The proxy industry rents access to other people's IP addresses. A provider assembles a pool of addresses: data centres, internet providers, ordinary homes, phones. It then sells the right to send traffic out through them, normally priced by the gigabyte. It exists because the internet attaches identity, permission and price to the address a request arrives from. One address cannot sit in two countries. It cannot spend an unlimited request budget, and it cannot be swapped out once a website has blocked it. Everything else in this market, the brands, the dashboards, the rotation logic, the arguments about ethics, sits on top of that single gap.
We run a proxy network, so read the opinions here with that in mind and the numbers with their sources. Every figure below either comes from a primary document you can open yourself, or from a measurement we ran and describe well enough for you to repeat. Where the honest answer is that nobody knows, this page says so instead of borrowing a number from a market report.
What the proxy industry actually sells
A proxy is an old and boring piece of plumbing. The current HTTP specification is RFC 9110. It defines a proxy as "a message-forwarding agent that is chosen by the client, usually via local configuration rules, to receive requests for some type(s) of absolute URI and attempt to satisfy those requests via translation through the HTTP interface". RFC 1928 standardised SOCKS version 5 in March 1996. Firewalls were spreading, and the specification says "there exists a need to provide a general framework for these protocols to transparently and securely traverse a firewall". Getting an application across a boundary was the original purpose. Disguising who was asking was not.
The industry sells three things bundled together, and confusing them is the most common mistake a buyer makes.
The first is an address, with a location, an owner and a reputation attached to it. The second is a route, meaning the servers and session logic that carry your request to that address and back, including how often the address changes. The third is a promise about how the address looks to the site you are visiting: that it will read as a home in Ohio rather than a rack in Frankfurt.
Three things it is not. It is not a VPN business, although several companies run both: a VPN sells one person a private tunnel, a proxy network sells many people the use of many strangers' addresses. It is not a data business, although the two are converging fast, because a data provider sells you the answer while a proxy provider sells you the ability to go and ask. And it is not privacy. A proxy moves the point where your traffic enters the public internet. Whoever operates that point can see what leaves it.
Why the industry exists at all
Five facts about how the internet is built, none of them about proxies, together create the market. Take away any one of them and the industry shrinks to a niche.
An address is the cheapest question a website can ask
Every request arrives with an address, and that address is the one piece of identity a site gets for free, before any cookie, login or fingerprint. From the address a site can look up the network that owns it through its autonomous system number, estimate a country and city, and pull a reputation score assembled from past abuse. That lookup costs a fraction of a millisecond and it happens on defended sites before the page is built.
The court record shows how deep this goes. In Meta's case against Bright Data, the court's order sets out Meta's own account of its defences. The list includes a lockout mechanism, CAPTCHA challenges, and machine-learning models that detect automated activity. It also includes "imposing rate and data limits that restrict the number of times anyone can interact with Meta's computers and view certain types of data". The order recording that description is public (Northern District of California, 23 January 2024). Rate limits are counted per something, and on the open web that something is usually the address.
Two of our own pages go into what a site sees when it looks: what makes an address clean, and how to read a fraud score.
There are not enough addresses, so addresses became an asset
On 25 November 2019 the registry that hands out addresses across Europe, the Middle East and Central Asia announced that it had none left. The RIPE NCC's own statement contains the clearest sentence anyone has written about why this market exists. "In recent years, we have seen the emergence of an IPv4 transfer market and greater use of Carrier Grade Network Address Translation (CGNAT) in our region. There are costs and trade-offs with both approaches and neither one solves the underlying problem, which is that there are not enough IPv4 addresses for everyone."
Scarce things get priced. Geoff Huston, chief scientist at the Asia Pacific registry, publishes an annual measurement of that market. His review of 2025 was published on 20 January 2026. It records a mean transfer price of 22 dollars per address, with a low of 9 dollars for a large block. It also records 33 million addresses transferred inside the registry system during the year. He also tracks leasing, which is the part that matters here: one broker's leased pool grew from 0.7 million addresses at the start of 2022 to 9.2 million.
Renting addresses is therefore not an exotic idea invented by proxy companies. It is a normal part of how the address system now works, and proxy networks are its retail end.
The second consequence of scarcity is carrier-grade NAT. RFC 6598 reserved a block of addresses in April 2012 so that providers could put many subscribers behind one public address, because "IPv4 address space is nearly exhausted. However, ISPs must continue to support IPv4 growth until IPv6 is fully deployed." That is why a mobile address is the most expensive product in this industry: behind it sits a crowd of real subscribers, and a site that blocks it blocks paying customers too. We wrote up the mechanism in what CGNAT is and what it does to pricing in what a mobile proxy is.
