Skip to content
Proxy Type

Mobile proxies

Addresses belonging to a mobile carrier and shared behind carrier-grade NAT. Why that sharing is the entire mechanism, what control you give up, and the two billing models.

A mobile proxy exits from an address belonging to a mobile network operator, shared at that moment with a crowd of real handsets. It is for mobile-only surfaces and for targets that have refused every cheaper category, and it is where you buy tolerance by giving up control.

Carrier-grade NAT is the entire mechanism

Mobile operators have far fewer public addresses than subscribers, so they place many subscribers behind one public address using carrier-grade NAT. The handset gets no public address at all. It gets one from the space set aside for this purpose, 100.64.0.0/10, allocated in RFC 6598 because operators needed a block they could reuse internally without colliding with customers' private networks. The address the destination logs is the carrier's, on the public side of that translator, and a large, shifting group of real people are using it too.

Everything about the category falls out of that:

Consequence of the shared addressWhat it means for you
Blocking the address blocks real subscribersFiltering systems tolerate carrier ranges more
The operator cannot tell which subscriber caused a problemNeither can the target, so behaviour attaches to the crowd
The crowd's traffic is mixed with yoursYou inherit a reputation you did not create
The address is a translator's, not a device'sIt can change for reasons outside your session

The third row is the counterweight to the marketing. Tolerance is a property of the sharing, not of your traffic, and not something the provider supplies. A target that has decided to be strict with a carrier range applies that as readily as leniency.

What you give up: control

In every other category the address is something you hold; here it is something you observe. RFC 6888 requires a carrier-grade NAT to default to paired address pooling — while a subscriber's mappings exist, its sessions leave from one external address — but it permits other behaviours, and says nothing about how long a mapping lasts or what happens when the device changes cell. Nothing promises you the same address on the next request.

So rotation stops being a parameter you set:

  • Rotation is triggered, not requested. On a dedicated modem the address changes when the port is cycled or the carrier decides — an out-of-band action with a delay, not a per-request flag like a rotating endpoint.
  • Stickiness is not yours to promise. A sticky session here rides on a carrier mapping, so treat an address change as an event to detect, not one to rule out.
  • Location is the cell, not a menu. City-level geo-targeting is constrained by where the hardware sits.
  • The path is radio. Latency and throughput vary with signal and cell load, even inside one session.

Verify the exit address at the start of every session and record it with every result. Code that assumes the address from ten minutes ago still holds fails in a way that reads as an application bug.

How it is billed, and why there are two models

Shared pool, per gigabyteDedicated port or SIM, per month
What you rentAccess to many carrier exitsOne modem and its data plan
Who else is on your addressOther customers and carrier subscribersThe carrier's subscribers only
Who triggers rotationThe provider's gatewayYou, by API or timer — and the carrier
The constraint that bitesThe meter, as on residentialThe plan's fair-use policy behind the SIM
SuitsMany short requests, wide spreadFew, long-lived identities

Both trace back to sourcing. The input is a real SIM on a real consumer data plan, so the provider's cost is either the carrier's metered data — passed on per gigabyte, metering everything bandwidth billing describes — or a fixed line and a modem, passed on as rent. The second looks unmetered and is not: fair-use terms sit behind it, and the operator can throttle a heavy job with no signal from the provider.

Where it is right, and where it is an expensive mistake

Right: endpoints that exist only for handsets; targets whose defences have beaten residential addresses on the same job; work where a shared carrier address is the plausible context.

Wrong, and commonly bought anyway:

  • You were blocked and did not diagnose why. If the refusal came from a TLS fingerprint, a header set or a JavaScript challenge, no address changes it. Work the escalation order before paying for the top of the ladder.
  • Bulk transfer. Metered radio bandwidth is the most expensive way to move bytes.
  • Latency-sensitive work. A radio path is variable by construction.
  • Anything needing a stable long-lived address. That is an ISP proxy, the opposite purchase.

Verifying what you got, and what to ask

# Is the exit really on a carrier network, and does it hold still?
for i in $(seq 1 30); do
  curl -s --max-time 30 -x "http://USER:[email protected]:8000" https://echo.example/ip
  sleep 60
done | tee exits.txt | sort -u

# Who announces each address you saw?
sort -u exits.txt | while read -r ip; do
  whois -h whois.cymru.com " -v $ip" | tail -1
done

Read the holder field, not the invoice: you paid for a mobile network operator, and a hosting company there means you did not get one. See ASN for how that record drives classification. The run over time is the other half of the test, because how often the address really moves is what no product page states accurately.

  • Which carriers, in which cities, and can I select one?
  • How is rotation triggered, how long does it take, and what happens to connections in flight?
  • Is the port dedicated to me, and is the modem shared?
  • What are the fair-use terms on the SIM, and who tells me when I hit them?
  • Is the exit ever a carrier address reached through another proxy? Chained exits behave differently from a modem you rent.
  • What is metered, if anything? Get it in writing before the first invoice.

What we do not publish about this category

No prices, no latency figures, no success rates and no pool sizes. Latency here is a radio measurement that changes with the cell and the hour, so a number from our vantage point would mislead. A success rate would describe which carrier crowd we shared an address with that day. Pool size is barely defined when the addresses belong to an operator, not the provider selling them.

Sample it yourself instead, over hours rather than minutes, against your own targets. Success rate lists what a rate must state to be comparable, and the tools show the address the far end really sees.

In this section

2 pages
Proxy fundamentals

Carrier-grade NAT

Carrier-grade NAT is address translation performed inside an operator's own network, so that many subscribers share a single public address.

2 min read