Most proxy "providers" do not own a proxy network. They rent access to a bigger pool, put their own dashboard and billing page on top, and sell it as if the network were theirs. That is not a scandal by itself. Reselling is a normal, legal way to run a business, and some of the most honest providers in this market resell upstream pools and tell you so. The problem is the version that hides it: a storefront with a world-beating pool number, a friendly name, and a vague non-answer when you ask where the IPs come from. When you buy from that, you are not buying redundancy or a private network. You are buying a logo in front of someone else's infrastructure, and inheriting whatever that infrastructure has been doing.
We run a competing network and we track every rival in it, so we spend a lot of time working out which brands are real and which are skins. This is the field guide: the tells that a provider is reselling a pool it does not control, the checks you can run yourself in ten minutes, and the honest way to tell an upfront reseller from a hidden one. None of it requires insider access. All of it is checkable from the outside.
Reselling is not the crime, hiding it is
Start with the honest frame, because the loudest version of this argument gets it wrong. The claim is not "resellers are frauds." Half the industry resells, including brands you would call reputable, and there is nothing wrong with buying wholesale access and adding your own tooling, support and billing. The crime, when there is one, is the dishonesty around it: a shared pool sold as a private one, a rented network sold as an owned one, and a sourcing question met with silence. That combination is what turns a normal reseller into a liability, because it is exactly the profile of every botnet-sourced pool that has been taken down.
Here is what you are actually paying for when the reselling is hidden.
The target site never sees the brand you paid. It sees the upstream network: its IP ranges, its ASN, its reputation. If that upstream is a botnet, or a pool that three hundred other customers are hammering, the friendly logo on the billing page protects you from none of it. This is why "who do you actually resell" is a fair question to ask any provider, and why the ones who cannot answer it plainly are telling you something.
The tells of a reseller skin
No single sign proves a brand is a hollow reseller. Stacked together, they are hard to explain any other way. Here are the six that do the most work.
It has no network of its own. Every real network on the internet announces its address space through an autonomous system, or ASN, a numbered block that says "these IP ranges are mine" (we explain the concept in what is an ASN). A provider that genuinely operates infrastructure usually has one, or is transparent about whose it uses. A pure reseller has none: take an IP it gives you, look up the ASN, and it belongs to a cloud host or another company entirely. That is not automatically damning, most residential providers legitimately route through consumer ISPs, but it means the "network" is not theirs, and the next tells decide whether that is disclosed or disguised.
The pool number is round, huge, and not unique. Real pool sizes are messy and hard to state. Rented ones get advertised in confident round numbers, and those numbers travel. The IPIDEA cluster is the clearest case: four of its "separate" brands each advertised 80 to 200 million IPs, which cannot be four independent pools because the total would dwarf the entire legitimate industry. The same coincidence shows up in the Chinese domestic market, where a brand new operator and an unrelated typosquat both advertised the identical figure of 90 million IPs. When the same suspiciously round number appears on multiple sites, you are looking at one pool with several price tags.
It hides behind a shell, at an address other brands share. Follow the corporate registration and a reseller skin often lands at a shell company: a Hong Kong, Cyprus or offshore entity with a virtual-office address and no real staff. That alone is legal and common. It becomes a tell when the same shell, or the same building, sits behind more than one "independent" brand. Mars Brothers Limited, a Hong Kong shell, stands behind both PIA S5 Proxy and LunaProxy. Prince Legend Limited, behind ABC Proxy, registers at The Phoenix on Luard Road in Wan Chai, a mailbox address used by hundreds of companies. In our own scan of competitor domains, eleven routed their registration through a single Bahamas privacy registrar. One entity, many logos, is the shape.
It has a rebrand in its past. Names get changed for good reasons, but in this industry a sudden new name on the same infrastructure, especially after bad press, is a recurring move to shed a history. We lay the documented chains out below.