Websites ration and restrict by address, on purpose
Rationing has its own standard. RFC 6585 defines status code 429, where "the user has sent too many requests in a given amount of time". A server that wants to give everyone a fair share counts requests against something stable, and the address is the default choice. One address therefore carries a request budget, and any job larger than that budget needs more addresses. This is the entire technical basis of the scraping half of the market.
Geographic restriction is the other half, and it survives for legal reasons rather than technical ones. The European Union banned unjustified geo-blocking inside its single market. The European Parliament announced on 30 November 2018 that "as of 3 December, Europeans will be able to shop online without unjustified geo-blocking, wherever they are in the EU". The regulation carves out access to copyright-protected content, which is exactly where demand to defeat geography is highest. Streaming catalogues, sports rights and games were left territorial, and they remain so.
Public data turned into a production input
The demand side stopped being a niche some time around 2023. Imperva sits in front of a large share of the world's web applications. Its 2026 Bad Bot Report, published on 29 April 2026, found that "automated traffic continues to outpace human activity online, accounting for more than 53% of all web traffic in 2025, up from 51% the year before". Most of the web's traffic is now machines, and every one of those requests needs an address a target will accept.
Then came model training. Cloudflare measured the gap between what AI crawlers take and what they send back, and published it on 29 August 2025. One major crawler "crawled 38,000 pages for every referred page visit in July 2025", the largest imbalance among the big AI companies. Its 2025 year in review separates the purposes, finding that crawling for model training reached "as much as 7-8x search crawling and 32x user action crawling at peak" across the year.
The money follows. Alarum Technologies, the Nasdaq-listed parent of the NetNut proxy network, is the only company in this industry with audited public accounts. It reported group revenue of 40.7 million dollars for 2025, up 28 percent, and told the market that growth "was driven primarily by expanding workloads from large-scale artificial intelligence ('AI') customers". That statement is in an exhibit filed with the SEC on 19 March 2026.
One honest limit on all of this. A large part of the public web can be downloaded without any proxy at all. Common Crawl has been publishing an open corpus since 2008. Its own overview states that access to the data hosted on Amazon is free. Plenty of collection work does not need this industry. The work that does need it is the work that is fresh, personalised, regional or defended.
Somebody is willing to rent out their connection
Supply exists because home bandwidth is mostly idle and money is money. Consumer applications advertise the trade openly. Honeygain's own site, read on 12 September 2026, invites visitors to "sell internet data and earn money automatically". The same page claims twelve million users in one place and over sixty million in another, and reports an average payout of 27 dollars. Cisco Talos named the category in research published on 31 August 2021. Users "share a percentage of their bandwidth with other internet users for a fee, with the companies that created this software acting as a go-between".
That is the consenting end of the supply chain. The rest of it is the most uncomfortable part of this industry, and it gets its own section below.
The five layers of the trade
Almost every confusion about this market comes from mistaking one layer for another. A brand is not a network. A network is not an address holder. A tool that bundles proxy access is not a proxy provider.
Address holders
registries, hosting firms, ISPs, carriers, individual devices
Pool operators
the few dozen networks that really exist
Brands and resellers
most of the names you can buy from
Tools
scraper APIs, antidetect browsers, agents
Buyers
commerce, ad tech, security, travel, AI labs
Address holders own or control the addresses. Registries allocate them, hosting companies buy and lease them, internet providers and mobile carriers hold large ranges, and hundreds of millions of households hold one each without knowing it.
Pool operators assemble addresses into something sellable: exit software, session management, a gateway, a billing system. There are far fewer of these than there are brands. When a supplier's gateway has a bad day, every brand in front of it has a bad day at the same moment, which is how outages reveal the shape of the market.
Brands and resellers are most of what you can buy. Some own their pool, many rent access to somebody else's and put a logo on it. We wrote about how to tell the difference in does your provider resell someone else's network and what a white label proxy provider is. The mobile end of the market is even more concentrated than the residential end. One vendor's software turned out to be running behind a long list of separate mobile brands, which we documented in one software behind many mobile proxy brands.
Tools bundle proxy access into something with a different name. A scraper API is a proxy pool with retry logic and a parser. An antidetect browser is a fingerprint manager that needs an address to be useful. AI agents that browse on a user's behalf are the newest example. Imperva's 2026 report describes them as "a new category of internet participant", one that interacts with sites rather than only reading them.
