Explainer

What Is the Proxy Industry, and Why Does It Exist?

What the proxy industry is and why it exists: the five layers of the trade, real prices, where residential IPs come from, and the court record.

HProxy Team··35 min read
HProxy.Explainer

Skip the dead lists.

Our free proxy list re-checks every exit every few minutes across 100+ countries, with a live last-checked time, so you copy IPs that worked moments ago, not a stale text dump.

Open the free proxy list

The proxy industry rents access to other people's IP addresses. A provider assembles a pool of addresses: data centres, internet providers, ordinary homes, phones. It then sells the right to send traffic out through them, normally priced by the gigabyte. It exists because the internet attaches identity, permission and price to the address a request arrives from. One address cannot sit in two countries. It cannot spend an unlimited request budget, and it cannot be swapped out once a website has blocked it. Everything else in this market, the brands, the dashboards, the rotation logic, the arguments about ethics, sits on top of that single gap.

We run a proxy network, so read the opinions here with that in mind and the numbers with their sources. Every figure below either comes from a primary document you can open yourself, or from a measurement we ran and describe well enough for you to repeat. Where the honest answer is that nobody knows, this page says so instead of borrowing a number from a market report.

What the proxy industry actually sells

A proxy is an old and boring piece of plumbing. The current HTTP specification is RFC 9110. It defines a proxy as "a message-forwarding agent that is chosen by the client, usually via local configuration rules, to receive requests for some type(s) of absolute URI and attempt to satisfy those requests via translation through the HTTP interface". RFC 1928 standardised SOCKS version 5 in March 1996. Firewalls were spreading, and the specification says "there exists a need to provide a general framework for these protocols to transparently and securely traverse a firewall". Getting an application across a boundary was the original purpose. Disguising who was asking was not.

The industry sells three things bundled together, and confusing them is the most common mistake a buyer makes.

The first is an address, with a location, an owner and a reputation attached to it. The second is a route, meaning the servers and session logic that carry your request to that address and back, including how often the address changes. The third is a promise about how the address looks to the site you are visiting: that it will read as a home in Ohio rather than a rack in Frankfurt.

Three things it is not. It is not a VPN business, although several companies run both: a VPN sells one person a private tunnel, a proxy network sells many people the use of many strangers' addresses. It is not a data business, although the two are converging fast, because a data provider sells you the answer while a proxy provider sells you the ability to go and ask. And it is not privacy. A proxy moves the point where your traffic enters the public internet. Whoever operates that point can see what leaves it.

Why the industry exists at all

Five facts about how the internet is built, none of them about proxies, together create the market. Take away any one of them and the industry shrinks to a niche.

An address is the cheapest question a website can ask

Every request arrives with an address, and that address is the one piece of identity a site gets for free, before any cookie, login or fingerprint. From the address a site can look up the network that owns it through its autonomous system number, estimate a country and city, and pull a reputation score assembled from past abuse. That lookup costs a fraction of a millisecond and it happens on defended sites before the page is built.

The court record shows how deep this goes. In Meta's case against Bright Data, the court's order sets out Meta's own account of its defences. The list includes a lockout mechanism, CAPTCHA challenges, and machine-learning models that detect automated activity. It also includes "imposing rate and data limits that restrict the number of times anyone can interact with Meta's computers and view certain types of data". The order recording that description is public (Northern District of California, 23 January 2024). Rate limits are counted per something, and on the open web that something is usually the address.

Two of our own pages go into what a site sees when it looks: what makes an address clean, and how to read a fraud score.

There are not enough addresses, so addresses became an asset

On 25 November 2019 the registry that hands out addresses across Europe, the Middle East and Central Asia announced that it had none left. The RIPE NCC's own statement contains the clearest sentence anyone has written about why this market exists. "In recent years, we have seen the emergence of an IPv4 transfer market and greater use of Carrier Grade Network Address Translation (CGNAT) in our region. There are costs and trade-offs with both approaches and neither one solves the underlying problem, which is that there are not enough IPv4 addresses for everyone."

Scarce things get priced. Geoff Huston, chief scientist at the Asia Pacific registry, publishes an annual measurement of that market. His review of 2025 was published on 20 January 2026. It records a mean transfer price of 22 dollars per address, with a low of 9 dollars for a large block. It also records 33 million addresses transferred inside the registry system during the year. He also tracks leasing, which is the part that matters here: one broker's leased pool grew from 0.7 million addresses at the start of 2022 to 9.2 million.

Renting addresses is therefore not an exotic idea invented by proxy companies. It is a normal part of how the address system now works, and proxy networks are its retail end.

The second consequence of scarcity is carrier-grade NAT. RFC 6598 reserved a block of addresses in April 2012 so that providers could put many subscribers behind one public address, because "IPv4 address space is nearly exhausted. However, ISPs must continue to support IPv4 growth until IPv6 is fully deployed." That is why a mobile address is the most expensive product in this industry: behind it sits a crowd of real subscribers, and a site that blocks it blocks paying customers too. We wrote up the mechanism in what CGNAT is and what it does to pricing in what a mobile proxy is.