The pool appeared overnight. You rent millions of residential IPs, you do not build them in a month. A brand that incorporated last year and already advertises a world-leading pool did not lay that infrastructure, it bought access to it. One Chinese operator registered in 2025 was advertising 90 million IPs within about a year of incorporation. Fast is not proof, but a network that large with a birthday that recent came from a wholesaler.
It dodges the sourcing question. This is the one that ties the rest together. Ask a provider, in plain words, how its residential IPs get into the pool. A network that runs on consented, disclosed opt-in can answer directly and often names the mechanism. A reseller that does not know or does not want to say gives you marketing language where a plain sentence belongs. Academic work has been flagging this gap for years: a 2019 study at the IEEE Symposium on Security and Privacy found residential-proxy providers routinely claim their hosts "willingly joined," while many of the IPs ran on likely compromised devices. Vagueness is not shyness. It is the answer.
- No ASN of its ownthe IPs announce from someone else's network
- Round, borrowed pool numbersthe same 90M or 200M shows up across brands
- A shell address shared with other brandsone offshore entity, many logos
- A rebrand chainan old name and a sudden new one on the same infrastructure
- A huge pool that appeared overnightyou rent millions of residential IPs, you do not build them fast
- Dodges the sourcing questionmarketing language where a plain answer belongs
- Says how the pool is sourced, plainlyconsented, disclosed opt-in it can name
- Lets you verify any IP you are givena real checker, not a screenshot
- A findable legal entity and real peoplenot just a mailbox
- A consistent identity over yearsno unexplained rebrand
- Honest about being a reseller if it is onewelcomes the sourcing question instead of dodging it
The rebrand chains, laid out
Rebrands are the reseller market's paper trail. A brand accumulates bad press or a burned reputation, and the cleanest fix is a new name over the same pool. Here are the documented ones, none invented, each traceable to reporting or the companies' own records.
Same pool, new name
Blue marks the brand you would meet on a shelf today. Each chain is documented in reporting or the company's own filings.
Luminati started by reselling free Hola VPN users' bandwidth as proxy exit nodes, then renamed to Bright Data in 2021. The network began as resold VPN traffic.
Microleaves, whose software antivirus vendors flagged as a trojan, rebranded to Shifter around 2020 under new ownership. New name, older baggage.
Founded as Blazing SEO in 2015, rebranded to Rayobyte in 2022, and sits under the holding company Sprious. A rebrand can be perfectly clean, this one looks it.
The team behind the Scrapy framework renamed Scrapinghub to Zyte in 2021. Not every rebrand hides something, know which is which.
Smartproxy, in the Tesonet portfolio, rebranded to Decodo on April 22, 2025, keeping the same accounts and infrastructure. Same pool, cleaner name.
After 911 S5 was exposed and its operator sanctioned, the same botnet model re-emerged as CloudRouter, then fed the 922Proxy and IPIDEA cluster. The dark version: a network that renames to outrun a takedown.
Notice the ledger does not point one way. Blazing SEO to Rayobyte and Scrapinghub to Zyte are ordinary corporate housekeeping. Microleaves to Shifter and 911 S5 to CloudRouter to 922Proxy are the network outrunning its reputation. The rebrand itself is neutral. What matters is whether the new name is honest about what the old one was, which is exactly the transparency test the rest of this guide keeps landing on.
How to check in ten minutes
You cannot audit a provider's whole supply chain from the outside, but you can settle the reseller question fast, with public tools and one IP.
- Get one IP and look up its network. Take any IP the provider hands you, from a trial, the dashboard, or the gateway's exit, and paste it into a WHOIS or IP-intelligence lookup, or run
whois <ip>from a terminal. Read the ASN and the organization. A "residential" IP that resolves to Amazon, Alibaba, OVH or another cloud host is datacenter, full stop. - Compare the gateway across brands. Resolve the gateway hostname the provider gives you. If two brands you are told are separate hand you the same gateway host, or IPs in the same block, they share a back-end. This is the single fastest way to catch a skin.