Buyers are less exotic than the industry's own marketing suggests. Price and catalogue monitoring in retail, ad verification, travel fare data, brand protection, cybersecurity research, app store and search result checks, social media operations, and now model training. Sitting alongside them is a criminal demand that law enforcement documents in detail, and which this page treats as a fact rather than a footnote.
Our own register holds 1,254 brands, of which 1,237 sell proxy access directly. On 12 September 2026, 625 of their sites answered normally, 305 were dead, 30 returned a 403, 11 were parked, and 44 of the domains were free to register. Roughly one name in four that we have ever recorded is already gone.
What a pool actually is, and what you are paying for
A pool is three pieces of software and one commercial arrangement. A buyer sees none of them, which is the single most important fact about shopping in this market.
The gateway is what you connect to. You are handed one hostname and port, a username that encodes your options, and a password. Every decision about which address your request leaves from happens behind that hostname. You are buying a decision made by somebody else's software, which is why two brands quoting the same price per gigabyte can return completely different results on the same job.
The exit is a program running on a device somewhere else. It takes the relay instruction, opens the connection to the target, and carries the answer back. Its quality sets your latency and your failure rate. Nothing on a pricing page describes it.
The session layer maps you to an exit and holds you there for as long as your job needs. A session that survives ten minutes and a session that changes address on every request are different products at the same advertised price. The mechanics are in what a rotating proxy is and sticky versus rotating sessions. Sticky duration is an upper limit, never a promise, because the exit is a stranger's device and it can leave at any moment.
The commercial arrangement is the fourth piece, and researchers found that the architecture is built to hide it. The 2019 academic study of five commercial services identified "hidden backend gateways in the RESIP service infrastructure, which decouple the clients and RESIPs in their infrastructure". The front door you connect to is deliberately separated from the network that carries your traffic. That separation is what makes reselling invisible to the customer.
What it costs, and how to read a price
Prices in this market are quoted in incompatible units on purpose. Traffic is sold by the gigabyte, static addresses by the address and month, scraping APIs by the thousand successful requests. Comparing two numbers in different units is how buyers talk themselves into the wrong product.
We keep a register of published prices, captured from providers' own pages. The table below is the distribution of the 862 plans we captured in August 2026, of which 783 were verified a second time against the live page.
What the market charges, by product type
| Product | Unit | Plans | Cheapest | Typical | Most expensive |
|---|---|---|---|---|---|
| Rotating residential traffic | per GB | 391 | $0.10 | median $2.50 | $12.50 |
| Mobile traffic | per GB | 74 | $0.35 | mean $3.64 | $9.83 |
| ISP (static residential) address | per IP | 67 | $0.17 | mean $2.91 | $14.41 |
| Data centre address | per IP | 60 | $0.02 | mean $1.18 | $5.00 |
| Data centre traffic | per GB | 46 | $0.14 | mean $0.48 | $1.00 |
| Scraping API | per 1,000 requests | 64 | $0.00 | mean $2.52 | $36.75 |
HProxy price register, captured August 2026
The residential quartiles are worth stating in full, because that is the line most buyers are quoted on. They run 1.00 dollar at the lower quartile, 2.50 at the median, 4.00 at the upper quartile and 5.99 at the ninetieth percentile.
Three things to take from that table. The spread inside one product is wider than the gap between products: rotating residential traffic runs from 10 cents to 12.50 dollars per gigabyte, so a quoted price tells you almost nothing on its own. The lower quartile of one dollar per gigabyte describes the market's working floor better than the headline figures on the largest providers' pages. And the ladder from data centre to residential to mobile is a ladder of how hard the address is to block, which is the only thing a buyer is actually paying for.
Why the ladder exists is worth one paragraph. A data centre address is cheap because it is easy to identify and therefore easy to refuse. A residential address costs more because it belongs to a household, so refusing it has a cost for the site. An ISP address sits in between: provider-owned space, hosted in a data centre, which buys stability. A mobile address costs the most because of RFC 6598: a crowd of real subscribers sits behind it, and blocking the crowd is expensive for the target. The full taxonomy is in types of proxies.
The price of a gigabyte fell by a factor of ten
The same 2019 study recorded what this market charged when it was young. Proxies Online, the first residential service the researchers found, "increased their price from $3/GB to $25/GB in 6 months" during 2017. Nine years later our register of 391 published residential plans puts the median at 2.50 dollars and the lower quartile at 1.00 dollar.
