Proxy acceptable use policy: what providers ban and why

What a proxy acceptable use policy bans, which targets get blocked, how KYC and enforcement work, what a breach costs, and what to read before you pay.

Fraud and identity theftCredential stuffingDoS and DDoS attacksMalware distributionSpam and fake accounts
Quick summary · TL;DR
  1. A proxy acceptable use policy sets what customers may not do through a provider's network. It covers banned activities, blocked targets, identity checks and what happens on a breach. The target site's own terms still apply on top.
  2. The ban lists are nearly identical across providers. Fraud, unauthorized access, credential stuffing, DoS, malware, spam, fake accounts and ad fraud appear everywhere, because the same abuse burns every shared pool.
  3. Termination for breach usually means no refund. The unused balance is lost when an account is closed for breaking the rules, whatever the normal refund window says.
  4. The policy can reach past one page. A provider's rules can include requirements set by the networks it works with, so the effective policy can be stricter than the ban list a buyer skims.

A proxy acceptable use policy is the part of a proxy provider’s terms that says what customers may not do through its network, which targets it blocks, how it checks who customers are, and what happens on a breach. It binds the customer, not the websites. The target site’s own terms still apply on top of it.

Most buyers skim it once, at checkout. Then a job gets suspended, the balance is gone, and the policy turns out to be the only document that mattered.

This guide reads the policies the way a buyer should: what they ban and why, the grey areas where real jobs sit, how verification and enforcement work, what a breach costs, and what to check before paying. It ends with proxymint’s own terms, quoted.

What proxy acceptable use policies cover

A proxy provider rents out exit IPs that other customers share, over time or in reputation. The acceptable use policy is how the provider keeps one customer’s traffic from burning addresses for everyone else, and how it stays on good terms with the networks and ISPs behind its exits.

It rarely lives in one place. Look for four documents:

  • Terms of service. The contract. Usually carries the ban list, suspension rights, refunds and liability.
  • An AUP page. Sometimes a separate page that expands the ban list and names blocked targets.
  • A KYC or verification page. Who has to prove identity, when, and with what.
  • Product or fair-use notes. Limits on “unlimited” plans, concurrency and bandwidth.

A proxy acceptable use policy governs the customer’s relationship with the provider. It does not grant permission to access any site. A scraper that follows the provider’s rules can still breach a target’s terms of use, and the provider’s policy usually says so.

Activities every policy prohibits

The ban lists across providers are close to identical, because the same abuse shows up on every pool. The common core:

  • Fraud and identity theft. Payment fraud, account takeover, phishing, money laundering.
  • Unauthorized access. Credential stuffing, password spraying, brute-forcing logins, port scanning, exploiting systems.
  • Attacks on availability. DoS and DDoS, flooding, anything that degrades a target.
  • Malware. Distribution, command and control, hosting payloads.
  • Spam and fake activity. Unsolicited bulk messages, fake accounts, fake reviews, fake engagement, ad click fraud.
  • Illegal content. Child sexual abuse material, terrorist content, non-consensual imagery.
  • Surveillance of people. Stalking or tracking identifiable individuals outside what the law allows.
  • Sharing access without approval. Sub-letting or passing access to third parties the provider has not approved.

Each ban protects the pool as much as the victims. Credential stuffing through a residential exit gets that address flagged by IP-intelligence services, and the next customer who draws it inherits the flag. A spam run triggers abuse reports to the ISP that owns the range, and the ISP can act against the whole range. So the policy is also the product: a pool is only as clean as the least careful customer the provider lets in.

Blocked target categories

Beyond banned activities, most providers block some destinations outright, whatever the stated purpose. Government domains and adult sites are the common ones. Some add financial login pages and other high-risk categories. The lists are usually short, not exhaustive, and followed by a clause that lets the provider block anything else it judges risky.

For a buyer, the practical question is whether a job’s targets sit on that list. An uptime check against a public government portal or a QA suite for a payment page can be refused by the network even though the work is legitimate. Ask before ordering, not after the first failed request.

