router’s and then
the carrier’s. That arrangement is called NAT444, and
RFC 7021 tested its effect on
everyday applications in September 2013.
On IPv6-only mobile networks the same job is done by 464XLAT, defined in RFC 6877 in April 2013. The handset runs on IPv6, and a translator on the carrier side maps IPv4 traffic many-to-one onto shared public IPv4 addresses. The target still sees a shared carrier IPv4 either way.
No provider can make a carrier’s public address exclusively yours, because the carrier shares it with its own subscribers whatever the proxy provider does, and that sharing is the reason the tier works. At proxymint, mobile proxies run on mobile carrier networks, with exits classified as cellular by MaxMind, billed per GB, with a new IP per request, a 5 to 60 minute timer, or a sticky session for as long as the device stays online.
Why sharing an address is a defence
Anti-bot systems make their first decision about a request before they look at anything you control. They classify the address, and the classification that matters most is what kind of network announces it. A hosting Autonomous System Number tells the system that no ordinary consumer is likely on the other end. A mobile carrier ASN tells it the opposite, and the detection mechanics behind that judgement are covered in more depth in proxymint’s guide to what platforms actually check on mobile proxies.
CGNAT proxies add a second layer on top of the ASN, made of what a block costs. When a platform blocks a datacenter address, nothing happens to anybody. When it blocks a CGNAT address, it disconnects every real subscriber sharing that address at that moment: people who pay the carrier, have accounts on the platform, and will complain.
The block becomes expensive. That expense is why platforms facing suspicious traffic from a carrier address usually raise friction rather than close the door. You get a captcha, a verification step, or a rate limit, where the same behaviour from a hosting IP would earn a straight refusal. Cloudflare put numbers on this in its October 2025 CGNAT study: one shared address can stand for hundreds or even thousands of users, and CGNAT addresses were rate-limited three times more often than others, while their median bot rate was the same (4.8% against 4.7%).
The signal is crowd noise. A busy CGNAT address is carrying app updates, video, messaging, and browsing from unrelated people simultaneously. Automated traffic arrives inside that mixture instead of standing alone on a quiet address, which makes behavioural analysis harder.
For that study Cloudflare trained a classifier on traceroutes, WHOIS and reverse-DNS records, so it can recognise shared carrier addresses and stop treating them as single users. For a proxy buyer that cuts both ways. Once a platform knows an address is shared, the address earns the benefit of the doubt, and the decision moves to what your session sends: its TLS fingerprint, its cookies, its request rate. A mobile exit puts you among real subscribers, and a scripted client whose fingerprint matches none of them still stands out inside that crowd.
How platforms work out that an address is shared
There is no field in a packet that declares CGNAT. Every classification is inferred from evidence, and the same evidence tells you what a pool of CGNAT proxies has to get right.
The ASN does most of the work. Routing data is public. Anyone can look up which Autonomous System announces an address and what kind of organisation operates it, and commercial classification databases keep that mapping current. An address announced by a mobile operator starts from a different baseline than one announced by a hosting company, which is the same ASN reputation mechanism that governs every other proxy tier.
Session multiplicity confirms it. A shared carrier address carries many unrelated sessions at once, with many source ports in use as the translator hands them out to different handsets. That pattern is difficult to reproduce on an address that belongs to one machine.
Reachability gives it away. Addresses behind CGNAT accept no unsolicited inbound connections, because there is no mapping until something inside creates one. RFC 6888, the IETF’s 2013 requirements document for carrier-grade NAT, sets the mapping, filtering and port-reuse rules operators are expected to follow.
Check an address for CGNAT
On your own connection the check takes a minute. Compare the WAN address on the
router’s status page with the public address an echo service returns. A WAN
address inside 100.64.0.0/10 means a carrier translator sits between you and
the internet, and a traceroute usually shows a hop in that range before the
first public one.
A proxy exit needs a different check, because the carrier’s side is invisible from outside. Fetch the public address through the proxy, then ask which network announces it:
# 1. The public address a target sees through the proxy
curl -x http://USERNAME:PASSWORD@HOST:PORT https://api.ipify.org
# 2. The network that announces it (replace EXIT_IP with the result)
whois -h whois.cymru.com " -v EXIT_IP"
The AS name in the second answer should be a mobile operator. Repeat the pair across 20 rotations: every answer should land on a carrier ASN, and a single hosting ASN in the sample is a question for the provider.
What CGNAT proxies take away from you
You cannot hold an address. RFC 6888 requires a carrier to keep a subscriber on the same public address while its mappings are live, but the carrier reclaims those mappings on its own schedule. After an idle gap or a network reattach, your public address can change in the middle of a logged-in workflow, for reasons that have nothing to do with you.
You cannot accept connections. Anything that needs a service reachable from outside, a webhook receiver or a listening port, is impossible on this tier by construction.
You share a reputation. The crowd protects you, and it can also cost you. If someone else behind the same address triggers a platform’s defences, the elevated scrutiny lands on the address you are currently using too.