What a gigabyte of residential traffic has cost
| When | What was measured | Price per GB | Source |
|---|---|---|---|
| 2017, early | Proxies Online, its own list price | $3 | IEEE Symposium on Security and Privacy, 2019 |
| 2017, six months later | the same provider, same product | $25 | IEEE Symposium on Security and Privacy, 2019 |
| August 2026 | 391 published plans, lower quartile | $1.00 | our price register |
| August 2026 | 391 published plans, median | $2.50 | our price register |
| August 2026 | 391 published plans, highest | $12.50 | our price register |
IEEE S&P 2019 for 2017; HProxy price register for 2026
Three forces did that. Supply was industrialised. Paying consumers a few dollars a month for spare bandwidth, and paying app developers to embed a software kit, turns supply into a manufacturing process rather than a scarce find. The address market matured underneath it, with a mean transfer price of 22 dollars per address in 2025 and one broker's leased pool growing from 0.7 million addresses to 9.2 million since early 2022. And volume buyers arrived who negotiate by the terabyte rather than the gigabyte, which pulls the published rate down for everyone.
The direction of travel has one consequence worth stating plainly. A market whose unit price falls by an order of magnitude while its costs stay real is a market where somebody is cutting a corner. Which corner, and by whom, is the subject of the next two sections.
Where the addresses come from, and who agreed
This is the question the industry answers least often and least clearly. There are six routes into a pool, and they differ enormously in who knew and who was paid.
Six ways an address enters a proxy pool
| Route | Who knows | Who is paid | The record |
|---|---|---|---|
| Data centre space leased | the hosting company and the buyer | the hosting company | ordinary commercial leasing; registry transfer and lease data, APNIC 2026 |
| Provider address range contracted | the network owner and the buyer | the network owner | how ISP products are built; no household is involved |
| Bandwidth-sharing app installed for payment | the user, if they read what they installed | the user, in small amounts | the apps' own marketing; Cisco Talos, 31 August 2021 |
| Software kit inside another application | the app developer; the user often not at all | the app developer | Google Threat Intelligence, 28 January 2026: over 600 Android apps |
| Malware | nobody | nobody | United States indictment of the 911 S5 operator: 19 million addresses |
| Device compromised before purchase | nobody, and a factory reset does not help | nobody | FBI public service announcement, 12 March 2026 |
HProxy, from the primary documents listed at the end of this page
The bottom two rows are not hypothetical. In May 2024 the United States Treasury sanctioned the operators of a residential proxy service called 911 S5. The notice states that it "compromised approximately 19 million IP addresses". It also states that the service "essentially enables cybercriminals to conceal their originating location, effectively defeating fraud detection systems". The indictment is more specific about how the pool was built. The operator "surreptitiously propagated the malware through Virtual Private Network (VPN) programs; torrent distribution models run by WANG; and pay-per-install services that bundled WANG's malware with other program files, including pirated versions of licensed software". Free VPN downloads were a recruitment channel. The same document records 613,841 of those addresses as being in the United States.
Two much larger actions followed in 2026, and both are documented by the company that carried them out. On 28 January 2026 Google's threat intelligence group described its disruption of a network it calls IPIDEA. It counted over 600 Android applications carrying the proxy software kit and 3,075 distinct Windows binaries reaching its control domains. A dozen retail brand names sold access to the same pool. Its sharpest sentence is about who the customers were. In a single seven-day period in January 2026 its analysts observed "over 550 individual threat groups that we track" using addresses it identifies as IPIDEA exit nodes. That list included "groups from China, DPRK, Iran and Russia".
On 2 July 2026 the same group, working with the FBI, acted against NetNut. It estimated the network at "at least 2 million devices, distributed across the world". In a single week of June 2026 it observed 316 distinct threat clusters using those exit nodes. NetNut is not an underground brand. Its parent, Alarum Technologies, is listed on Nasdaq. The day after the seizure it told investors that "if these disruptions continue for an extended period, they are likely to have a material adverse effect on the Company's operations". The same filing said the company was investigating whether its network had been used for unlawful purposes. Four months earlier the same company had reported record revenue driven by AI customers. We covered the sequence in detail in the NetNut takedown and the IPIDEA cluster.
The platforms have a rule for the software-kit route, and it is short. Google Play's Device and Network Abuse policy states that apps providing proxy services to third parties "may only do so in apps where that is the primary, user-facing core purpose of the app". An SDK hidden inside a flashlight app is not a grey area under that rule.