Where legitimate jobs meet the line

Most buyers are not near the ban list. They run price monitoring, search tracking, ad verification and QA. The policy still shapes how those jobs have to run.

Scraping and public data rules

Most providers allow collection of public data and forbid getting past access controls. In practice that means no scraping behind a login the customer has no right to use, no paywalls, no defeating a site’s access controls, and no collecting sensitive personal data without a lawful basis.

The target’s own terms and rate limits still apply on top. When a site returns a block or a captcha, the safe reading of almost every policy is to stop, not to escalate. The best proxies for web scraping guide covers which tier fits which target once the job is inside those lines.

Accounts, ads and QA

Accounts the customer owns. Logging in to a seller dashboard or an ad account the business runs is usually fine. Creating accounts in bulk, or using proxies to get around a platform’s limits, is the “fake accounts” ban. The platform’s own route (team access, business manager, partner access) comes first; a proxy only keeps the login origin consistent.

Ad verification. Loading a page to see which creative appears in a market is a standard, permitted use. Clicking ads to inflate counts is click fraud.

QA and localization. Testing an app or checkout flow from another country is normal. Load testing a target the customer does not own is an attack.

Customer verification and KYC

Know-your-customer checks decide who shares the pool. Practice varies widely. Some providers verify identity before any residential access. Others use a risk-based model: a card and email to start, and a verification request when something triggers it. Common triggers are free trial requests, high volume, traffic to sensitive domains and accounts that share access with others.

What a buyer should expect to provide:

  • a legal name, and a company name and registration for a business account;
  • a government ID or a business document, often through a third-party verification service;
  • a short description of the use case and the main targets;
  • sanctions terms written into the contract, which apply whether or not identity is checked.

Enforcement, suspension and refunds

Enforcement ladders look similar everywhere: a warning, throttling or blocking a target, suspension, then termination. Most policies reserve the right to skip straight to the end without notice when the risk is high. Many add that the provider may report serious crime to the authorities, and that the customer indemnifies the provider for claims caused by their traffic.

What a breach costs

The refund clause is the one buyers miss: termination for breach usually comes with no refund. Under proxymint’s terms, a first purchase can be refunded inside 7 days unless more than 10% of the data, or 1 GB, whichever is larger, has been used.

Network terms pass through to customers

A provider’s policy can include rules set by the networks it works with, and the provider enforces them on customers the same way as its own. The effective policy can then be stricter than the ban list on the main page, and it can change when those rules change. Read the whole document, not just the list, and ask whether any outside rules apply to the job’s targets.

Why providers enforce acceptable use

Residential and mobile exits are someone’s home or phone connection. When those exits carry abuse, the damage lands on the device owner, the target and every other customer of the pool.

The scale is on record. In January 2026 Google’s threat intelligence team observed more than 550 threat groups using one residential network’s exit nodes in a seven-day window, for password spraying and access to victim SaaS environments among other things, and found that network’s SDK in more than 600 Android apps (Google GTIG, 2026-01-28).

That is the commercial reason a strict policy is worth reading as a feature. A provider that enforces named bans and acts on abuse is protecting the reputation of the addresses a buyer is paying for. How residential proxies work, and why their reputation matters, is covered in the pillar guide.

How to read a policy before paying

Ten minutes with the terms saves a suspended order. Score each item the way a security team scores a vendor questionnaire: a vague answer counts as no.

  • Ban list. The policy names the banned activities, such as credential stuffing, fraud, spam, fake accounts and malware, rather than saying only “no illegal use”.
  • Blocked targets. It names the blocked categories and gives a way to ask before ordering, so failed requests are not how a buyer finds out.
  • Verification. It states the provider’s verification rights and the sanctions terms in the contract.
  • Enforcement. It promises a reason on suspension and publishes an abuse contact.
  • Money on breach. It states what a breach costs plainly, with the normal refund rules beside it.
  • Outside rules. It says whether rules from the networks the provider works with apply.

