What are mobile proxies? Carrier IPs, CGNAT and rotation
What are mobile proxies? Carrier IPs behind CGNAT, how rotation works, when they are worth it, when they are not, detection limits and per-GB billing.
Quick summary · TL;DR
- Mobile proxies exit through carrier networks. The target sees a public IP announced by a 4G or 5G carrier ASN, the same address class phones use for everyday apps.
- The shared address is the mechanism. More than 90% of cellular networks run carrier-grade NAT (Richter et al., IMC 2016), so one carrier IP fronts many real subscribers and a ban hits paying users.
- Shared still gets flagged. Cloudflare found CGNAT addresses were rate limited three times more often than other addresses (October 2025), and fingerprint, pace and geo are scored on top of the IP.
- Carrier IPs move by design. Rotation comes from the device reconnecting or the carrier rebuilding a session. proxymint offers per-request, a 5 to 60 minute timer, or sticky while the device stays online.
- The tier is for targets that check origin. App-first account work, mobile ad verification and app QA need it. Price monitoring and bulk scraping of lenient targets do not.
What are mobile proxies? They are proxies that exit through a phone, modem or SIM device on a 4G or 5G carrier network, so the target sees a public IP announced by a mobile carrier. That address is usually shared with other subscribers behind carrier-grade NAT, which makes it costly to ban, and it moves whenever the carrier rebuilds the session.
A target flags the third account in a week. The vendor says “use mobile, they are real phones” and sends a price list. Nobody explains why a carrier IP behaves differently, how long it lasts, or which jobs need it.
What are mobile proxies, exactly
The definition. A mobile proxy relays a request through a device attached to a 4G or 5G carrier network, so the connection reaches the target from a public IP that the carrier’s autonomous system (ASN) announces. The target never sees the proxy gateway, only a carrier address of the same class that phones use for Instagram, banking apps and maps.
The address class. This is what the buyer pays for. Residential IPs are real too; the difference is the network that announces the address and how many people stand behind it. Anti-bot systems score the ASN, and a carrier ASN starts that score in a different place than a hosting range.
Not a proxy on a phone. Renting mobile proxies means requests from a server or laptop leave through a carrier device. Setting a proxy on a phone is the reverse: the phone’s own traffic goes out through some other exit, of any tier. Setting up a proxy on Android or iPhone is a separate walkthrough.
The boundary. Past the carrier core it is ordinary TCP and TLS, so a carrier IP with a desktop Linux fingerprint is still a mismatch.
Carrier IPs sit behind CGNAT
Carriers never had enough IPv4 addresses to give every phone its own. So they put subscribers behind carrier-grade NAT (CGNAT): each device gets an internal address, and a translator maps many of them onto one public IPv4 address on the way out. The IETF reserved 100.64.0.0/10 as shared address space for exactly this in RFC 6598 (April 2012).
On cellular networks this is the norm. A measurement study presented at ACM IMC in 2016 found CGN in 17-18% of fixed-line eyeball networks but in more than 90% of cellular networks (Richter et al., arXiv, 2016). If the exit is a device on a carrier, it almost certainly shares its public address with strangers.
How mobile proxies work
The path has five hops: client, proxy gateway, carrier device, carrier core, target. The client authenticates to the gateway with a username and password, and the gateway hands the request to a device in the ordered location. In the carrier core, the CGN swaps the device’s internal address for a shared public one, and the target answers that public carrier IP.
Paired addressing. RFC 6888 (April 2013) makes “paired” pooling the default, so all of one subscriber’s connections leave on the same public address, and it lets carriers cap the ports each subscriber gets. Hundreds of parallel connections through one device can hit that carrier port cap before any proxy limit; the detail is in CGNAT explained for proxy buyers.
Can mobile proxies be detected?
Yes. The address is one signal next to the TLS and browser fingerprint, timezone, language, request pace and whether the session’s location stays put.
Why a carrier IP is harder to block. Cloudflare’s CGNAT detection research (October 29, 2025) notes that one public IPv4 address behind CGNAT can represent hundreds or even thousands of users, so blocking it disconnects people who did nothing wrong. Platforms that recognize a shared carrier address tend to challenge or slow a session rather than ban the IP.
Why it is not a free pass. The same post found CGNAT addresses were rate limited three times more often than other addresses, while their median bot rate was nearly identical (4.8% against 4.7%). A per-IP limiter throttles a busy address whoever stands behind it, and when another subscriber on the address trips a defence, the scrutiny lands on the proxied requests too.
IP databases also expect carrier addresses to churn. MaxMind’s user context data (checked September 2026) gives many cellular addresses a static IP score under 1.0, against above 30 for residential broadband, so a carrier IP that changes between sessions is what the database expects to see. The outcome depends on the target and the client more than on the address, which is why no honest vendor can quote a universal detection rate. The full signal stack is broken down in mobile proxy detection in 2026.