Trend Micro measured what leaves such networks. Its list, published on 7 February 2023, includes SQL injection probing, scans for system password files, crawling of national identity numbers and bulk registration of social accounts. Its warning to the people who install these apps is the honest summary of the trade. “By allowing anonymous persons to use your computer as an exit node, you bear the brunt of the risk if they perform illegal, abusive, or attack related actions.”
The consent question is not unique to proxies. In February 2024 the United States Federal Trade Commission ordered Avast to pay 16.5 million dollars. The Commission found that the company "promised users that its products would protect the privacy of their browsing data but delivered the opposite". Software installed for one purpose, monetised for another, is a pattern regulators now recognise on sight.
What the inside of this industry looked like when researchers measured it
The paid residential business has been measured independently exactly once at scale. In 2019 a team of ten researchers published "Resident Evil: Understanding Residential IP Proxy as a Dark Service" at the IEEE Symposium on Security and Privacy. They found 17 residential proxy services, bought five of them, and sent 62 million requests through them to servers and a DNS server they controlled. That infiltration recorded 6 million exit addresses across more than 230 countries and 52,905 networks. It is dated now, and it remains the only independent look inside the product.
Four findings from it still describe the industry.
The pools were real, and unevenly sized. The study's own count put Luminati, now Bright Data, at 4,033,418 exit addresses across 17,820 networks, Proxies Online at 1,257,418, ProxyRack at 857,178 and Geosurf at 432,975. Address churn means those are upper bounds on the number of devices, not device counts. The researchers say so themselves, which is more than most pool-size marketing does.
The addresses were mostly genuine, and geographically nothing like the marketing. 95.22 percent were assessed as genuinely residential and only 2.20 percent appeared on public blocklists. The top country was India at 32.2 percent of one provider's pool and 27.9 percent of another's, while a third was concentrated in Russia and a fourth in Turkey at 12.7 percent. A product sold on American and European addresses was substantially supplied by emerging markets, because that is where spare bandwidth is cheapest to buy.
No provider's consent story survived contact with the data. The paper identified 237,029 IoT devices and 4,141 hosts running potentially unwanted programs among the exits. It also identified 67 distinct programs acting as exit software, 50 of which antivirus tools flagged as malicious. Its conclusion is one sentence long: "none of the 5 RESIP providers is a completely consent-based anonymity system and even the most prominent companies like Luminati were found to use suspiciously compromised residential hosts."
One brand's traffic came out of another brand's network. The researchers found that their "infiltration traffic from the IAPS proxies was actually relayed by Hola clients controlled by Luminati". They noted that IAPS ran no background check and accepted bitcoin. Their overlap matrix shows one provider pair sharing 66 percent of observed addresses. A customer buying the stricter brand's compliance was sharing a network with a customer who had passed no checks at all.
Hold that 2019 finding next to Google's January 2026 disruption post, which describes a dozen retail brand names selling access to one sourced pool. Seven years apart, two independent parties looked into this market and found the same shape: fewer networks than logos, and a customer who cannot see which one they are on.
The free layer is a different market
Free proxy lists, the open ports and the browser-based web proxy sites, are how most people meet the word proxy. They are not this industry, and it is worth saying why in one paragraph rather than confusing the two.
Nobody is paid to keep a free proxy alive, so nothing about it behaves like a product. We collect every free endpoint published by 113 public sources and retest all of them continuously. On 12 September 2026, of 774,697 endpoints collected since May, 6,437 were alive, which is 0.83 percent, and 97.4 percent of those live ones sit on addresses already flagged for recent abuse. The browser-based layer has collapsed outright: of the 8,948 sites listed on the largest surviving web proxy directory, not one served a working proxy when we opened all of them on 10 September 2026.
That is a market of abandoned infrastructure, and it deserves its own pages rather than a paragraph in this one. The measurements live in we checked all 8,948 proxy sites. The working list, with its own last-check time on every row, is our free proxy list. The single-address test is the proxy checker, and the legal question is answered in are free proxies legal. The free layer explains one thing about the paid one. Keeping an address available, clean and answerable is work, and work has to be paid for.
The other half of the market is detection
For every company selling addresses there is a company selling the ability to recognise them. That side of the market is larger, better funded and more public: application firewalls, bot management, fraud scoring, device fingerprinting and address-reputation databases.
The two sides push each other along in a way that explains most product decisions in this industry. Data centre ranges are easy to enumerate, so data centre proxies became cheap and weak. Address reputation data got good, so clean addresses became the product and our measurement of the free layer became a measurement of dirty ones. Fingerprinting moved up the stack to the TLS handshake, which is why JA3 and JA4 fingerprinting now matter as much as the address, and why an address alone stopped being enough. The full detection stack is in how websites detect proxies.