Work that benefits from looking like many ordinary consumers, spread across a carrier’s subscriber base, fits CGNAT well. Work that needs one durable identity per account, held for weeks, does not. That second job belongs on static ISP proxies, and the difference between the two session models is laid out in ISP proxies versus rotating residential.
Proxies and VPNs behind CGNAT
Plenty of searches for a CGNAT proxy come from the other side of the translator: someone on a carrier or fibre line behind CGNAT who wants to reach out, or be reached. Outbound, nothing breaks. A proxy client or a VPN opens its connection from inside, so the translator creates a mapping exactly as it would for a browser.
Inbound is where both stop. Neither gives the carrier address an open port, because the translator still has no mapping for traffic that arrives first. The usual fix is a reverse tunnel: the device behind CGNAT dials out to a server with its own public IP, holds the connection open, and that server forwards incoming traffic back down it. A VPN that offers port forwarding is the same idea sold as a feature, on the VPN’s address rather than the carrier’s.
When another tier fits the job
A fixed identity and inbound reachability are ruled out above. The third case is volume on soft targets.
Bulk collection from lenient targets. Carrier bandwidth is premium infrastructure, built for targets that weigh the network behind an address. A large unprotected catalogue does not check for a mobile origin, so datacenter addresses, billed per IP with bandwidth included, are built for that workload and return the same result.
What to check before buying CGNAT proxies
Pool size is the number providers advertise, and it says little about the pool. Three questions separate real pools of CGNAT proxies from hosting addresses with an ambitious label.
Which carrier, named. A real answer is an operator name and an ASN. Verify it independently with a WHOIS lookup on a sample address, the two commands above, rather than accepting the claim.
How rotation is triggered. Ask whether the address changes on a timer, on request, or whenever the carrier decides. All three are legitimate. Only the last is driven by the carrier, and your session handling has to match whichever one you have.
What happens when the address changes mid-session. Your session breaks and your code re-authenticates. A provider promising sticky sessions on carrier infrastructure that can never break is promising more than the carrier controls.
Where CGNAT sits against the other tiers
Mobile is the top of the trust ladder, and CGNAT is the mechanism that puts it there. Datacenter addresses are announced by hosting networks and classified accordingly. Residential addresses come from consumer ISP connections and carry consumer trust; the sourcing questions behind them are covered in what a residential proxy is. Carrier addresses carry consumer trust and the blocking asymmetry on top. The radio generation does not move that position: 4G and 5G proxies sit behind the same kind of carrier translation.
That ordering ranks how hard an address is to reject; the job decides which tier to buy. Each tier is built for a level of enforcement, and the target sets the level. A scrape of an unprotected catalogue does not need carrier IPs; a platform that checks for a mobile origin does.
Match the tier to what the target actually enforces
Decide with the target in front of you, before the first run. If the target checks for a mobile origin, the carrier tier is the one built for it. If it does not, residential or datacenter proxies serve that workload. A challenge on a running job is the platform saying no, not a cue to move up a tier.
Frequently asked questions
A CGNAT proxy routes your request through a mobile carrier connection that sits behind Carrier-Grade NAT, so the request exits from a public IPv4 address the carrier shares among many subscribers at once. The target site sees an ordinary mobile address carrying mixed consumer traffic rather than an address dedicated to one machine.
Because public IPv4 addresses ran out. Rather than assign one to every handset, carriers assign private addresses from 100.64.0.0/10, the shared range the IETF reserved in RFC 6598 in 2012, and translate them onto a much smaller pool of public addresses. Cloudflare's October 2025 measurement found a single shared IPv4 can stand for hundreds or even thousands of users.
On your own line, a router WAN address inside 100.64.0.0/10 that differs from the public IPv4 an echo service returns means carrier-grade NAT. For a proxy exit, fetch the public IP through the proxy and look up which network announces it: a mobile operator's ASN is the strongest single sign. Platforms infer it the same way, adding many unrelated sessions, rapid port reuse and no inbound connectivity, because no packet field announces CGNAT.
It can, but the cost is high. Because the address is shared with real paying subscribers on the same carrier, a hard block takes legitimate customers offline alongside the automated traffic, so platforms usually serve a captcha, a challenge or a rate limit instead of an outright ban. Cloudflare's 2025 study found CGNAT addresses were rate-limited three times as often as other addresses.
Yes for outbound traffic. A proxy or VPN client opens the connection from inside, so the carrier's translator creates the mapping as it would for any browser. Neither one restores inbound reachability on the carrier address, so hosting a service behind CGNAT still needs a reverse tunnel to a server with its own public IP.
No. A CGNAT IP is the carrier's public address, shared by its ordinary subscribers whether or not any proxy is involved. A mobile proxy is one way to send traffic out through that address. Rotating residential proxies are different again: they move requests between separate home connections on purpose, while a CGNAT address changes only as a side effect of carrier housekeeping, after an idle gap or a network reattach.
Not in practice. Carriers deploy IPv6 widely, but the sites being reached often remain IPv4-only, so traffic still passes through a translation layer such as 464XLAT to reach them. For proxy buyers the practical effect is unchanged: the IPv4 address presented to the target is still shared.