Websites ration and restrict by address, on purpose

Rationing has its own standard. RFC 6585 defines status code 429, where "the user has sent too many requests in a given amount of time". A server that wants to give everyone a fair share counts requests against something stable, and the address is the default choice. One address therefore carries a request budget, and any job larger than that budget needs more addresses. This is the entire technical basis of the scraping half of the market.

Geographic restriction is the other half, and it survives for legal reasons rather than technical ones. The European Union banned unjustified geo-blocking inside its single market. The European Parliament announced on 30 November 2018 that "as of 3 December, Europeans will be able to shop online without unjustified geo-blocking, wherever they are in the EU". The regulation carves out access to copyright-protected content, which is exactly where demand to defeat geography is highest. Streaming catalogues, sports rights and games were left territorial, and they remain so.

Public data turned into a production input

The demand side stopped being a niche some time around 2023. Imperva sits in front of a large share of the world's web applications. Its 2026 Bad Bot Report, published on 29 April 2026, found that "automated traffic continues to outpace human activity online, accounting for more than 53% of all web traffic in 2025, up from 51% the year before". Most of the web's traffic is now machines, and every one of those requests needs an address a target will accept.

Then came model training. Cloudflare measured the gap between what AI crawlers take and what they send back, and published it on 29 August 2025. One major crawler "crawled 38,000 pages for every referred page visit in July 2025", the largest imbalance among the big AI companies. Its 2025 year in review separates the purposes, finding that crawling for model training reached "as much as 7-8x search crawling and 32x user action crawling at peak" across the year.

The money follows. Alarum Technologies, the Nasdaq-listed parent of the NetNut proxy network, is the only company in this industry with audited public accounts. It reported group revenue of 40.7 million dollars for 2025, up 28 percent, and told the market that growth "was driven primarily by expanding workloads from large-scale artificial intelligence ('AI') customers". That statement is in an exhibit filed with the SEC on 19 March 2026.

One honest limit on all of this. A large part of the public web can be downloaded without any proxy at all. Common Crawl has been publishing an open corpus since 2008. Its own overview states that access to the data hosted on Amazon is free. Plenty of collection work does not need this industry. The work that does need it is the work that is fresh, personalised, regional or defended.

Somebody is willing to rent out their connection

Supply exists because home bandwidth is mostly idle and money is money. Consumer applications advertise the trade openly. Honeygain's own site, read on 12 September 2026, invites visitors to "sell internet data and earn money automatically". The same page claims twelve million users in one place and over sixty million in another, and reports an average payout of 27 dollars. Cisco Talos named the category in research published on 31 August 2021. Users "share a percentage of their bandwidth with other internet users for a fee, with the companies that created this software acting as a go-between".

That is the consenting end of the supply chain. The rest of it is the most uncomfortable part of this industry, and it gets its own section below.

The five layers of the trade

Almost every confusion about this market comes from mistaking one layer for another. A brand is not a network. A network is not an address holder. A tool that bundles proxy access is not a proxy provider.

Who is actually in the chain when you buy a gigabyte
  1. Address holders

    registries, hosting firms, ISPs, carriers, individual devices

  2. Pool operators

    the few dozen networks that really exist

  3. Brands and resellers

    most of the names you can buy from

  4. Tools

    scraper APIs, antidetect browsers, agents

  5. Buyers

    commerce, ad tech, security, travel, AI labs

Source: HProxy: our own competitor register, 1,254 brands tracked, read 12 September 2026

Address holders own or control the addresses. Registries allocate them, hosting companies buy and lease them, internet providers and mobile carriers hold large ranges, and hundreds of millions of households hold one each without knowing it.

Pool operators assemble addresses into something sellable: exit software, session management, a gateway, a billing system. There are far fewer of these than there are brands. When a supplier's gateway has a bad day, every brand in front of it has a bad day at the same moment, which is how outages reveal the shape of the market.

Brands and resellers are most of what you can buy. Some own their pool, many rent access to somebody else's and put a logo on it. We wrote about how to tell the difference in does your provider resell someone else's network and what a white label proxy provider is. The mobile end of the market is even more concentrated than the residential end. One vendor's software turned out to be running behind a long list of separate mobile brands, which we documented in one software behind many mobile proxy brands.

Tools bundle proxy access into something with a different name. A scraper API is a proxy pool with retry logic and a parser. An antidetect browser is a fingerprint manager that needs an address to be useful. AI agents that browse on a user's behalf are the newest example. Imperva's 2026 report describes them as "a new category of internet participant", one that interacts with sites rather than only reading them.

Buyers are less exotic than the industry's own marketing suggests. Price and catalogue monitoring in retail, ad verification, travel fare data, brand protection, cybersecurity research, app store and search result checks, social media operations, and now model training. Sitting alongside them is a criminal demand that law enforcement documents in detail, and which this page treats as a fact rather than a footnote.