There is one asymmetry the defending side cannot engineer away, and it is the reason the mobile tier exists. Carrier-grade NAT means a single mobile address can front thousands of real subscribers. Blocking it is cheap for the attacker and expensive for the site, so well-run sites do not block it. The industry's most expensive product is built on a structural fact about address scarcity, not on anything clever in the software.
The dates matter, because this market changed shape twice in the eight months before this page was written.
November 2019
Europe's registry runs out of IPv4
addresses become a transfer and lease market
June 2021
Van Buren narrows the US computer-crime statute
permission, not purpose, decides
April 2022
hiQ v LinkedIn, on remand
public data is not accessed without authorisation
April 2022
India orders five years of subscriber records
VPN, virtual server and cloud providers
January 2024
Meta loses its contract claim against Bright Data
terms do not reach logged-off scraping
February 2024
FTC order against Avast
16.5 million dollars over browsing data sold on
May 2024
911 S5 dismantled and sanctioned
19 million addresses recruited by malware
July 2024
A jury finds Booking.com liable for scraping
5,000 dollars, the statutory minimum
January 2025
That verdict is set aside
the loss threshold was not proved
June 2025
FBI warns on home devices sold as proxies
millions of infected consumer devices
July 2025
Cloudflare prices crawler access
402 Payment Required, with a price
January 2026
IPIDEA disrupted
600 Android apps, 550 threat groups in a week
March 2026
Alarum reports record 2025 revenue
40.7 million dollars, driven by AI customers
July 2026
NetNut domains seized
at least 2 million devices, per Google's estimate
Is any of this legal?
Four different questions hide inside that one, and mixing them is how both marketing and criticism go wrong. This section describes what courts and regulators have actually decided. It is not legal advice, and the answers differ by country.
Is using a proxy lawful? In the United States and the European Union, yes, in itself. Proxies are ordinary infrastructure, standardised by the IETF and deployed by every large company internally. Some states take a different view of anonymity tools. India's 2022 directions show what a regulatory answer looks like in practice. VPN, virtual server and cloud providers must keep validated subscriber records "for a period of 5 years", and system logs for 180 days, inside the country.
Is collecting data that anyone can see lawful? In the United States the answer has held up in court. On 18 April 2022 the Ninth Circuit, ruling again after the Supreme Court sent the case back, concluded in hiQ Labs v. LinkedIn that the computer-crime statute's "without authorization" concept "is inapplicable where, as here, prior authorization is not generally required but a particular person ... is refused access". The omitted words in that sentence are "or bot", which the court added in the same breath. The opinion leans on the Supreme Court's decision in Van Buren v. United States of 3 June 2021, which read the statute as a "gates-up-or-down inquiry": either you can access a system or you cannot. Purpose stopped being the test. Permission became it.
Is breaking a website's terms lawful? A separate question, decided on contract law, and the answer has surprised both sides. On 23 January 2024 the Northern District of California granted summary judgment to Bright Data against Meta, holding that "the Terms do not apply to Bright Data's logged-off scraping of publicly viewable data". The login screen is where the industry's public-data line is now drawn, and it was drawn there by a court rather than by a vendor. The other direction is just as instructive. A Delaware jury found Booking.com liable under the computer-crime statute for scraping Ryanair in July 2024. In January 2025 the trial judge set that verdict aside, because the claimant had not proved the 5,000 dollars of loss the statute requires. Both outcomes are real, and neither is a rule you can build a business on without advice.
Was the pool sourced lawfully? This is the question that produces sanctions, indictments and seizures. It is also the only one of the four where the buyer's exposure depends entirely on a supplier's conduct. The 911 S5 case, the IPIDEA disruption and the NetNut seizure are all answers to this question, not to the other three. It is also the question a buyer can ask directly: where do the addresses come from, what does the consent flow look like, and what happens to a device owner who wants out.
And one question that sits outside all four: personal data. Collecting public information about identifiable people is governed by data-protection law regardless of how you reached the page, and robots.txt does not help you there. RFC 9309, which standardised robots.txt in September 2022, says so plainly: "These rules are not a form of access authorization."
How big is this industry really?
Nobody outside it knows, and most published figures are worthless. The honest position is short.
One company publishes audited accounts. Alarum Technologies reported group revenue of 40.7 million dollars for 2025, up 28 percent year on year. Fourth-quarter revenue was 11.8 million, up 60 percent, with net profit of 1.0 million dollars and adjusted EBITDA of 4.4 million. That is the whole of the verifiable revenue record for this industry. It belongs to one group whose proxy subsidiary had its domains seized four months later, and it covers that group's business rather than the market.