Then map the job against it. List the targets, the request rates, whether any login is involved, and whether the work touches personal data. If any item is unclear, ask the provider in writing and keep the answer.

The proxymint acceptable use terms

proxymint publishes its rules in its terms of service, last updated 2 July 2026.

Responsibility. The “You are responsible for your traffic” section makes the customer responsible for all traffic and content, and for having the rights and lawful basis for the data collected. It says: collect public data only, do not get behind logins, paywalls or DRM without a right to, do not defeat access controls or rate limits where the law requires respecting them, and do not collect sensitive personal data without a lawful basis.

Bans. The “Acceptable use” section bans breaking any law, illegal content, fraud, money laundering, sanctions evasion, identity theft, DoS and DDoS, port scanning, credential stuffing, unauthorized access, malware, interception, spam, fake ad traffic and click fraud, fake accounts, reviews and engagement, inventory-hoarding bots, surveillance of people outside the law, and passing the service on to others without written approval.

Targets and network rules. The same section applies network-level acceptable use requirements on top of its own, and lets proxymint block high-risk categories, naming adult and government targets as examples.

Verification. “Your account and verification” says proxymint may verify identity before or at any time, one verified identity per account. “Who can use it” excludes anyone on a US sanctions or denied-party list.

Enforcement. “Suspension and termination” allows suspension without notice where the risk requires it, and says the customer will be told why. “Billing and refunds” rules out refunds on a termination for breach. “Abuse reporting” names [email protected], and “Law enforcement” allows reporting serious criminal activity to the authorities.

For a target or use case the terms do not name, ask before ordering and keep the answer in writing.

Reading a proxy AUP before you pay

If the job is public-data collection, price monitoring, ad verification or QA, any strict proxy acceptable use policy fits. Check the blocked-target list against the target list, and pick from the types of proxies on the job’s merits. Rotating residential proxies fit broad collection from targets that block datacenter ranges.

If the job logs in to accounts the business owns, read the fake-account and account-sharing clauses first, use the platform’s own team or partner access, and look at static ISP proxies for a fixed login origin.

If the job needs anything on the ban list, or a provider whose policy is silent on it, no tier fits. A provider that accepts that traffic is selling a pool other customers will get blocked on.

Frequently asked questions

Providers typically warn, block the target, suspend or terminate the account, and many can skip straight to termination without notice when the risk is high. Termination for breach usually comes with no refund of the unused balance. Serious crime can be reported to the authorities, and the customer usually indemnifies the provider for claims caused by the traffic.

Practice varies. Some providers verify identity before any residential access, while others start with a card and email and ask for verification when a trigger fires, such as free trials, high volume, sensitive domains or accounts that share access with others. Sanctions terms in the contract apply either way.

Reports go to a published abuse contact, and the provider acts on them along the same enforcement ladder: a warning, a blocked target, suspension or termination, depending on the risk. proxymint takes reports at [email protected] and acts on them under its terms, which also allow reporting serious criminal activity to the authorities.

It is the part of a proxy provider's terms that lists what customers may not do through the network, which targets are blocked, how customers are verified and what happens on a breach. It binds the customer to the provider. It does not give permission to access any website, whose own terms still apply.

Collecting public data is allowed by most providers. Getting past logins, paywalls or other access controls without a right to them, and collecting sensitive personal data without a lawful basis, is usually banned. The target site's own terms and rate limits still apply, and a block or captcha is a signal to stop.

Some destinations carry high legal or abuse risk, so providers block them for every customer regardless of purpose. Government domains and adult sites are the common examples, and most policies let the provider block other categories it judges risky. A buyer whose job needs such a target should ask before ordering.

Usually not without the provider's written approval. Sharing or sub-letting access hands it to people the provider has not approved, so most policies ban it outright or require a separate agreement, often with extra verification.