What is a residential proxy? How it works and when you need one
A residential proxy sends traffic out through a home ISP connection. How it works, where the IPs come from, whether it is legal, and what it costs per GB.
Quick summary · TL;DR
- A residential proxy borrows a home ISP label. Requests exit from a device on a consumer ISP ASN (Comcast
AS7922, AT&TAS7018), so the target sees a household IP instead of a hosting range. That label opens at medium-to-high trust. - Sites increasingly detect it anyway. IP-intelligence feeds now flag residential proxy exits as their own category, and whole companies sell that detection. The IP buys an opening score, not a finished request.
- Residential is the middle of the ladder. It clears targets that stop datacenter ranges, but static ISP holds one identity over days better, and mobile is the tier for platforms that expect a mobile origin.
- Sourcing and use decide legality. The technology is legal to buy in most jurisdictions. How the device was enrolled and what the traffic does are what cross the line, so ask how a provider enrolls its devices before buying.
What is a residential proxy? By definition, it is an intermediary that forwards a client’s requests through an IP address a consumer ISP assigned to a home connection. The target sees a household IP on a consumer ISP’s network, not the client’s own address and not a hosting range. That label is what buyers pay for, and it raises sourcing, detection and cost questions.
A price monitor checks a retailer’s product pages in three cities, and at request 30 the clean 200s turn into 503s. The IPs were datacenter ranges out of Hetzner, cheap and fast, and the edge flagged the ASN before the first byte of HTML shipped. Moving the job to a residential proxy changes the arithmetic, because the request now leaves a home broadband line instead of a rack in a server farm.
What a residential proxy is
A residential proxy is an intermediary that sends a client’s requests out through an IP address a consumer ISP assigned to a home connection. The target sees a household IP on a consumer ISP’s autonomous system (ASN), such as Comcast (AS7922), AT&T (AS7018) or Deutsche Telekom (AS3320), not the client’s address and not a hosting range.
How a residential proxy works
The request path has four hops:
- The client (a scraper, a browser, a rank tracker) connects to the provider’s gateway with a username and password.
- The gateway picks a home device that is online in the country, region or city the order asked for.
- That device, on a consumer ISP line, opens the connection to the target.
- The target answers the device, and the reply travels back the same way.
The target logs the device’s IP, the consumer ISP’s ASN, and a geolocation that matches the chosen location. A pool is thousands of these devices across cities and ISPs.
What makes an IP residential
Two labels, and neither is under the proxy’s control. The ASN says who announces the address: a consumer ISP like Comcast, or a hosting company like Hetzner, OVH or DigitalOcean. And IP-intelligence databases attach a type to every network, so a site reads “ISP” or “hosting” in one lookup. Residential proxies are ordinary home IPs borrowed for a request, so where those homes come from is a real question for the buyer.
How the trust mechanism works
The mechanism runs in two stages, and both happen before a target reads what the request is asking for.
Stage one: ASN classification. The edge looks up the IP’s owner, checks whether it reads as a consumer ISP or a hosting company, and cross-references abuse databases and blocklists. IP data vendors package that lookup: the IPinfo ASN database (updated October 28, 2025) sorts every network into ISP, hosting, education, government or business, so a site can challenge the hosting type in one rule while consumer ISP addresses pass to the next check. A residential proxy passes this first cut because its ASN says “home broadband subscriber.”
Stage two: fingerprinting. This is where the residential IP earns or loses the rest of its budget. Modern stacks fingerprint the TCP/IP handshake, reading TTL, window size, and TCP option order to catch a Linux server tunneling through a residential exit while its User-Agent claims Windows. They triangulate latency against the claimed location. They scan for exposed proxy services on open ports (SOCKS5 on 1080, HTTP on 3128 or 8080, RouterOS on 8291). And they hash the TLS ClientHello into JA3 and JA4 signatures: one client rotating through many residential IPs shows up as one rare JA3 across all of them inside a short window.
So a home IP buys a strong opening score and nothing more. The IP layer clears; the automation layer still has to behave.
Can websites detect residential proxies?
Yes. IP-intelligence feeds now label residential proxy exits as their own category: MaxMind’s Anonymous IP database documentation (checked September 29, 2026) describes an is_residential_proxy flag for addresses on a suspected anonymizing network that belong to a residential ISP. Whole companies sell that detection to fraud teams.
Behavior adds to it. One account hopping across dozens of residential IPs in minutes reads as automation. Every flagged exit lowers the success rate, and the success rate sets the real bill.
Rotating versus sticky sessions
Residential proxies come in two session types on the same pool, rotating and sticky, and a static ISP address covers the third case, one identity held for days. Picking wrong wastes the trust the IPs bought.
Rotating. Rotating residential proxies swap the exit IP on every request or on a timer; on proxymint the timer runs from 5 to 60 minutes. That suits stateless reads at a pace the target allows: price monitoring, search-result collection, catalog crawls.