Everything else in circulation is an estimate with an undisclosed method. Market-report vendors publish compound growth rates for a "residential proxy market" without saying whom they surveyed, and those numbers then travel through provider blogs as facts. This page does not repeat them. The one third-party estimate worth naming is an analysis published by the threat intelligence firm Intel 471 in September 2024, which put the addresses available across the major services somewhere between 90 and 350 million. We have not been able to verify either end of that range. A range that wide is a statement about how little is known.
Three things can be counted instead of estimated.
The number of brands: our register holds 1,254, of which 305 are dead and 44 have domains free to register today. The number of addresses independently measured: six million residential proxy addresses in the 2019 peer-reviewed study, which is now dated and was never a full census. And the number of documented disruptions: two networks of millions of devices each, disrupted eight months apart, in January and July 2026.
A fourth number describes the industry's own information quality. We hold a crawled corpus of 23,797 articles from the blogs of 134 proxy companies. The median article is 1,319 words. 9,410 of them, 39.5 percent, contain no link to anywhere outside their own site, and only 4,826, one in five, contain a table. An industry that publishes 23,797 articles and cites almost nothing is an industry whose buyers cannot check anything, which is the reason this page carries its sources at the bottom.
How this market breaks
Five failure modes recur, and all five are visible from the outside if you know what to look for.
Provenance. A pool is only as defensible as its consent story. The NetNut sequence, record revenue in March 2026 and a federal seizure in July, is the clearest demonstration that provenance is a commercial risk and not only an ethical one.
Concentration. Fewer networks exist than brands, so one supplier's failure surfaces simultaneously across many unrelated logos. The mobile tier, where one vendor's panel software sat behind a long list of brands, is the extreme case.
Resale layers. Each layer between you and the network adds margin and removes information. When something breaks three layers down, the brand you bought from often cannot tell you what happened, because it does not know either.
Address burn. Addresses are a consumable. Every aggressive customer degrades the pool for every other customer, which is why a provider's abuse policy is a technical feature. Our free-layer measurement, 97.4 percent of live endpoints already flagged, is what a fully burnt pool looks like.
Brand mortality. Companies here disappear, rebrand after incidents, or quietly become a skin on somebody else's network. We keep a running record in the proxy graveyard, and the ownership map behind the familiar names is in who owns your proxy provider. One familiar brand in this market traded under a different name before it was rebranded, a history we traced in Shifter was Microleaves.
Where this goes next
Four movements are already documented, and none of them is a prediction dressed up as analysis.
Access is starting to be priced openly. On 1 July 2025 Cloudflare launched pay per crawl. A crawler either "present[s] payment intent via request headers for successful access (HTTP response code 200), or receive[s] a 402 Payment Required response with pricing". If buying access at the front door becomes normal, part of the demand for taking it quietly at the back door goes away.
Address separation is becoming a platform feature. Apple's iCloud Private Relay routes traffic through two relays. In Apple's own description, "the second relay, which is operated by a third-party content provider, generates a temporary IP address" before connecting to the site. When the operating system ships address separation to hundreds of millions of consumers, an address means less as an identifier, and the detection side has to move further up the stack.
The address system keeps shifting underneath. IPv6 deployment grows, carrier-grade NAT spreads, and the address price fell again through 2025 on the registry measurement above. Each of those changes the economics of a product line: cheaper addresses mean cheaper data centre supply, more CGNAT means more crowds to hide inside.
Agents are a new demand class. Imperva's 2026 report describes AI agents as systems that "don't just scan websites; they interact with them, retrieve data, execute workflows, and increasingly act on behalf of users". An agent acting for a real person is neither a scraper nor a browser, and neither the detection side nor the proxy side has settled what it should be allowed to do.
What this page cannot tell you
The size of this industry in revenue. One audited number exists and it is quoted above. Everything else would be a guess with a decimal point.
What share of any named provider's pool is genuinely consented. Nobody outside the provider can measure it, and providers publish claims rather than audits. The documented routes and the enforcement record are in this page; the audit is not, because it does not exist publicly.
What a specific provider charges today. Prices here move monthly. The table above is a distribution captured in August 2026, not a live price list, and the market floor in particular moves downward faster than any published comparison keeps up with.
How much of any pool is compromised today. The only independent measurement of the inside of this industry is from 2019, and this page does not pretend that its numbers still hold. Nobody has repeated that work at scale since.