Our own register holds 1,254 brands, of which 1,237 sell proxy access directly. On 12 September 2026, 625 of their sites answered normally, 305 were dead, 30 returned a 403, 11 were parked, and 44 of the domains were free to register. Roughly one name in four that we have ever recorded is already gone.

What a pool actually is, and what you are paying for

A pool is three pieces of software and one commercial arrangement. A buyer sees none of them, which is the single most important fact about shopping in this market.

The gateway is what you connect to. You are handed one hostname and port, a username that encodes your options, and a password. Every decision about which address your request leaves from happens behind that hostname. You are buying a decision made by somebody else's software, which is why two brands quoting the same price per gigabyte can return completely different results on the same job.

The exit is a program running on a device somewhere else. It takes the relay instruction, opens the connection to the target, and carries the answer back. Its quality sets your latency and your failure rate. Nothing on a pricing page describes it.

The session layer maps you to an exit and holds you there for as long as your job needs. A session that survives ten minutes and a session that changes address on every request are different products at the same advertised price. The mechanics are in what a rotating proxy is and sticky versus rotating sessions. Sticky duration is an upper limit, never a promise, because the exit is a stranger's device and it can leave at any moment.

The commercial arrangement is the fourth piece, and researchers found that the architecture is built to hide it. The 2019 academic study of five commercial services identified "hidden backend gateways in the RESIP service infrastructure, which decouple the clients and RESIPs in their infrastructure". The front door you connect to is deliberately separated from the network that carries your traffic. That separation is what makes reselling invisible to the customer.

What it costs, and how to read a price

Prices in this market are quoted in incompatible units on purpose. Traffic is sold by the gigabyte, static addresses by the address and month, scraping APIs by the thousand successful requests. Comparing two numbers in different units is how buyers talk themselves into the wrong product.

We keep a register of published prices, captured from providers' own pages. The table below is the distribution of the 862 plans we captured in August 2026, of which 783 were verified a second time against the live page.

What the market charges, by product type

Our own price register: 862 plans captured from providers' published pages in August 2026, 783 of them verified twice. Distributions are across plans, not weighted by volume sold.
ProductUnitPlansCheapestTypicalMost expensive
Rotating residential trafficper GB391$0.10median $2.50$12.50
Mobile trafficper GB74$0.35mean $3.64$9.83
ISP (static residential) addressper IP67$0.17mean $2.91$14.41
Data centre addressper IP60$0.02mean $1.18$5.00
Data centre trafficper GB46$0.14mean $0.48$1.00
Scraping APIper 1,000 requests64$0.00mean $2.52$36.75

HProxy price register, captured August 2026

The residential quartiles are worth stating in full, because that is the line most buyers are quoted on. They run 1.00 dollar at the lower quartile, 2.50 at the median, 4.00 at the upper quartile and 5.99 at the ninetieth percentile.

Three things to take from that table. The spread inside one product is wider than the gap between products: rotating residential traffic runs from 10 cents to 12.50 dollars per gigabyte, so a quoted price tells you almost nothing on its own. The lower quartile of one dollar per gigabyte describes the market's working floor better than the headline figures on the largest providers' pages. And the ladder from data centre to residential to mobile is a ladder of how hard the address is to block, which is the only thing a buyer is actually paying for.

Why the ladder exists is worth one paragraph. A data centre address is cheap because it is easy to identify and therefore easy to refuse. A residential address costs more because it belongs to a household, so refusing it has a cost for the site. An ISP address sits in between: provider-owned space, hosted in a data centre, which buys stability. A mobile address costs the most because of RFC 6598: a crowd of real subscribers sits behind it, and blocking the crowd is expensive for the target. The full taxonomy is in types of proxies.

The price of a gigabyte fell by a factor of ten

The same 2019 study recorded what this market charged when it was young. Proxies Online, the first residential service the researchers found, "increased their price from $3/GB to $25/GB in 6 months" during 2017. Nine years later our register of 391 published residential plans puts the median at 2.50 dollars and the lower quartile at 1.00 dollar.

What a gigabyte of residential traffic has cost

The 2017 figures are one provider's own price changes as recorded by researchers who bought the service. The 2026 figures are the distribution across 391 published plans in our own register.
WhenWhat was measuredPrice per GBSource
2017, earlyProxies Online, its own list price$3IEEE Symposium on Security and Privacy, 2019
2017, six months laterthe same provider, same product$25IEEE Symposium on Security and Privacy, 2019
August 2026391 published plans, lower quartile$1.00our price register
August 2026391 published plans, median$2.50our price register
August 2026391 published plans, highest$12.50our price register

IEEE S&P 2019 for 2017; HProxy price register for 2026

Three forces did that. Supply was industrialised. Paying consumers a few dollars a month for spare bandwidth, and paying app developers to embed a software kit, turns supply into a manufacturing process rather than a scarce find. The address market matured underneath it, with a mean transfer price of 22 dollars per address in 2025 and one broker's leased pool growing from 0.7 million addresses to 9.2 million since early 2022. And volume buyers arrived who negotiate by the terabyte rather than the gigabyte, which pulls the published rate down for everyone.

