An IP scrambler is a tool that changes your IP address often, usually for every request. The term has no technical meaning: no RFC uses it. In practice it means a rotating proxy, or a VPN or Tor that keeps switching exits. RFC 9110 describes a proxy as "a message-forwarding agent that is chosen by the client". A rotating proxy simply sends each request out through a different exit.
What does that change about you? We sent eight requests through eight different free proxies on 11 October 2026. The address changed. The TLS fingerprint, the user agent and the cookie did not.
How does an IP scrambler work?
There are two common ways to build one.
The first is a rotating proxy service. You connect to one gateway, and the gateway picks the exit. Our own documentation describes the default mode this way: "Every request through the line can exit from a different residential IP." Most services also offer the opposite, a sticky session, which "holds the SAME exit IP instead of rotating per request".
The second is a list. You take many proxies, for example from a free list, and send each request through the next one. That is what we tested, because it shows the idea without a gateway in between.
What did our test show?
We used the same client for every request: curl, with one user agent and one cookie. Each request went through another proxy from our free list to a public test page that reports what it receives, including the TLS fingerprint.

Three things stand out:
- The address changed, but not every time. Eight proxies gave six addresses. Two of them left through the address of another proxy on the list, so a new proxy did not always mean a new exit.
- Free rotation is unreliable. We had to try 13 proxies to get 8 answers.
- Nothing else changed. The TLS fingerprint, the user agent and the cookie were identical in all eight answers.
What does rotation not change?
The TLS fingerprint. Before any page loads, your client opens an encrypted connection and describes itself in a ClientHello message. The JA4 method "looks at the TLS Client Hello packet and builds a fingerprint of the client based on attributes within the packet". A proxy only passes that message through, so the fingerprint stays the same behind every exit. We explain the method in what is JA3/JA4 fingerprinting.
The headers. The user agent is a string that "lets servers and network peers identify the application, operating system, vendor, and/or version" of the client, in MDN's words. It comes from your software, not from the proxy.
The cookies. A cookie stays in your client and goes out through every proxy, as we showed in HTTP cookies explained. One cookie can tie eight addresses to one visitor.
The browser fingerprint. In our CreepJS runs, the fingerprint ID stayed the same through a proxy. Only a change inside the browser, its time zone, moved it.
Even Tor treats a new address as only half of a new identity. Tor Browser's New Identity button exists "to prevent your subsequent browser activity from being linkable to what you were doing before". It does more than switch exits: it will "close all your open tabs and windows, clear all private information such as cookies and browsing history, and use new Tor circuits for all connections".
Rotating or sticky?
Rotation helps when every request stands alone. Our documentation calls it best for "scraping, wide coverage, and spreading load". It works best when each identity also starts with an empty cookie jar.
A login, a cart or a checkout needs the opposite: in the same documentation's words, "a stable identity across several requests". A sticky session keeps one exit for that time. We compare the two in sticky vs rotating proxy sessions.
Our residential proxies offer both, rotating on every request or sticky for a set time.
What this page could not check
- One run of eight answers through free proxies from our own list. We did not measure paid rotating services, VPNs or Tor.
- The client was curl, so its TLS fingerprint and headers are curl's, not a browser's.
- The test page reports what reached it. We did not test a site that actually links visitors.
- From outside we cannot tell why two proxies shared an exit: a chain, one operator's gateway or a shared network would all look the same.
- Free proxies change within hours. We will run the test again by 11 January 2027.
Sources
- RFC 9110, HTTP Semantics, IETF, June 2022: rfc-editor.org.
- FoxIO, JA4 TLS Client Fingerprinting, read 11 October 2026: github.com.
- MDN Web Docs, User-Agent header, read 11 October 2026: developer.mozilla.org.
- RFC 6265, HTTP State Management Mechanism, IETF, April 2011: rfc-editor.org.
- The Tor Project, Tor Browser manual, Managing identities, read 11 October 2026: tb-manual.torproject.org.
- HProxy, Proxy API plans, rotating and sticky lines, read 11 October 2026: hproxy.com/docs/proxy-api/plans.
- Our own test: eight requests through eight free proxies from our server, 11 October 2026, 07:54 UTC.