- Run the WHOIS on the company, not just the IP. Look up the domain's registration and the company behind it. A generic offshore shell, a virtual-office address, or a registrar known for anonymity are all worth a second look, especially if the same details show up on another brand.
- Check the brand's past with the Wayback Machine. Search the domain and the company name in the Internet Archive. A rebrand shows up as an older name on the same site, and a "ten-year-old provider" whose site only appears in 2024 is telling on itself.
- Verify the IP through a checker. Run the IP through a proxy checker to see the real network, the anonymity grade and the reputation behind the label before you trust it. A hijacked or blacklisted address shows itself here, no matter what the storefront claimed.
None of these steps needs the provider's cooperation, which is the point. A network that stands behind itself has nothing to lose when you run them. A skin does.
Reselling done honestly, and what to ask
To be fair to the honest half of the market, here is what the good version looks like. IPRoyal sources its residential pool through Pawns.app, an opt-in bandwidth-sharing app where users are paid and know they joined, and the company says so on the record. That is a reseller-adjacent model, users' connections routed for a fee, done with disclosure and consent. The label "reseller" is not the problem there, because the sourcing is stated and the arrangement is honest. Contrast that with a provider that sources through backdoored browser extensions or silent SDKs and never mentions it, and the difference is not the business model. It is the honesty.
So when you press a provider, ask the questions that separate the two:
- How is the residential pool sourced, in one plain sentence?
- Do you operate this network, or resell an upstream, and which?
- Can I verify any IP you give me against its real network and reputation?
- What was this brand called before, if anything?
A provider that answers those without flinching has passed the only test that matters. One that reaches for marketing language has answered too.
Where HProxy fits
We can pass our own test, which is the whole reason we wrote this. HProxy is independent, not a skin of a larger group, and our position is transparency over pool-size theater: we would rather tell you plainly what our network is and let you verify every IP than headline a number we cannot stand behind. Our residential proxies are $0.65/GB pay as you go with no KYC and a balance that does not expire, and you can inspect the machinery before you trust it. Run the free proxy checker against any IP, ours or a competitor's, to see the real network behind it, and browse the live free proxy list to see exactly what we show and how we label it. If you want the ownership map that sits under all of this, who owns your proxy provider traces which "rivals" are really siblings, and Google erased 13 proxy brands in one move shows the reseller-skin model at its most extreme.
Sources
- Wikipedia, Bright Data and Globes, EMK Capital acquires Luminati (Luminati spun out of Hola VPN reselling users' bandwidth, renamed Bright Data 2021, EMK Capital bought ~75% in 2017)
- KrebsOnSecurity, Microleaves / Shifter and the residential proxy trade (Microleaves flagged as trojan by AV vendors, rebranded to Shifter around 2020; Infatica sourcing via backdoored browser extensions)
- Rayobyte, about / company history and saas.group (founded as Blazing SEO 2015, rebranded Rayobyte 2022, under Sprious)
- Proxyway, Smartproxy rebrands, becomes Decodo (rebrand effective April 22, 2025; also DataImpulse under Softoria, NodeMaven run by the Multilogin team, Massive's SDK sourcing)
- Google Threat Intelligence Group, disruption of the IPIDEA residential proxy network (one operator behind IP2World, PIA S5, LunaProxy, ABC Proxy and more, tied through shared Hong Kong shells including Mars Brothers and Prince Legend)
- KrebsOnSecurity, Treasury sanctions creators of the 911 S5 proxy botnet and U.S. Treasury, sanctions announcement (911 S5 to CloudRouter to 922Proxy lineage, Yunhe Wang)
- IPRoyal, how the residential pool is sourced via Pawns.app (opt-in, paid, disclosed bandwidth sharing as the consented model)
- Xianghang Mi et al., "Resident Evil: Understanding Residential IP Proxy as a Dark Service", 2019 IEEE Symposium on Security and Privacy (providers claim hosts "willingly joined" while many run on likely compromised devices)