The direction of travel has one consequence worth stating plainly. A market whose unit price falls by an order of magnitude while its costs stay real is a market where somebody is cutting a corner. Which corner, and by whom, is the subject of the next two sections.

Where the addresses come from, and who agreed

This is the question the industry answers least often and least clearly. There are six routes into a pool, and they differ enormously in who knew and who was paid.

Six ways an address enters a proxy pool

Each row names the document that establishes it. Consent falls away down the table.
RouteWho knowsWho is paidThe record
Data centre space leasedthe hosting company and the buyerthe hosting companyordinary commercial leasing; registry transfer and lease data, APNIC 2026
Provider address range contractedthe network owner and the buyerthe network ownerhow ISP products are built; no household is involved
Bandwidth-sharing app installed for paymentthe user, if they read what they installedthe user, in small amountsthe apps' own marketing; Cisco Talos, 31 August 2021
Software kit inside another applicationthe app developer; the user often not at allthe app developerGoogle Threat Intelligence, 28 January 2026: over 600 Android apps
MalwarenobodynobodyUnited States indictment of the 911 S5 operator: 19 million addresses
Device compromised before purchasenobody, and a factory reset does not helpnobodyFBI public service announcement, 12 March 2026

HProxy, from the primary documents listed at the end of this page

The bottom two rows are not hypothetical. In May 2024 the United States Treasury sanctioned the operators of a residential proxy service called 911 S5. The notice states that it "compromised approximately 19 million IP addresses". It also states that the service "essentially enables cybercriminals to conceal their originating location, effectively defeating fraud detection systems". The indictment is more specific about how the pool was built. The operator "surreptitiously propagated the malware through Virtual Private Network (VPN) programs; torrent distribution models run by WANG; and pay-per-install services that bundled WANG's malware with other program files, including pirated versions of licensed software". Free VPN downloads were a recruitment channel. The same document records 613,841 of those addresses as being in the United States.

Two much larger actions followed in 2026, and both are documented by the company that carried them out. On 28 January 2026 Google's threat intelligence group described its disruption of a network it calls IPIDEA. It counted over 600 Android applications carrying the proxy software kit and 3,075 distinct Windows binaries reaching its control domains. A dozen retail brand names sold access to the same pool. Its sharpest sentence is about who the customers were. In a single seven-day period in January 2026 its analysts observed "over 550 individual threat groups that we track" using addresses it identifies as IPIDEA exit nodes. That list included "groups from China, DPRK, Iran and Russia".

On 2 July 2026 the same group, working with the FBI, acted against NetNut. It estimated the network at "at least 2 million devices, distributed across the world". In a single week of June 2026 it observed 316 distinct threat clusters using those exit nodes. NetNut is not an underground brand. Its parent, Alarum Technologies, is listed on Nasdaq. The day after the seizure it told investors that "if these disruptions continue for an extended period, they are likely to have a material adverse effect on the Company's operations". The same filing said the company was investigating whether its network had been used for unlawful purposes. Four months earlier the same company had reported record revenue driven by AI customers. We covered the sequence in detail in the NetNut takedown and the IPIDEA cluster.

The platforms have a rule for the software-kit route, and it is short. Google Play's Device and Network Abuse policy states that apps providing proxy services to third parties "may only do so in apps where that is the primary, user-facing core purpose of the app". An SDK hidden inside a flashlight app is not a grey area under that rule.

Trend Micro measured what leaves such networks. Its list, published on 7 February 2023, includes SQL injection probing, scans for system password files, crawling of national identity numbers and bulk registration of social accounts. Its warning to the people who install these apps is the honest summary of the trade. “By allowing anonymous persons to use your computer as an exit node, you bear the brunt of the risk if they perform illegal, abusive, or attack related actions.”

The consent question is not unique to proxies. In February 2024 the United States Federal Trade Commission ordered Avast to pay 16.5 million dollars. The Commission found that the company "promised users that its products would protect the privacy of their browsing data but delivered the opposite". Software installed for one purpose, monetised for another, is a pattern regulators now recognise on sight.

What the inside of this industry looked like when researchers measured it

The paid residential business has been measured independently exactly once at scale. In 2019 a team of ten researchers published "Resident Evil: Understanding Residential IP Proxy as a Dark Service" at the IEEE Symposium on Security and Privacy. They found 17 residential proxy services, bought five of them, and sent 62 million requests through them to servers and a DNS server they controlled. That infiltration recorded 6 million exit addresses across more than 230 countries and 52,905 networks. It is dated now, and it remains the only independent look inside the product.

Four findings from it still describe the industry.

The pools were real, and unevenly sized. The study's own count put Luminati, now Bright Data, at 4,033,418 exit addresses across 17,820 networks, Proxies Online at 1,257,418, ProxyRack at 857,178 and Geosurf at 432,975. Address churn means those are upper bounds on the number of devices, not device counts. The researchers say so themselves, which is more than most pool-size marketing does.

