Skip to content

Transparent vs anonymous vs elite proxies: proxy anonymity levels, tested

Only 15% of the HTTP proxies on our free list were elite, and httpbin's default header page hides the leak. Proxy anonymity, measured on 10 October 2026.

HProxy TeamJuly 21, 2026Updated October 10, 202612 min read

Transparent vs Anonymous vs Elite Proxies: The Anonymity Grades Explained

Proxy anonymity is what a proxy tells the website about you. A transparent proxy passes your real IP address on in a header. An anonymous proxy hides your address but still admits that a proxy is in the path. An elite proxy, also called high anonymity, hides both, so the request looks direct.

A few HTTP headers decide the level, and you can only see them in a plain http request. On our free list on 10 October 2026, 67.3% of graded proxies were elite, but only 15.3% of the HTTP proxies were.

We rewrote this guide on 10 October 2026 from new measurements. From our own server, we sent requests through public proxies of each level to an echo we run and to httpbin.org. We also read the grade counts of our list. The July figures from our data study stay, with their date.

What are the three proxy anonymity levels?

A proxy's level answers two questions: does the site see your real IP address, and does it see that a proxy relayed the request? The answers give three levels.

LevelYour real IPProxy visible to the site?What the site typically receives
TransparentPassed onYesX-Forwarded-For with your address, often Via
AnonymousHiddenYesVia or another proxy header, none of your address
Elite (high anonymity)HiddenNoThe headers of an ordinary direct request

Each level hides one more fact than the one before. Transparent hides nothing, so it adds a hop and gives you no cover. Anonymous does the main job, since your address is gone, yet the site can tell that a proxy sits in the path. Elite hides both facts, so pick it whenever looking proxied is itself the problem.

The level is not a claim you have to trust but a property of the request, which you can measure. A label on a list is only as good as the last check behind it.

Which headers decide proxy anonymity?

An HTTP proxy that forwards a plain http request can add headers about where the request came from. Four kinds matter most.

  • X-Forwarded-For is the classic. MDN calls it a "de-facto standard header" for finding the original client behind a proxy. The leftmost address in it is that client, so this is where a transparent proxy puts yours.
  • Forwarded is the standard successor. RFC 7239 defined it in 2014 to carry what the X-Forwarded- headers carried, in one field. It also says that a proxy meant for client anonymity "will not use" it. When a proxy does fill its for part, the RFC asks for an obfuscated identifier by default, not your address.
  • Via is the proxy's own mark. RFC 9110 says that "A proxy MUST send an appropriate Via header field" in each message it forwards. It names the protocol and the proxy, and an optional comment may name the software. It carries no address of yours, but it tells the site that a proxy relayed the request.
  • X-Real-IP and the rest carry a single address or another proxy tell. Our checker looks for ten names in all, from Client-IP to Proxy-Connection.

The level follows from those headers. Your address in any of them makes the proxy transparent, a proxy header without your address makes it anonymous, and neither makes it elite.

One detail surprises people: an elite proxy breaks the HTTP standard, because it leaves out the Via that RFC 9110 requires. Proxy software treats that as a setting. Tinyproxy's manual says that turning Via off "virtually puts Tinyproxy into stealth mode", and that "you break compliance".

Squid works the other way round. By default it appends your address to X-Forwarded-For and adds Via, so an open Squid proxy on default settings is transparent. Its own options can send X-Forwarded-For: unknown or drop the header altogether.

What does a website receive through each level?

We tested this on 10 October 2026. From our own server, we sent one plain http request through each of 15 HTTP proxies per level on our free list, to the echo our checker uses. We kept only the headers each proxy added, and replaced our address with OUR-ADDRESS.

Terminal output: the headers a transparent and an elite proxy added to our request
Our own capture, 10 October 2026, 21:04 UTC

All 15 transparent proxies answered, and all 15 put our address in X-Forwarded-For. Several added other headers as well.

Header the proxy addedTransparent proxies (of 15)
X-Forwarded-For15
X-Real-IP6
Via6
X-Forwarded-Host, -Port, -Proto, -Server5 each
Cache-Control3
X-Proxy-Id3

The elite proxies were quiet: of the 15, 14 answered, 13 added nothing at all, and none showed our address. The one exception added a non-standard header named X-SWG-Via. None of the 15 anonymous proxies answered our echo; we come back to them below.

The transparent proxy in the capture shows how much one header can give away. Its Via names the software in a comment, MikroTik HttpProxy, as RFC 9110 allows. Some of the other proxies wrote our address in its IPv6-mapped form, with ::ffff: in front. A check that compares whole header values with your address would miss those.

How common is each level?

On 10 October 2026 at 20:50 UTC, our free list held 5,417 live proxies, and 5,413 carried a grade. The split depends heavily on the protocol.