A challenge on a clean carrier address usually points at the client: pace, fingerprint or a session that changed country mid-login. The full list is the subject of why proxies trigger captchas.
How mobile proxies rotate
A carrier IP belongs to a device’s data session, and it changes when that session changes. Every rotation mode, whatever it is called, rests on that one fact.
Reconnect rotation. On a pool built from phones or modems, what usually causes a new IP is the device dropping its data connection and attaching again: an airplane-mode toggle, or a modem reconnect. The carrier builds a new session and the exit often lands on a different public address, but the carrier’s public pool is finite and shared, so a reconnect can hand back an address used minutes earlier.
Carrier-driven change. Carriers also move addresses on their own schedule. Idle mappings expire fast: Richter et al. measured a median idle UDP mapping timeout of 65 seconds on cellular CGNs, and once a device has no live mapping left, paired pooling no longer ties its next connection to the old public address. Devices also hand off between cells, and sessions get rebuilt overnight. A sticky session is sticky until the network decides otherwise, and client code has to survive that.
Rotating vs sticky sessions. proxymint’s mobile proxies offer a new IP on every request, a timer from 5 to 60 minutes, or sticky for as long as the device stays online. Per-request suits stateless collection. A timer suits multi-step flows: a search, a few pages, a form. Sticky suits logged-in sessions, because a cookie that appears from a new IP on every click reads as account sharing.
3G, 4G or 5G. The radio generation changes throughput and latency, not the address class the target sees. 5G carried 48% of mobile data traffic at the end of 2025, according to the Ericsson Mobility Report (June 16, 2026), so 4G is still ordinary carrier traffic. proxymint’s mobile pool runs on mobile carrier networks, with exits classified as cellular by MaxMind. When the generation matters is covered in 4G vs 5G proxies.
What to measure on any pool. Three numbers decide whether rotation behaves as sold: how long a sticky session holds, how often a rotation returns one of the last ten addresses (the repeat rate), and how many unique IPs appear in 100 per-request calls. The test below scripts the last one; the other two need a timer and a log.
Where mobile beats other tiers
The tier fits where a target cares about the origin of a connection, not only whether it looks like a person.
What mobile proxies are used for
- App-first account work. For agencies managing client accounts, the platform’s own route comes first: Meta Business Manager, partner access or team roles. When a team still needs a consistent login origin for accounts it owns or manages on a phone-first app, a carrier IP in the right market matches what the platform expects. Desk-based teams on web dashboards fit static ISP proxies better: one fixed address for the term.
- Mobile ad verification. The creative and redirect chain a carrier user sees can differ from what a home user sees, so checking a campaign means requesting it from a carrier IP in its market, the job ad verification proxies exist for.
- App QA on carrier routing. Geo-gated features, carrier CDN routing and timeouts under mobile latency only show up on a real carrier path.
Where mobile is the wrong tool
Price monitoring, catalog scraping and bulk collection from lenient targets clear on rotating residential proxies or datacenter proxies, because those targets never check for a carrier origin. Any job that needs one fixed address for weeks fails here, because carrier IPs move by design.
The table lines the four tiers up on the attributes that decide a purchase; how a home address earns its trust is covered in what is a residential proxy.
The second table makes the same call job by job.
Two comparisons go deeper: residential vs mobile proxies maps which targets need a carrier origin, and mobile vs ISP proxies weighs moving identity against fixed identity.
What the traffic costs
proxymint prices mobile per GB as one-off packages with no renewal. The rate per GB falls as the package grows, with volume bands on the pricing page.
Pricing models. Mobile is sold two ways across the market: per GB, or a flat price per port or device per day or month. Per GB wins for light, bursty or media-blocked jobs, where a rented device would sit mostly idle. A flat plan only wins when a job pushes a lot of bytes through one device every day.
Bytes per task. Cost follows bytes, not requests or IPs. As a planning assumption, if one mobile ad capture moves about 3 MB, 1 GB covers about 333 captures (1,000 MB / 3 MB), so the package size follows from bytes per capture. Measure the bytes of ten real captures before sizing a package, and block images, video and fonts the job does not need, because every byte bills at carrier rates.
Test a pool before scaling
Any vendor page can answer “what are mobile proxies” with “real phones”. Setup and testing take five minutes and check three claims on the pool itself: an endpoint, a credential and an IP that belongs to a carrier.
1. Set up the endpoint. Pick country, region or city from the locations with devices online, and the rotation mode; both are set on the order. The pool returns HOST, PORT, USERNAME and PASSWORD. On proxymint, both can be changed later on the same credentials, and the same port speaks HTTP and SOCKS5.