Exit addresses counted inside four paid residential services, 2019
Luminati (now Bright Data)17,820 networks
4,033,418
Proxies Online7,701 networks
1,257,418
ProxyRack8,751 networks
857,178
Geosurf4,971 networks
432,975
Source: IEEE Symposium on Security and Privacy 2019, from 62 million requests sent through services the researchers bought. Churn makes these upper bounds on device counts.

The addresses were mostly genuine, and geographically nothing like the marketing. 95.22 percent were assessed as genuinely residential and only 2.20 percent appeared on public blocklists. The top country was India at 32.2 percent of one provider's pool and 27.9 percent of another's, while a third was concentrated in Russia and a fourth in Turkey at 12.7 percent. A product sold on American and European addresses was substantially supplied by emerging markets, because that is where spare bandwidth is cheapest to buy.

No provider's consent story survived contact with the data. The paper identified 237,029 IoT devices and 4,141 hosts running potentially unwanted programs among the exits. It also identified 67 distinct programs acting as exit software, 50 of which antivirus tools flagged as malicious. Its conclusion is one sentence long: "none of the 5 RESIP providers is a completely consent-based anonymity system and even the most prominent companies like Luminati were found to use suspiciously compromised residential hosts."

One brand's traffic came out of another brand's network. The researchers found that their "infiltration traffic from the IAPS proxies was actually relayed by Hola clients controlled by Luminati". They noted that IAPS ran no background check and accepted bitcoin. Their overlap matrix shows one provider pair sharing 66 percent of observed addresses. A customer buying the stricter brand's compliance was sharing a network with a customer who had passed no checks at all.

Hold that 2019 finding next to Google's January 2026 disruption post, which describes a dozen retail brand names selling access to one sourced pool. Seven years apart, two independent parties looked into this market and found the same shape: fewer networks than logos, and a customer who cannot see which one they are on.

The free layer is a different market

Free proxy lists, the open ports and the browser-based web proxy sites, are how most people meet the word proxy. They are not this industry, and it is worth saying why in one paragraph rather than confusing the two.

Nobody is paid to keep a free proxy alive, so nothing about it behaves like a product. We collect every free endpoint published by 113 public sources and retest all of them continuously. On 12 September 2026, of 774,697 endpoints collected since May, 6,437 were alive, which is 0.83 percent, and 97.4 percent of those live ones sit on addresses already flagged for recent abuse. The browser-based layer has collapsed outright: of the 8,948 sites listed on the largest surviving web proxy directory, not one served a working proxy when we opened all of them on 10 September 2026.

That is a market of abandoned infrastructure, and it deserves its own pages rather than a paragraph in this one. The measurements live in we checked all 8,948 proxy sites. The working list, with its own last-check time on every row, is our free proxy list. The single-address test is the proxy checker, and the legal question is answered in are free proxies legal. The free layer explains one thing about the paid one. Keeping an address available, clean and answerable is work, and work has to be paid for.

The other half of the market is detection

For every company selling addresses there is a company selling the ability to recognise them. That side of the market is larger, better funded and more public: application firewalls, bot management, fraud scoring, device fingerprinting and address-reputation databases.

The two sides push each other along in a way that explains most product decisions in this industry. Data centre ranges are easy to enumerate, so data centre proxies became cheap and weak. Address reputation data got good, so clean addresses became the product and our measurement of the free layer became a measurement of dirty ones. Fingerprinting moved up the stack to the TLS handshake, which is why JA3 and JA4 fingerprinting now matter as much as the address, and why an address alone stopped being enough. The full detection stack is in how websites detect proxies.

There is one asymmetry the defending side cannot engineer away, and it is the reason the mobile tier exists. Carrier-grade NAT means a single mobile address can front thousands of real subscribers. Blocking it is cheap for the attacker and expensive for the site, so well-run sites do not block it. The industry's most expensive product is built on a structural fact about address scarcity, not on anything clever in the software.

The dates matter, because this market changed shape twice in the eight months before this page was written.

Seven years of decisions that made this market what it is
  1. November 2019

    Europe's registry runs out of IPv4

    addresses become a transfer and lease market

  2. June 2021

    Van Buren narrows the US computer-crime statute

    permission, not purpose, decides

  3. April 2022

    hiQ v LinkedIn, on remand

    public data is not accessed without authorisation

  4. April 2022

    India orders five years of subscriber records

    VPN, virtual server and cloud providers

  5. January 2024

    Meta loses its contract claim against Bright Data

    terms do not reach logged-off scraping

  6. February 2024

    FTC order against Avast

    16.5 million dollars over browsing data sold on

  7. May 2024

    911 S5 dismantled and sanctioned

    19 million addresses recruited by malware

  8. July 2024

    A jury finds Booking.com liable for scraping

    5,000 dollars, the statutory minimum

  9. January 2025

    That verdict is set aside

    the loss threshold was not proved

  10. June 2025

    FBI warns on home devices sold as proxies

    millions of infected consumer devices

  11. July 2025

    Cloudflare prices crawler access

    402 Payment Required, with a price

  12. January 2026

    IPIDEA disrupted

    600 Android apps, 550 threat groups in a week

  13. March 2026

    Alarum reports record 2025 revenue

    40.7 million dollars, driven by AI customers

  14. July 2026

    NetNut domains seized

    at least 2 million devices, per Google's estimate

Source: Every entry from the primary documents listed at the end of this page

Four different questions hide inside that one, and mixing them is how both marketing and criticism go wrong. This section describes what courts and regulators have actually decided. It is not legal advice, and the answers differ by country.

