A cellular network tower with glowing cobalt data arcs radiating down to a dense grid of smartphones, illustrating how a mobile proxy routes traffic through a carrier network

Mobile Proxies vs Residential Proxies: What the Carrier IP Buys You

Cloudflare measured something in October 2025 that reframes the mobile proxies vs residential proxies question. Addresses behind carrier-grade NAT get rate-limited three times more often than addresses that are not, even though their average bot rate is lower.

Two things follow. A shared carrier IP is expensive for a site to block outright, and that is the pitch. It is also cheap for the same site to throttle instead, which is the half of the trade that rarely makes the pricing page.

The short version. A residential proxy relays your request through a consumer device on a fixed-line home connection, so the target reads a consumer ISP ASN. A mobile proxy relays it through a SIM-equipped device on a cellular network, so the target reads a carrier ASN that is almost always shared with real subscribers. Either way your browser still runs on your own infrastructure. A real device is the third case: on Archonum the browser runs on the smartphone that owns the IP, so there is no relay in the path at all.

more rate limiting on CGNAT addresses than on non-CGNAT addresses
Giotsas & Fayed, Cloudflare, October 2025
90%+
of cellular autonomous systems deploy carrier-grade NAT
Richter et al., ACM IMC, 2016
128
subscribers multiplexed onto one public IPv4 address at the limiting end
Richter et al., ACM IMC, 2016

What does a mobile proxy buy you that a residential proxy doesn’t?

It buys you an address that is expensive for the target to ban. A mobile proxy routes your traffic through a device attached to a cellular network, so the exit address comes out of a carrier’s mobile pool, and that pool is shared with paying subscribers who will notice if it goes dark.

Carriers ran out of IPv4 before fixed-line ISPs did and solved it with address translation instead of buying more addresses. RFC 6598, published by Weil and colleagues in April 2012, reserved 100.64.0.0/10 so providers could number the link between a carrier-grade NAT and customer equipment without colliding with private space.

Richter and colleagues measured how common that got in A Multi-perspective Analysis of Carrier-Grade NAT Deployment, ACM Internet Measurement Conference 2016. They found CGN in more than 90% of cellular autonomous systems, and over 92% within every regional registry, against 13.3% of non-cellular ASes overall and 17 to 18% of non-cellular eyeball networks.

Share of autonomous systems deploying carrier-grade NAT More than 17 percent of fixed-line eyeball autonomous systems deploy carrier-grade NAT, against more than 90 percent of cellular autonomous systems. Fixed-line eyeball ASes 17%+ Cellular ASes 90%+ 0 25% 50% 75% 100%
Percentage of autonomous systems found to deploy carrier-grade NAT. Single source: Richter et al., ACM IMC 2016, measured via Netalyzr sessions and BitTorrent DHT crawls. The two populations differ by construction, one being fixed-line eyeball networks and the other cellular networks, and the study reports both figures as lower bounds. Cloudflare’s October 2025 work confirms CGNAT is still widespread in 2025 but does not restate these per-AS shares, so no newer equivalent figure is plotted.

The IETF documented the consequence before mobile proxies were a product category. RFC 6269, edited by Ford and colleagues in June 2011, states that blacklisting a shared address “will result in all other subscribers sharing that address” losing the same service, and notes that someone else’s worm can interfere with your access to a site.

A mobile proxy is therefore not selling you a cleaner address. It sells you an address the other side pays a price to switch off.

When is a shared carrier IP a liability instead?

A shared carrier IP becomes a liability the moment the site reaches for something softer than a block. Cloudflare’s October 2025 post by Vasilis Giotsas and Marwan Fayed reports a mean bot rate of 7% on CGNAT addresses against 13.1% on the rest, and medians of 4.8% against 4.7%. By that measure a carrier address is the cleaner one.

It still gets rate-limited three times as often. Sharing that makes a hard block costly makes a rate limit cheap, because a rate limit is what you reach for when you cannot safely say no to an address but can afford to slow it down.

The second liability is that cellular traffic is labelled rather than hidden. MaxMind’s GeoIP2 Connection Type database returns one of Cable/DSL, Cellular, Corporate or Satellite, and its ISP database carries mobile country code and mobile network code fields. Treating mobile traffic as its own category takes a lookup, not a clever detection.

Procurement note

Ask a mobile proxy vendor how many of their customers share an exit address with you at the same time. CGNAT already puts real subscribers on that IP, which is the feature. A resold pool stacks other automation on top of them, which is not, and that ratio decides whether the shared address helps you or marks you.

What does a residential proxy still do better?

A residential proxy looks like the majority. Most consumer traffic to most websites arrives over fixed-line connections, and a residential exit puts you in that population without further explanation.