Sticky. Sticky sessions pin one exit IP for a 5 to 60 minute timer, or as long as the home device stays online: long enough to hold a login, walk a checkout, or finish a multi-step form. Logged-in work on accounts the customer owns, or runs for clients with permission, needs sticky. A session that rotates mid-login looks hijacked and gets challenged.
Peer churn. The exit is somebody’s home device, and home devices go offline, reboot, or get a new IP overnight. When that happens a sticky session cannot survive on that address: the connection drops or the exit changes. So long jobs need retry logic plus a clean re-login path. A job that needs one identity for days belongs on static ISP proxies: an ISP-registered address assigned to your order for the whole billing term, with no home device to go offline.
The failure mode is mixing them up. Rotating on an account flow breaks state; sticky on a high-volume crawl burns one IP into a rate limit. The same split decides ISP proxies versus rotating residential when the job needs one persistent identity.
Where residential sits on the ladder
The trust ladder climbs datacenter, then residential, then ISP, then mobile, and residential is the middle rung.
Datacenter proxies clear most unprotected targets but are the first to be challenged behind a real bot-management layer, on strict retail and marketplaces especially, because the hosting label is the cheapest signal to act on. Residential clears that gate, and the margin narrows once Imperva, Akamai, or DataDome combine IP trust with fingerprinting. Mobile usually sits highest because carrier ASNs and CGNAT on shared carrier IPs protect the address, covered in proxymint’s guide to what platforms actually check on mobile proxies.
Each rung serves a different requirement. Datacenter proxies are billed per port and suit volume on lenient targets, residential is usage-based per GB for broad consumer-origin coverage, and mobile proxies are per GB for platforms that expect a carrier origin.
What residential costs per month. Residential is a one-off per-GB package with no subscription, with a rate that falls across the volume bands on the pricing page, so a month’s bill is the traffic moved. Cost per successful request is the useful metric: a pool clearing 80% of requests spends a fifth of its traffic on failures, and one clearing 25% spends three quarters, so the success rate moves the bill more than the rate card.
The residential vs datacenter proxies question resolves on target hardness. If the target is unprotected or lightly gated, datacenter is enough and residential adds nothing the target checks. And on platforms that expect a mobile origin, mobile is the tier that holds. Recommending residential there would be dishonest.
Residential proxy vs VPN
A VPN is a different tool. Its exits sit on the VPN company’s server ranges, every subscriber on a server shares them, and the whole device tunnels through; IP-intelligence feeds label those ranges on sight. A residential proxy works per request or per app, exits on a home ISP line, and lets the client choose the city. A VPN protects a person on café Wi-Fi. A residential proxy makes a data job arrive from a household in a given market.
How pools are sourced
Every residential IP comes from a real household, so a complete answer to what is a residential proxy includes how that household’s connection joined the pool. That origin is now a legal question as well as a technical one.
The FBI’s March 12, 2026 alert (PSA I-031226-PSA) says some device owners consent and others never learn their connection is in use. It names five routes in:
- Bundled apps that carry proxy code without a clear consent screen.
- Free VPNs that enroll devices through terms few people read.
- Compromised IoT devices such as streaming boxes, some shipped with malware.
- Malware in pirated games, films and software.
- Bandwidth-sharing apps that pay for spare bandwidth.
The alert is written for the public and for defenders. It does not call residential proxies illegal, and it does not list legitimate uses either.
The courts are pulling on the same thread. In October 2025, Reddit sued Perplexity together with three scraping and proxy vendors (Reddit, Inc. v. SerpApi LLC, filed in the Southern District of New York on October 22, 2025). On July 31, 2026 the court largely denied Perplexity’s and SerpApi’s motions to dismiss and kept the DMCA anti-circumvention and civil-conspiracy claims. The case is still open in late September 2026.
Pool size stopped being a quality signal too. Google’s disruption of IPIDEA (January 28, 2026) found many residential brands controlled by the same actors on the same infrastructure, and many of the apps involved never disclosed that they enrolled devices.
So ask specific questions. How do devices join, did their owners agree, and can they leave? What happens when abuse is reported? A provider that answers with a pool size is answering a different question. proxymint’s residential exits come from device owners who opted in and can opt out at any time.
Are residential proxies legal?
Once a reader knows what is a residential proxy, this is usually the next question. In most jurisdictions the technology is legal to buy and use. This is not legal advice, and the answer turns on two things.
How the IPs were obtained. A device enrolled with its owner’s informed consent is one thing. A device enrolled through malware, a compromised streaming box or buried terms is another, and that is what the FBI alert and Google’s IPIDEA action go after.
What the traffic does. City targeting is a legitimate tool for local SERP and price checks. The FBI’s own account-takeover example uses a same-city IP to log in to a victim’s bank account with stolen credentials, and that is exactly the kind of use proxymint’s terms of service ban.