Anonymity level of graded proxies on our free list (%)
  • Data study, July 2026
  • All proxies, 10 Oct 2026
  • HTTP proxies, 10 Oct 2026
Most HTTP proxies on a free list are not elite.
Source: HProxy free proxy list API, 10 October 2026, 20:50 UTC; July split from our 129M-check free-proxy data study · hproxy.comProxy.
LevelAll graded proxiesHTTP proxiesSOCKS5 proxiesJuly data study
Elite67.3%15.3%99.6%about 67%
Anonymous17.0%44.2%0.4%about 3%
Transparent15.6%40.5%under 0.1%about 30%

Across the whole list, two thirds were elite. Among HTTP proxies the order turns around: fewer than one in six were elite, and about two in five were transparent. SOCKS5 proxies were almost all elite, by design more than by care. SOCKS does not add HTTP headers, so our checker grades every working SOCKS proxy elite, and every HTTPS-only one too.

Our July free-proxy data study, which ran more than 129,131,311 checks across the pool, found a barbell: about 67% elite, roughly 30% transparent and around 3% anonymous. The pools and the dates differ, so the two splits are not a trend. They point the same way, though. A real share of free proxies pass your address on, so a level you did not check yourself is a guess.

What does anonymous mean on a proxy list?

On our list, anonymous covers two cases. In the first, a proxy header arrived but your address did not. In the second, our checker could see only the address the proxy exits from, with no headers at all. It will not call such a proxy elite, so it grades it anonymous at most.

We read 30 of the listed anonymous HTTP proxies through httpbin.org on 10 October, and 21 answered. Of those, 12 added nothing visible, just as an elite proxy would. Others added Via, X-Real-IP or X-Forwarded-For, and a few showed our address. Treat anonymous on any list, ours included, as not yet proven, and test the proxy before you rely on it.

How do you test a proxy's anonymity yourself?

Two rules decide whether a test means anything.

Use plain http. Through an HTTP proxy, an https request travels inside a CONNECT tunnel. RFC 9110 limits the proxy there to "blind forwarding of data" until the tunnel closes. A proxy cannot add headers to a request it cannot read, so over https even a transparent proxy looks clean.

Use an echo that shows every header. The plain httpbin.org/headers page does not. Its code hides X-Forwarded-For, X-Real-Ip and Via unless the address carries show_env. We checked this through listed transparent proxies on 10 October: the plain page hid our address every time, and ?show_env=1 showed it every time.

# first without the proxy, to see what httpbin adds by itself
curl --max-time 10 "http://httpbin.org/headers?show_env=1"
# then through the proxy
curl -x http://203.0.113.10:8080 --max-time 10 "http://httpbin.org/headers?show_env=1"

Compare the two answers. The front end of httpbin adds its own X-Forwarded-For, holding the address that connected to it, plus a few other headers; through a proxy, that address is the proxy's. Then read what the proxy added:

  • Your own address anywhere in the answer means transparent.
  • A Via or another proxy header, without your address, means anonymous.
  • Nothing new beyond the proxy's address means elite.

The quicker way is our proxy anonymity checker. It sends a request through the proxy to an endpoint we control, reads the headers that arrive, and shows the grade with the network beside it. The proxy checker runs the same live test and adds the exit IP, the country and the latency, for HTTP and SOCKS, with no signup. A SOCKS5 proxy adds no HTTP headers at all, so a header test always finds it elite.

Nearly every row on our free proxy list carries a grade, and the elite list shows only elite proxies. When we read the list on 10 October, its rows had last been verified a median of 9.6 minutes earlier, and none more than 21.1 minutes earlier.

Which proxy anonymity level should you use?

Match the level to the job, and the choice is short.

  • Elite, for anything that must not look proxied. Scraping a guarded site, managing accounts, checking prices or ads: in each, a visible proxy is a red flag on its own. Elite is the default to reach for.
  • Anonymous, only where a visible proxy does no harm. It hides your address, which is enough when the site does not care about proxies. If you are choosing anyway, elite hides the same and one fact more.
  • Transparent, never for privacy. It passes your address on, so it adds a hop and hides nothing. It still has honest uses on a network you run. RFC 9110 notes that proxies often group an organization's requests "for the sake of security services, annotation services, or shared caching".

For hiding who you are, transparent loses outright, and elite is the level to insist on.

Does an elite proxy make you anonymous?

Only toward the header check, because the level measures one thing: the headers the site receives. Three other facts decide whether a proxy works and whether it protects you.

The network. An elite grade cannot hide what kind of address the proxy uses. On 10 October, 1,967 of the 3,639 elite proxies on our list sat on ranges our data marks as datacenter, a best-effort flag. A proxy can send perfect direct-looking headers from a datacenter IP block, and a site that checks who owns the address still sees it. We walk through those checks in how websites detect proxies, and why the owner of the network matters in what is an ASN.

The operator. A proxy receives your request in order to satisfy it, so whoever runs it can read a plain http request in full. Over https, the CONNECT request still names the host and port of every site you open. We cover this side, with the free-proxy angle, in free anonymous proxy: what it hides and what it leaks.

Honesty. Some proxies tamper with https itself. Our checker also tests whether the certificate that comes back through a proxy is the real one. On 10 October it had tested 1,793 of the elite proxies, and 181 of them returned a forged certificate. Their grade stayed elite, because the grade reads headers only.