That matters for workloads where a cellular ASN is the anomaly. A B2B analytics dashboard whose real users sit on office and home broadband does not expect a session arriving over a carrier network, and an unusual connection type is a signal even when it is a legitimate one.

Residential pools are also larger and geographically finer. City-level targeting is normal there and coarse in mobile pools, which are constrained by how carriers assign addresses regionally. Per gigabyte, residential bandwidth is the cheaper of the two on most published price lists, and we compared those rates in datacenter vs residential proxies.

Mobile proxies vs residential proxies vs real devices: how do they compare?

Mobile proxies and residential proxies differ in exit network, blocking cost and geographic granularity. They are identical in the thing that decides most modern blocks, because both leave the browser on your own infrastructure. Real devices differ on that last point, which is the only reason they belong in the same table.

Mobile proxies, residential proxies and real devices (Archonum), compared on the dimensions that decide the buy. Archonum figures are published rates and network numbers checked August 2026.
Dimension Mobile proxy Residential proxy Real device
Exit network Cellular carrier Fixed-line consumer ISP The handset’s own connection
Where the browser runs Your infrastructure Your infrastructure On the device that owns the IP
Is there a relay Yes, the phone relays Yes, the home device relays No relay
Address shared with real subscribers Usually, via CGNAT Rarely The handset’s own address
Cost of a hard block to the site High, hits real subscribers Low to moderate High, hits a real subscriber
Exposure to rate limiting Elevated, 3× per Cloudflare 2025 Baseline Same as any consumer address
Connection type visible to the target Labelled Cellular Labelled Cable/DSL Whatever the handset actually uses
Browser fingerprint Whatever your stack emits Whatever your stack emits Genuine handset
Geographic granularity Coarse, carrier-region bound Fine, often city level 175+ countries
Best at Targets that block by address and rarely inspect above it Geographic spread and plain HTTP fetching Logged-in, fingerprinted, session-bound work

What does neither option change?

Neither one changes the browser. Both products terminate at the IP layer, and the process rendering your pages is still the one you started in your own cloud.

That gap is measurable. Gómez-Boix, Laperdrix and Baudry found in Hiding in the Crowd, WWW 2018, that only 18.5% of mobile fingerprints were unique, because real handsets form a homogeneous crowd of identical hardware. A carrier address paired with headless Chrome on a Linux VM does not join that crowd. The address says Android phone on a mobile network, the fingerprint says something else, and a detector records the mismatch.

We walked through the fingerprint mechanics in why real devices beat emulators. Buying a better IP does not answer a question asked above the IP.

Where do real devices fit, and why aren’t they a mobile proxy?

Archonum is not a mobile proxy, because there is no relay in the path. Archonum runs Chrome on a network of 250,000+ real consumer smartphones across 175+ countries, one network hop from the target, as a drop-in for existing Playwright and Puppeteer scripts.

A mobile proxy gives you a phone’s address. A real device gives you the phone, so the address and the fingerprint come from the same handset and there is no split to reconcile.

Cost is the honest counterweight. Archonum’s published plans start at $24.99 per month with browser runtime at $0.09 to $0.12 per hour and bandwidth at $4.00 to $5.00 per gigabyte, which sits above per-gigabyte proxy pricing. If the only thing your target inspects is the address, you are paying for a browser you did not need.

So which should you buy?

Buy a mobile proxy when the target enforces at the address, a residential proxy when you need geographic reach on mostly-static pages, and real devices when the target scores the browser itself.

Buy a mobile proxy
The target enforces at the address and blocks hard

Ad verification, app store and carrier-billing checks, mobile pages served differently to cellular clients, and any target whose main control is an IP ban. CGNAT sharing makes that ban expensive for them to keep, and no other product buys you that leverage. If this describes your workload, mobile wins outright and the rest of this post is academic.

Buy a residential proxy
You need geographic reach and the page is mostly HTML

Regional pricing and availability checks, SERP collection, catalog scraping. Fixed-line exits are cheaper per gigabyte, finer-grained by city, and unremarkable to a site whose users are mostly on broadband. Do the supply-chain diligence on the pool before you sign.

Buy real devices
The target scores the browser, and the session has to hold

Logged-in accounts, checkout and booking flows, anything behind Cloudflare, DataDome, Akamai or Kasada, and agent workloads that carry a session across many steps. That is the band Archonum is built for. When the block came from canvas entropy or a headless check, a carrier address changes nothing about it.

Automated requests passed 53% of all web traffic in 2025, up from 51% the year before, per the 2026 Imperva Bad Bot Report published in April 2026. Detection budgets are going up, so the question worth answering first is which layer your target actually inspects. If it stops at the address, buy the address that is hardest to switch off. If it reads the browser, the address was never the argument, and that is the case Archonum exists to answer by running the browser on a real handset instead of behind one.