Is using a proxy lawful? In the United States and the European Union, yes, in itself. Proxies are ordinary infrastructure, standardised by the IETF and deployed by every large company internally. Some states take a different view of anonymity tools. India's 2022 directions show what a regulatory answer looks like in practice. VPN, virtual server and cloud providers must keep validated subscriber records "for a period of 5 years", and system logs for 180 days, inside the country.

Is collecting data that anyone can see lawful? In the United States the answer has held up in court. On 18 April 2022 the Ninth Circuit, ruling again after the Supreme Court sent the case back, concluded in hiQ Labs v. LinkedIn that the computer-crime statute's "without authorization" concept "is inapplicable where, as here, prior authorization is not generally required but a particular person ... is refused access". The omitted words in that sentence are "or bot", which the court added in the same breath. The opinion leans on the Supreme Court's decision in Van Buren v. United States of 3 June 2021, which read the statute as a "gates-up-or-down inquiry": either you can access a system or you cannot. Purpose stopped being the test. Permission became it.

Is breaking a website's terms lawful? A separate question, decided on contract law, and the answer has surprised both sides. On 23 January 2024 the Northern District of California granted summary judgment to Bright Data against Meta, holding that "the Terms do not apply to Bright Data's logged-off scraping of publicly viewable data". The login screen is where the industry's public-data line is now drawn, and it was drawn there by a court rather than by a vendor. The other direction is just as instructive. A Delaware jury found Booking.com liable under the computer-crime statute for scraping Ryanair in July 2024. In January 2025 the trial judge set that verdict aside, because the claimant had not proved the 5,000 dollars of loss the statute requires. Both outcomes are real, and neither is a rule you can build a business on without advice.

Was the pool sourced lawfully? This is the question that produces sanctions, indictments and seizures. It is also the only one of the four where the buyer's exposure depends entirely on a supplier's conduct. The 911 S5 case, the IPIDEA disruption and the NetNut seizure are all answers to this question, not to the other three. It is also the question a buyer can ask directly: where do the addresses come from, what does the consent flow look like, and what happens to a device owner who wants out.

And one question that sits outside all four: personal data. Collecting public information about identifiable people is governed by data-protection law regardless of how you reached the page, and robots.txt does not help you there. RFC 9309, which standardised robots.txt in September 2022, says so plainly: "These rules are not a form of access authorization."

How big is this industry really?

Nobody outside it knows, and most published figures are worthless. The honest position is short.

One company publishes audited accounts. Alarum Technologies reported group revenue of 40.7 million dollars for 2025, up 28 percent year on year. Fourth-quarter revenue was 11.8 million, up 60 percent, with net profit of 1.0 million dollars and adjusted EBITDA of 4.4 million. That is the whole of the verifiable revenue record for this industry. It belongs to one group whose proxy subsidiary had its domains seized four months later, and it covers that group's business rather than the market.

Everything else in circulation is an estimate with an undisclosed method. Market-report vendors publish compound growth rates for a "residential proxy market" without saying whom they surveyed, and those numbers then travel through provider blogs as facts. This page does not repeat them. The one third-party estimate worth naming is an analysis published by the threat intelligence firm Intel 471 in September 2024, which put the addresses available across the major services somewhere between 90 and 350 million. We have not been able to verify either end of that range. A range that wide is a statement about how little is known.

Three things can be counted instead of estimated.

The number of brands: our register holds 1,254, of which 305 are dead and 44 have domains free to register today. The number of addresses independently measured: six million residential proxy addresses in the 2019 peer-reviewed study, which is now dated and was never a full census. And the number of documented disruptions: two networks of millions of devices each, disrupted eight months apart, in January and July 2026.

A fourth number describes the industry's own information quality. We hold a crawled corpus of 23,797 articles from the blogs of 134 proxy companies. The median article is 1,319 words. 9,410 of them, 39.5 percent, contain no link to anywhere outside their own site, and only 4,826, one in five, contain a table. An industry that publishes 23,797 articles and cites almost nothing is an industry whose buyers cannot check anything, which is the reason this page carries its sources at the bottom.

How this market breaks

Five failure modes recur, and all five are visible from the outside if you know what to look for.

Provenance. A pool is only as defensible as its consent story. The NetNut sequence, record revenue in March 2026 and a federal seizure in July, is the clearest demonstration that provenance is a commercial risk and not only an ethical one.

Concentration. Fewer networks exist than brands, so one supplier's failure surfaces simultaneously across many unrelated logos. The mobile tier, where one vendor's panel software sat behind a long list of brands, is the extreme case.

Resale layers. Each layer between you and the network adds margin and removes information. When something breaks three layers down, the brand you bought from often cannot tell you what happened, because it does not know either.