2. Send one request and read the exit IP.
curl -x "http://HOST:PORT" -U "USERNAME:PASSWORD" https://api.ipify.org
3. Confirm the ASN is a carrier. Look the address up in a public IP-to-ASN service. The AS name should be a mobile operator in the ordered country; a hosting company there means it is not a carrier IP, whatever the label says.
whois -h whois.cymru.com " -v EXIT_IP"
4. Check rotation against the order. In per-request mode, 20 calls should return several different addresses, with some repeats, because carrier addresses are shared. In timed or sticky mode, the address should hold until the timer ends or the device drops.
import requests
from urllib.parse import quote
# Percent-encode the login so @, : or / in a password cannot break the URL
user = quote("USERNAME", safe="")
password = quote("PASSWORD", safe="")
proxy = f"http://{user}:{password}@HOST:PORT"
seen = []
for _ in range(20):
r = requests.get("https://api.ipify.org", proxies={"http": proxy, "https": proxy}, timeout=30)
seen.append(r.text.strip())
print(f"{len(set(seen))} unique IPs in {len(seen)} requests")
5. Check DNS and the market. Set Accept-Language to the market whose pages the job needs. DNS matters too: with a plain socks5:// URL the client resolves hostnames through its own network, while socks5h:// and HTTP CONNECT leave the lookup to the proxy side. Check where the target’s geolocation database puts the exit, too: the IMC 2016 study found the CGN six or more hops from the device in 10% of cellular networks (Richter et al., arXiv, 2016), and centralized gateways can pull an IP’s apparent city away from the device’s real one.
How to judge a mobile pool
Every vendor claims the best pool. Five checks replace the claim with evidence:
- ASN. A sample of exits, not one IP, resolves to mobile operators in the ordered country.
- Locations online now. Locations come from devices online at order time, not a static country list.
- Rotation. Sticky hold time and repeat rate hold up in the log.
- Billing unit. Per GB or per device, matched to the job’s bytes per day.
- A small first package against the real target.
Sourcing and legality
Legality. Using a proxy, mobile included, is legal in most jurisdictions. Computer-misuse law, data-protection law and the target’s terms of service apply to the job, not the tool. This is general information, not legal advice.
Ethical sourcing. A pool device is either hardware the operator runs on its own SIMs, or a consumer’s phone sharing bandwidth through an app. The second model needs clear, informed consent from the phone’s owner.
Choose mobile when origin matters
Mobile proxies sell carrier IPs that many real subscribers share: costly for a target to ban, impossible for a buyer to hold. The job table sorts most jobs, and three calls remain:
- Check the origin first. If the target expects a phone on a carrier, a home or hosting IP fails on context.
- Weigh what one flag costs. If a single block costs an account’s history or a campaign’s evidence, carrier trust is the requirement. If it only costs a retry, residential or datacenter serve the job.
- Ask whether the address must stay. If the job needs one IP for weeks, no carrier IP will hold. Use an ISP proxy.
When the call is still open, run the five-step test against the real target on the smallest package and count successful tasks per GB. The guide to types of proxies maps every tier side by side.
Frequently asked questions
Mobile proxies route requests through phones, modems or SIM devices attached to 4G and 5G carrier networks. The target sees a public IP announced by the mobile carrier, usually shared by many real subscribers behind carrier-grade NAT. That sharing makes the address costly for a platform to ban, and the IP changes when the carrier rebuilds the device's session.
Yes. The IP is one signal among several, and platforms also score the browser fingerprint, timezone, language, request pace and whether the location stays consistent. A carrier IP is harder to block outright because banning it cuts off real subscribers, so platforms tend to challenge or slow the session instead. No vendor can honestly quote a universal detection rate.
Using a proxy, including a mobile one, is legal in most jurisdictions. What is done through it is judged separately: computer-misuse law, data-protection law and the target's terms of service still apply to the job. This is general information, not legal advice.
The best provider is the one whose pool passes a test on the real target. Check that exit IPs resolve to a mobile operator ASN, that the needed locations have devices online, that rotation modes match the job, and how billing works. Start with the smallest package and count successful tasks per GB before scaling.
No. A mobile proxy is a rented exit on a carrier network, so requests from a server or laptop leave through a carrier IP. A proxy set on a phone is the reverse: the phone's own traffic is routed through some other proxy, which can be any tier. The first changes the origin a target sees; the second changes where a phone's apps connect from.
A VPN tunnels all of a device's traffic to the VPN provider's server and exits there, and most commercial VPN exits sit on hosting ranges that anti-bot systems classify quickly. A mobile proxy handles the requests an application sends through it and exits on a carrier IP. A VPN is a privacy tool for one device; a mobile proxy changes the origin a target sees.
proxymint prices mobile proxies per GB as one-off packages with no renewal. The rate per GB falls as the package grows, with volume bands on the pricing page.