Блог

Residential proxies: why your blocklist stopped working

Fraud traffic increasingly comes from real home IPs rented out without the owner knowing. Here is what changed and how to adapt.

For years, the simple version of bot defence worked: block datacenter IPs, because real customers do not browse from Amazon or DigitalOcean servers. That rule still catches a lot. But over the last couple of years a quieter problem has grown underneath it, and teams relying only on datacenter blocks are starting to feel it.

The shift to residential proxies

A residential proxy routes traffic through a real home internet connection, so the IP looks exactly like an ordinary customer's. These networks are huge now, built from millions of devices: people who installed a free app that quietly resells their bandwidth, or devices pulled into a botnet. The attacker rents access and browses your site wearing a real household's address.

Because the IP belongs to a genuine broadband provider, a datacenter blocklist waves it straight through.

Why this is a 2026 problem specifically

Two things pushed this mainstream. First, the proxy services got cheap and easy, sold by the gigabyte with simple dashboards. Second, defenders got good at blocking datacenters, so fraud moved to where the blocking was not. Attack traffic follows the path of least resistance, and right now that path runs through residential IPs.

What still works

No single IP check catches every residential proxy, and anyone promising that is overselling. But the signal has not vanished, it has moved:

  • Behaviour over address. One residential IP making hundreds of requests, or thousands of IPs from one provider all hitting the same endpoint in minutes, is a pattern no real household produces.
  • Known proxy networks. Many residential proxy providers reuse identifiable network infrastructure that can still be flagged.
  • Stacking signals. Residential IP plus a mismatched BIN country plus a disposable email is still a clear risk, even when the IP alone looks clean.

Adjust the expectation

The goal is not a perfect wall; it is raising the cost. Datacenter and VPN blocks remain cheap wins that handle most automated traffic. Residential proxies are the harder tier, and the answer is layered screening, not one magic flag. Fraudex flags datacenter, VPN, Tor and known proxy networks, and pairs it with BIN checks so the layers add up instead of relying on any one of them.