Address burn. Addresses are a consumable. Every aggressive customer degrades the pool for every other customer, which is why a provider's abuse policy is a technical feature. Our free-layer measurement, 97.4 percent of live endpoints already flagged, is what a fully burnt pool looks like.

Brand mortality. Companies here disappear, rebrand after incidents, or quietly become a skin on somebody else's network. We keep a running record in the proxy graveyard, and the ownership map behind the familiar names is in who owns your proxy provider. One familiar brand in this market traded under a different name before it was rebranded, a history we traced in Shifter was Microleaves.

Where this goes next

Four movements are already documented, and none of them is a prediction dressed up as analysis.

Access is starting to be priced openly. On 1 July 2025 Cloudflare launched pay per crawl. A crawler either "present[s] payment intent via request headers for successful access (HTTP response code 200), or receive[s] a 402 Payment Required response with pricing". If buying access at the front door becomes normal, part of the demand for taking it quietly at the back door goes away.

Address separation is becoming a platform feature. Apple's iCloud Private Relay routes traffic through two relays. In Apple's own description, "the second relay, which is operated by a third-party content provider, generates a temporary IP address" before connecting to the site. When the operating system ships address separation to hundreds of millions of consumers, an address means less as an identifier, and the detection side has to move further up the stack.

The address system keeps shifting underneath. IPv6 deployment grows, carrier-grade NAT spreads, and the address price fell again through 2025 on the registry measurement above. Each of those changes the economics of a product line: cheaper addresses mean cheaper data centre supply, more CGNAT means more crowds to hide inside.

Agents are a new demand class. Imperva's 2026 report describes AI agents as systems that "don't just scan websites; they interact with them, retrieve data, execute workflows, and increasingly act on behalf of users". An agent acting for a real person is neither a scraper nor a browser, and neither the detection side nor the proxy side has settled what it should be allowed to do.

What this page cannot tell you

The size of this industry in revenue. One audited number exists and it is quoted above. Everything else would be a guess with a decimal point.

What share of any named provider's pool is genuinely consented. Nobody outside the provider can measure it, and providers publish claims rather than audits. The documented routes and the enforcement record are in this page; the audit is not, because it does not exist publicly.

What a specific provider charges today. Prices here move monthly. The table above is a distribution captured in August 2026, not a live price list, and the market floor in particular moves downward faster than any published comparison keeps up with.

How much of any pool is compromised today. The only independent measurement of the inside of this industry is from 2019, and this page does not pretend that its numbers still hold. Nobody has repeated that work at scale since.

What proportion of proxy traffic is criminal. Law enforcement documents what it prosecutes, and that is not a denominator. Anyone converting takedown counts into a percentage of the market is inventing the percentage.

We will re-check the prices and the enforcement status of the named networks by 1 December 2026, and the rest of the page by 1 March 2027. Our own measurements are re-read from the pool database at every refresh, so the free-layer figures here carry the date they were taken.

One line of self-interest, since you read this far. Our free proxy list shows what the public layer looks like when every entry carries its last check, and our plans are what the paid layer looks like when the pool is ours.