Treat the level as the first question, not the last. Check it yourself, then make sure the network agrees with what the headers say. You want elite headers, on a network that fits the job, from an operator you have reason to trust.

That combination is what a paid residential proxy is for. Our residential proxies exit from real consumer-ISP addresses, on pay-as-you-go pricing from $0.44/GB, with no identity checks for standard top-ups and a balance that never expires. If your work is surveys, our page on proxies for surveys explains why survey panels block proxies and what works.

What else can transparent proxy mean?

The proxy-list levels are one of three meanings of the word. The other two come from the standards, and RFC 3040 recommends always adding a word in front of the term "to avoid confusion".

RFC 9110 uses transparent proxy as a common name for an interception proxy. Such a proxy "is not chosen by the client". Instead, it "filters or redirects outgoing TCP port 80 packets". If a network sends your web traffic through a proxy without any setting on your device, that is this kind.

RFC 3040 uses the word differently again. There, a transparent proxy "does not modify the request or response beyond what is required for proxy authentication and identification". A non-transparent proxy does modify them to add a service, and the RFC names "anonymity filtering" among its examples. In that sense, every elite proxy is a non-transparent proxy.

What this page could not check

  • We read headers through 15 to 30 public proxies per level, not through the whole list. The split comes from our own checker, whose rule is fixed.
  • We sent plain http requests to our echo and to httpbin only. Real sites may also weigh the network, the TLS fingerprint and behavior, which no anonymity level covers.
  • We did not test the proxies of paid providers.
  • The certificate check had covered 2,163 of the 5,536 proxies on our list on 10 October, so its shares can move as it covers more.
  • The datacenter flag is a best-effort classification of the network, not a verdict.
  • The July study and the October list are different pools on different dates. The list changes by the minute, and we will measure it again by 10 January 2027.

Sources

Frequently asked questions

What is the difference between transparent, anonymous, and elite proxies?

It comes down to two questions: does the site see your real IP address, and does it see that a proxy is in the path? A transparent proxy passes your address on in a header such as X-Forwarded-For. An anonymous proxy hides your address but still sends a proxy header such as Via. An elite, or high anonymity, proxy hides both, so the request looks direct.

What is an elite proxy?

An elite proxy, also called a high anonymity proxy, forwards your request without adding any header that names you or the proxy. The site sees the proxy's address and an ordinary request. Strictly, this breaks the HTTP standard, which says a proxy must send a Via header. Elite describes headers only: the address can still belong to a datacenter network.

How do I check my proxy's anonymity grade?

Send a plain http request through the proxy to a page that shows every header it receives, then look for your own address and for proxy headers. With curl: curl -x http://IP:PORT --max-time 10 'http://httpbin.org/headers?show_env=1'. Without show_env, httpbin hides X-Forwarded-For, X-Real-Ip and Via. Never test over https, where the proxy only tunnels the request and cannot add headers. Our free proxy anonymity checker runs the same test for you.

Which headers reveal my real IP through a proxy?

Mostly X-Forwarded-For, the de-facto header whose leftmost address is the original client. Forwarded is its standard successor from RFC 7239, and X-Real-IP is a common variant. Via carries no address of yours, but it tells the site that a proxy relayed the request. Our checker looks for ten such headers, and some proxies add their own, such as X-Proxy-Id.

Does an elite proxy make me anonymous?

Only toward the header check. An elite proxy adds nothing that names you, but the site still sees which network the address belongs to: on 10 October 2026, 1,967 of the 3,639 elite proxies on our free list sat on datacenter ranges. The operator can also read plain http traffic, and 181 of the 1,793 elite proxies we had checked for tampering returned a forged HTTPS certificate.

Are most proxies elite?

On our free list, yes, but not among HTTP proxies. On 10 October 2026, 67.3% of all graded proxies were elite, yet only 15.3% of the HTTP ones were, and 40.5% of HTTP proxies were transparent. SOCKS5 proxies were 99.6% elite, because SOCKS cannot add HTTP headers. Our July data study found about 67% elite, 30% transparent and 3% anonymous.

Are SOCKS5 proxies elite?

For headers, yes. A SOCKS5 proxy relays your traffic below HTTP and adds no X-Forwarded-For or Via, so our checker grades every working SOCKS proxy elite. That says nothing about the network the address belongs to, or about who runs the proxy.

What is a non-transparent proxy?

In RFC 3040, a non-transparent proxy is one that changes the request or response to add a service, and anonymity filtering is one of its examples. A transparent proxy, in that sense, changes nothing beyond what proxy authentication and identification need. The HTTP standard uses transparent proxy for a third thing: an interception proxy that the client never chose.

Proxies that don't die mid-job

Residential, ISP, datacenter and mobile, verified by the same engine that runs tens of millions of checks. They read as a real device and hold up under load. Pay as you go, and your balance never expires. $0.44/GB is the 2,000 GB+ rate; a single gigabyte is $0.50/GB, with no minimum order.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup

HProxy.

Honest guides and comparisons on proxies, scraping and staying unblocked, from the team that runs the network.

RSS feed