What proportion of proxy traffic is criminal. Law enforcement documents what it prosecutes, and that is not a denominator. Anyone converting takedown counts into a percentage of the market is inventing the percentage.
We will re-check the prices and the enforcement status of the named networks by 1 December 2026, and the rest of the page by 1 March 2027. Our own measurements are re-read from the pool database at every refresh, so the free-layer figures here carry the date they were taken.
One line of self-interest, since you read this far. Our free proxy list shows what the public layer looks like when every entry carries its last check, and our plans are what the paid layer looks like when the pool is ours.
Sources
- RFC 1928, SOCKS Protocol Version 5, IETF, March 1996.
- RFC 6585, Additional HTTP Status Codes (429 Too Many Requests), IETF, April 2012.
- RFC 6598, IANA-Reserved IPv4 Prefix for Shared Address Space, IETF, April 2012.
- RFC 9110, HTTP Semantics, IETF, June 2022.
- RFC 9309, Robots Exclusion Protocol, IETF, September 2022.
- RIPE NCC, "The RIPE NCC has run out of IPv4 addresses", 25 November 2019.
- Geoff Huston, "IP addresses through 2025", APNIC, 20 January 2026.
- European Parliament press service, "Online shopping across the EU to be easier from 3 December", 30 November 2018.
- Indian Computer Emergency Response Team, Directions under section 70B(6) of the Information Technology Act, 28 April 2022.
- United States Department of the Treasury, Office of Foreign Assets Control, sanctions on the operators of the 911 S5 botnet, 28 May 2024.
- Indictment, United States v. YunHe Wang, Eastern District of Texas, published by the Department of Justice, unsealed May 2024.
- hiQ Labs, Inc. v. LinkedIn Corporation, United States Court of Appeals for the Ninth Circuit, No. 17-16783, 18 April 2022.
- Van Buren v. United States, Supreme Court of the United States, No. 19-783, 3 June 2021.
- Meta Platforms, Inc. v. Bright Data Ltd., Northern District of California, No. 23-cv-00077-EMC, order on summary judgment, 23 January 2024.
- Ryanair DAC v. Booking Holdings Inc., District of Delaware: jury verdict July 2024, judgment as a matter of law for the defendant, 22 January 2025 (reported by counsel of record for the successful party).
- United States Federal Trade Commission, order against Avast, 22 February 2024.
- FBI Internet Crime Complaint Center, alert I-060525-PSA on home internet-connected devices used in criminal activity, 5 June 2025.
- FBI Internet Crime Complaint Center, public service announcement on residential proxy networks, 12 March 2026.
- Google Threat Intelligence Group, "Disrupting the largest residential proxy network", 28 January 2026.
- Google Threat Intelligence Group, action against the NetNut residential proxy network, 2 July 2026.
- Google Play developer policy, Device and Network Abuse, read 12 September 2026.
- Alarum Technologies Ltd., fourth quarter and full year 2025 results, filed with the SEC, 19 March 2026.
- Alarum Technologies Ltd., update regarding law enforcement action, filed with the SEC, 3 July 2026.
- Xianghang Mi, Xuan Feng, Xiaojing Liao, Baojun Liu, XiaoFeng Wang, Feng Qian, Zhou Li, Sumayah Alrwais, Limin Sun and Ying Liu, "Resident Evil: Understanding Residential IP Proxy as a Dark Service", Proceedings of the 2019 IEEE Symposium on Security and Privacy, pages 1185 to 1201.
- Cisco Talos, "Attackers abusing proxyware platforms", 31 August 2021.
- Trend Micro Research, "Hijacking your bandwidth: how proxyware apps open you up to risk", 7 February 2023.
- Imperva (Thales), Bad Bot Report 2026, 29 April 2026.
- Cloudflare, "The crawl-to-click gap", 29 August 2025.
- Cloudflare, "Introducing pay per crawl", 1 July 2025.
- Cloudflare Radar, 2025 Year in Review, December 2025.
- Apple, "About iCloud Private Relay", read 12 September 2026.
- Common Crawl Foundation, corpus overview, read 12 September 2026.
- Our own measurements, all dated in the text: the free proxy verifier database (774,697 endpoints, 238,012,473 checks, read 12 September 2026), the price register (862 published plans captured August 2026), the web proxy directory census (8,948 addresses, 10 September 2026), the brand register (1,254 brands, read 12 September 2026), and the provider article corpus (23,797 articles from 134 brands).