Sources

  • RFC 1928, SOCKS Protocol Version 5, IETF, March 1996.
  • RFC 6585, Additional HTTP Status Codes (429 Too Many Requests), IETF, April 2012.
  • RFC 6598, IANA-Reserved IPv4 Prefix for Shared Address Space, IETF, April 2012.
  • RFC 9110, HTTP Semantics, IETF, June 2022.
  • RFC 9309, Robots Exclusion Protocol, IETF, September 2022.
  • RIPE NCC, "The RIPE NCC has run out of IPv4 addresses", 25 November 2019.
  • Geoff Huston, "IP addresses through 2025", APNIC, 20 January 2026.
  • European Parliament press service, "Online shopping across the EU to be easier from 3 December", 30 November 2018.
  • Indian Computer Emergency Response Team, Directions under section 70B(6) of the Information Technology Act, 28 April 2022.
  • United States Department of the Treasury, Office of Foreign Assets Control, sanctions on the operators of the 911 S5 botnet, 28 May 2024.
  • Indictment, United States v. YunHe Wang, Eastern District of Texas, published by the Department of Justice, unsealed May 2024.
  • hiQ Labs, Inc. v. LinkedIn Corporation, United States Court of Appeals for the Ninth Circuit, No. 17-16783, 18 April 2022.
  • Van Buren v. United States, Supreme Court of the United States, No. 19-783, 3 June 2021.
  • Meta Platforms, Inc. v. Bright Data Ltd., Northern District of California, No. 23-cv-00077-EMC, order on summary judgment, 23 January 2024.
  • Ryanair DAC v. Booking Holdings Inc., District of Delaware: jury verdict July 2024, judgment as a matter of law for the defendant, 22 January 2025 (reported by counsel of record for the successful party).
  • United States Federal Trade Commission, order against Avast, 22 February 2024.
  • FBI Internet Crime Complaint Center, alert I-060525-PSA on home internet-connected devices used in criminal activity, 5 June 2025.
  • FBI Internet Crime Complaint Center, public service announcement on residential proxy networks, 12 March 2026.
  • Google Threat Intelligence Group, "Disrupting the largest residential proxy network", 28 January 2026.
  • Google Threat Intelligence Group, action against the NetNut residential proxy network, 2 July 2026.
  • Google Play developer policy, Device and Network Abuse, read 12 September 2026.
  • Alarum Technologies Ltd., fourth quarter and full year 2025 results, filed with the SEC, 19 March 2026.
  • Alarum Technologies Ltd., update regarding law enforcement action, filed with the SEC, 3 July 2026.
  • Xianghang Mi, Xuan Feng, Xiaojing Liao, Baojun Liu, XiaoFeng Wang, Feng Qian, Zhou Li, Sumayah Alrwais, Limin Sun and Ying Liu, "Resident Evil: Understanding Residential IP Proxy as a Dark Service", Proceedings of the 2019 IEEE Symposium on Security and Privacy, pages 1185 to 1201.
  • Cisco Talos, "Attackers abusing proxyware platforms", 31 August 2021.
  • Trend Micro Research, "Hijacking your bandwidth: how proxyware apps open you up to risk", 7 February 2023.
  • Imperva (Thales), Bad Bot Report 2026, 29 April 2026.
  • Cloudflare, "The crawl-to-click gap", 29 August 2025.
  • Cloudflare, "Introducing pay per crawl", 1 July 2025.
  • Cloudflare Radar, 2025 Year in Review, December 2025.
  • Apple, "About iCloud Private Relay", read 12 September 2026.
  • Common Crawl Foundation, corpus overview, read 12 September 2026.
  • Our own measurements, all dated in the text: the free proxy verifier database (774,697 endpoints, 238,012,473 checks, read 12 September 2026), the price register (862 published plans captured August 2026), the web proxy directory census (8,948 addresses, 10 September 2026), the brand register (1,254 brands, read 12 September 2026), and the provider article corpus (23,797 articles from 134 brands).

Frequently asked questions

What is the proxy industry?
It is the market for access to other people's IP addresses. A provider assembles a pool of addresses from data centres, internet providers, homes and phones, then sells the right to send traffic out through them, usually priced by the gigabyte. The buyer is paying for an origin a target website will accept, not for privacy and not for data.
Why does the proxy industry exist at all?
Because the internet attaches identity, permission and price to the address a request comes from, and there are not enough addresses to go around. A website decides what to show, what to ration and what to refuse largely by looking at the address. One address cannot be in two countries, cannot spend an unlimited request budget, and cannot be replaced once it is blocked. That gap is the product.
Where do residential proxy providers get their IP addresses?
Six routes, with very different consent. Data centre space is leased. Internet provider address ranges are contracted. Home addresses arrive through bandwidth-sharing apps people install for payment, through software kits embedded in other applications, through malware, and through devices that arrive from the factory already compromised. The United States indictment of the 911 S5 operator states that its 19 million addresses were recruited by bundling malware with free VPN programs, torrents and pay-per-install software.
How much does a proxy cost?
We recorded 862 published plans from providers' own price pages in August 2026. Across the 391 plans that price rotating residential traffic by the gigabyte, the median is 2.50 dollars, the lower quartile 1.00 dollar and the maximum 12.50 dollars. Mobile traffic averages 3.64 dollars per gigabyte, a static provider address averages 2.91 dollars, and a data centre address averages 1.18 dollars.
Have proxies got cheaper or more expensive?
Much cheaper, by roughly a factor of ten. Researchers who bought residential proxy services in 2017 recorded one provider raising its price from 3 to 25 dollars per gigabyte in six months. Across 391 published residential plans we captured in August 2026, the median is 2.50 dollars per gigabyte and the lower quartile is 1.00 dollar. Supply was industrialised, the address market matured, and volume buyers now negotiate by the terabyte.
Is using a proxy legal?
Using one is not itself unlawful in the United States or the European Union, and four separate questions hide inside the one. Collecting data anyone can see without logging in has survived the American computer-crime statute in the Ninth Circuit. Breaking a site's contract is a different matter, and a platform lost that argument against a scraping company in January 2024. How the pool was sourced is a third question, and it is the one that has produced sanctions, indictments and seizures.
How big is the proxy industry?
Nobody honestly knows. Exactly one operator sits inside a company with audited public accounts: Alarum Technologies, the Nasdaq-listed parent of the NetNut proxy network, which reported group revenue of 40.7 million dollars for 2025, up 28 percent, and attributed the growth to large-scale AI customers. Every other figure in circulation comes from market-report vendors who do not publish their method, so this page does not repeat them.

Get proxies that are alive right now

Our free proxy list re-checks every exit every few minutes across 100+ countries, with a live last-checked time, so you copy IPs that worked moments ago, not a stale text dump. When the location has to survive a real check, the paid network holds up.

129M+ proxy checks run · 100+ countries · HTTP / HTTPS / SOCKS · re-checked every few minutes · no signup