adex-residential-proxy-fraud

Residential Proxy Fraud: Why a “Real” IP Doesn’t Always Mean a Real User

TL;DR

  • A residential proxy routes someone else’s traffic, often a bot’s, through a real person’s home internet connection, so the click or install lands on you wearing a genuine household IP address.
  • That is why IP blocklists keep missing it. The addresses are real, shared between many users, and rotate out of the pool in a matter of days.
  • You can still catch it by reading behavior and timing, and by asking your partners what they actually check beyond the IP.
  • For a buyer: stop treating a clean IP as proof of a real user, demand filtering that catches disguised traffic, and test any source by pausing its spend to see if your conversions actually drop.

Somewhere there is an ordinary apartment. A real family lives in it. A real internet bill goes out every month to a real provider, and the connection behaves exactly as you’d expect: someone streams a show after dinner, someone checks email before work, the router blinks quietly in the hallway. And in the gaps between all of that, without anyone in the apartment noticing, the same connection answers a click on your ad – in a country that family has never set foot in, for a product they have never heard of.

On your report, it shows up as a click from that household, in good standing. In reality, the traffic only passed through their connection on its way to you. That gap is the whole story of residential proxy fraud: the address is genuine, the household is genuine, and the traffic flowing through it frequently belongs to someone else entirely.


What actually gets borrowed

A residential proxy is a way to route someone’s request through a stranger’s home connection. The request leaves through a consumer device on a consumer ISP, so it arrives at your campaign carrying every reassuring detail a real household carries: a residential ASN, a believable city, and the name of an internet provider your filters see thousands of times a day. Nothing about the address itself looks rented.

Where those exit points come from varies, and that is where the picture gets uncomfortable. 

Some are recruited openly – free VPNs, browser extensions, and “earn money for your spare bandwidth” apps that quietly turn a phone or laptop into an exit node. Others are taken without consent, through malware and compromised home routers folded into the same pools. Security researchers have described these networks as a growing problem precisely because the supply looks indistinguishable from regular home users (see Barracuda’s breakdown). For a buyer, the effect is what counts: automation wearing a household as a disguise.


Why your IP filters wave it through

IP reputation works on memory. An address misbehaves, it lands on a list, and future requests from it get scored down. That model assumes addresses sit still long enough to earn a reputation. Residential proxies break the assumption by refusing to stay anywhere.

According to IPinfo’s analysis, the average residential proxy IP is visible for only about 4.56 days, and close to half of them surface across two or more provider networks, so the same address is shared, recycled, and gone before a blocklist can describe it.

The scale is the part that tends to surprise advertisers. In one study of roughly four billion sessions, residential-proxy traffic slipped past IP reputation checks in 78% of cases. A blocklist built yesterday is, in effect, a description of addresses that have already rotated out of the pool. Filtering on the IP alone means filtering on a fact with a short shelf life, and treating a clean geo-lookup as proof of a clean user.

IP reputation can’t keep up

Each home connection is used as a proxy exit for only a few days, then a new one takes over.

~4.56 days average time a residential proxy IP stays visible
Blocklist scan always one step behind
Day 0
Day 1
Day 2
Day 3
Day 4
Day 5
Live exit node (your traffic flows through it)
Rotated out (address recycled, gone)

The tells that don’t live in the IP

If the address can’t be trusted to tell you who sent a request, the answer is to read the things a borrowed connection can’t fake. 

Timing is the most stubborn of them. For app installs, click-to-install time (CTIT) follows a recognizable shape when real people are involved: a sharp peak in the first few minutes, then a long, gentle decay over the following hours as people get around to opening the store and downloading. Fraud bends that curve out of shape – clusters of installs landing one to three seconds after the click, or a flat distribution that real user behavior rarely produces.

Behavior closes the rest of the gap. Real sessions carry the small inconsistencies of a person: scroll cadence, cursor movement, and the time it takes to fill a field. 

Automation routed through a residential exit can borrow the address, but it still struggles to reproduce a plausible on-site journey. Layer in mismatches, the proxy can’t reconcile a device language and timezone that don’t match the claimed location, impossible velocity across regions, and the disguise starts to slip.

This is the category the industry built a name for. The MRC Invalid Traffic guidelines separate the crude, easy-to-catch cases (general invalid traffic) from sophisticated invalid traffic, or SIVT – hijacked devices, masked automation, and exactly the kind of residential-proxy activity that needs multi-point corroboration rather than a single check. 

The framing matters for buyers: any one signal can be spoofed, so the standard expects several to be read together.


Reading it from the buyer’s seat

None of this means a partner is feeding you fraud. Invalid traffic is the thing everyone in the chain spends money to keep out, and a residential proxy click can land on perfectly legitimate inventory before anyone has a chance to catch it. The useful shift is in what you ask for and what you watch.

Start by demoting the IP. 

A location lookup tells you where a request stepped onto the open internet, and that is all it tells you. It can’t see who is actually behind that request, so don’t let it stand in for proof in your reports. Then ask your traffic partners and your tracking tools a blunt question: besides the IP address, what do you actually check? 

If the answer comes back as “mostly blocklists,” that is the gap, and the Media Rating Council’s guidelines are the bar to hold them to, because they expect filtering to catch the disguised traffic, not just the obvious bots. 

On results, watch two things: how long it takes between the click and the install, and what the person does once the app is open. And run the simplest test there is — pause a source’s spend and see whether your conversions actually drop. If the numbers barely move, that source was taking credit for installs you were already getting.

Buyer checklist

Before you trust a “clean” IP

Adex · Residential proxy fraud

A real IP is a fact about plumbing. It tells you where a request entered the network, and that is genuinely useful – right up to the moment you ask it to vouch for the human you can’t see. The advertisers who protect their budgets read the address for what it is and put the weight of the decision on behavior, timing, and outcomes.


FAQ

What is a residential proxy, in plain terms?

It is a service that borrows ordinary people’s home internet connections and rents them out as a way to send traffic. A request from a bot or a scraper gets passed through someone’s phone, laptop, or router, so it reaches your campaign looking like it came from that household. The people whose connections are used are usually unaware, having signed up through a free VPN or a “share your bandwidth for cash” app, or having picked up malware.


Why don’t my IP blocklists catch this?

Blocklists work on reputation built up over time, and these addresses never stick around long enough to earn a bad one. IPinfo found the average residential proxy IP is visible for only about 4.56 days, and nearly half show up across more than one provider. By the time an address is on a list, it has already rotated out, and a different home is doing the work.


If the IP is genuinely real, how can I tell the user isn’t?

By looking at the things a borrowed connection can’t reproduce. A real person’s session has natural timing and small inconsistencies — how they scroll, how long they take on a form, how long after a click an install actually happens. Automation struggles to fake a believable version of that, and details like device language or timezone often don’t match the location the IP claims.


Does this mean my traffic partner is committing fraud?

No. Bad traffic is the thing everyone in the chain spends money to keep out, and a proxy-routed click can slip onto perfectly legitimate inventory before anyone catches it. The useful move is to ask partners what they check beyond the IP and to verify their results yourself, rather than to assume bad intent.


What is the single most useful check I can run?

Pause a source’s budget for a while and watch whether your conversions drop. If the volume barely moves, that source was largely taking credit for installs and actions you were already getting on your own.