Those terms rule out the uses the FBI lists: fraud and identity theft, credential stuffing and unauthorized account access, malware, spam, fake accounts and fake engagement, and bots that bulk-buy tickets or limited stock. Customers must have the rights and lawful basis for the data they collect, and proxymint acts on abuse reports.
How to spot a fake pool
Fake or poorly sourced residential pools leave tells, and a short check on a trial surfaces most of them. The commands use 203.0.113.10, a documentation address; swap in a real exit IP.
1. The ASN. Ask who announces the exit.
whois -h whois.cymru.com " -v 203.0.113.10"
If the AS name is a hosting company, the “residential” label is decoration and the pool scores as datacenter on stage one, the same ASN reputation test every tier faces.
2. The IP type. Read the org and type fields in an IP-intelligence lookup, and check the sample subnets against abuse lists.
curl -s https://ipinfo.io/203.0.113.10/json
3. The sticky hold. Log the exit IP every 30 seconds through a sticky session.
while true; do
echo "$(date +%T) $(curl -s -x http://HOST:PORT -U 'USERNAME:PASSWORD' https://api.ipify.org)"
sleep 30
done
A 30-minute session should print one IP for 30 minutes. Every early change is peer churn, so count them in a few cities.
4. The fingerprints. Through a CONNECT tunnel the TLS ClientHello is the client’s own, so a TLS echo endpoint should report the same JA3 or JA4 hash through every exit. A hash that changes means something in the path rewrites TLS. The TCP/IP fingerprint should do the opposite and vary, because real homes run different routers and operating systems. Dozens of “homes” sharing one Linux server signature point to a single stack behind the pool.
A fake pool rarely fails loudly. Success rate just slides, and cost per successful request climbs with it.
When residential is the honest tier
If the target runs a real anti-bot layer (Cloudflare, Akamai, Imperva, DataDome) and the job is one of the fits below, a residential proxy is the honest tier: enough trust to clear the ASN gate, where the target does not ask for a mobile origin. If the target is lightly gated, datacenter is fine. If the job needs one identity for days, static ISP holds. And if the platform expects a mobile origin, test mobile.
What residential proxies are used for
Where residential fits:
- E-commerce price and stock monitoring across markets.
- Search result and local SEO tracking by location.
- Ad verification on desktop and home networks.
- Brand protection and marketplace monitoring.
- Public pages on targets that block datacenter ranges.
Where it is the wrong tool:
- Keeping one identity for days. Home devices go offline; an ISP proxy holds.
- Platforms that only trust mobile origins.
- High-volume jobs against lenient targets, where datacenter is faster and built for volume.
Before buying, weigh cost per successful request over headline $/GB, and ask how the devices were enrolled.
Frequently asked questions
A residential proxy is an intermediary that sends a client's requests out through an IP address a consumer ISP assigned to a home connection. The target sees a household IP on a consumer ISP's network (ASN), not the client's own address and not a hosting range, and that label is what earns it more trust than a datacenter IP.
No, not in most jurisdictions: the technology is legal to buy and use. Legality turns on how the IPs were obtained, with or without the device owner's consent, and on what the traffic does. Fraud, credential stuffing, unauthorized account access and fake accounts are illegal through any connection. This is general information, not legal advice.
Residential proxies are usually billed per GB rather than per month, so the monthly cost is the traffic a job moves. On proxymint, residential is a one-off package with no subscription, with a per-GB rate that falls across the volume bands on the pricing page. The success rate moves the real bill more than the rate does.
A shared exit can inherit someone else's abuse history and arrive already flagged. A badly sourced pool carries legal and procurement risk, because some devices are enrolled through malware or hidden terms. The provider sees connection metadata, such as timestamps, volumes and the destinations sessions reach. And plain HTTP is readable by anything in the path, so requests to the target site should run over HTTPS end to end.
Buy a per-GB package from a provider, choose the country, region or city and the rotation mode, connect over HTTP or SOCKS5, and authenticate with the username and password the provider issues. Before the real job, send one request through it to an IP lookup and confirm the exit sits on a consumer ISP. Avoid free residential proxies: the FBI ties free VPNs and bandwidth-sharing apps to hidden device enrollment.
The IPs belong to real consumer devices. The FBI's March 2026 alert lists five routes into these networks: apps that bundle proxy code without a clear consent screen, free VPNs with hidden terms, compromised IoT devices, malware in pirated content, and bandwidth-sharing apps. Some owners consent and some never know. Ask a provider how devices join, whether owners agreed and whether they can leave, and how it handles abuse.
It resolves on target hardness. If the target is unprotected or lightly gated, datacenter is enough and residential adds nothing the target checks. The gap only opens once a real anti-bot layer (Cloudflare, Akamai, Imperva, DataDome) is in the path, where hosting ranges are the first to be challenged and residential IPs hold longer. For platforms that expect a mobile origin, neither wins consistently and mobile is usually the tier that holds.