Cloudflare measured something in October 2025 that reframes the mobile proxies vs residential proxies question. Addresses behind carrier-grade NAT get rate-limited three times more often than addresses that are not, even though their average bot rate is lower.
Two things follow. A shared carrier IP is expensive for a site to block outright, and that is the pitch. It is also cheap for the same site to throttle instead, which is the half of the trade that rarely makes the pricing page.
The short version. A residential proxy relays your request through a consumer device on a fixed-line home connection, so the target reads a consumer ISP ASN. A mobile proxy relays it through a SIM-equipped device on a cellular network, so the target reads a carrier ASN that is almost always shared with real subscribers. Either way your browser still runs on your own infrastructure. A real device is the third case: on Archonum the browser runs on the smartphone that owns the IP, so there is no relay in the path at all.
What does a mobile proxy buy you that a residential proxy doesn’t?
It buys you an address that is expensive for the target to ban. A mobile proxy routes your traffic through a device attached to a cellular network, so the exit address comes out of a carrier’s mobile pool, and that pool is shared with paying subscribers who will notice if it goes dark.
Carriers ran out of IPv4 before fixed-line ISPs did and solved it with address translation instead of buying more addresses. RFC 6598, published by Weil and colleagues in April 2012, reserved 100.64.0.0/10 so providers could number the link between a carrier-grade NAT and customer equipment without colliding with private space.
Richter and colleagues measured how common that got in A Multi-perspective Analysis of Carrier-Grade NAT Deployment, ACM Internet Measurement Conference 2016. They found CGN in more than 90% of cellular autonomous systems, and over 92% within every regional registry, against 13.3% of non-cellular ASes overall and 17 to 18% of non-cellular eyeball networks.
The IETF documented the consequence before mobile proxies were a product category. RFC 6269, edited by Ford and colleagues in June 2011, states that blacklisting a shared address “will result in all other subscribers sharing that address” losing the same service, and notes that someone else’s worm can interfere with your access to a site.
A mobile proxy is therefore not selling you a cleaner address. It sells you an address the other side pays a price to switch off.
When is a shared carrier IP a liability instead?
A shared carrier IP becomes a liability the moment the site reaches for something softer than a block. Cloudflare’s October 2025 post by Vasilis Giotsas and Marwan Fayed reports a mean bot rate of 7% on CGNAT addresses against 13.1% on the rest, and medians of 4.8% against 4.7%. By that measure a carrier address is the cleaner one.
It still gets rate-limited three times as often. Sharing that makes a hard block costly makes a rate limit cheap, because a rate limit is what you reach for when you cannot safely say no to an address but can afford to slow it down.
The second liability is that cellular traffic is labelled rather than hidden. MaxMind’s GeoIP2 Connection Type database returns one of Cable/DSL, Cellular, Corporate or Satellite, and its ISP database carries mobile country code and mobile network code fields. Treating mobile traffic as its own category takes a lookup, not a clever detection.
Ask a mobile proxy vendor how many of their customers share an exit address with you at the same time. CGNAT already puts real subscribers on that IP, which is the feature. A resold pool stacks other automation on top of them, which is not, and that ratio decides whether the shared address helps you or marks you.
What does a residential proxy still do better?
A residential proxy looks like the majority. Most consumer traffic to most websites arrives over fixed-line connections, and a residential exit puts you in that population without further explanation.
That matters for workloads where a cellular ASN is the anomaly. A B2B analytics dashboard whose real users sit on office and home broadband does not expect a session arriving over a carrier network, and an unusual connection type is a signal even when it is a legitimate one.
Residential pools are also larger and geographically finer. City-level targeting is normal there and coarse in mobile pools, which are constrained by how carriers assign addresses regionally. Per gigabyte, residential bandwidth is the cheaper of the two on most published price lists, and we compared those rates in datacenter vs residential proxies.
Mobile proxies vs residential proxies vs real devices: how do they compare?
Mobile proxies and residential proxies differ in exit network, blocking cost and geographic granularity. They are identical in the thing that decides most modern blocks, because both leave the browser on your own infrastructure. Real devices differ on that last point, which is the only reason they belong in the same table.
| Dimension | Mobile proxy | Residential proxy | Real device |
|---|---|---|---|
| Exit network | Cellular carrier | Fixed-line consumer ISP | The handset’s own connection |
| Where the browser runs | Your infrastructure | Your infrastructure | On the device that owns the IP |
| Is there a relay | Yes, the phone relays | Yes, the home device relays | No relay |
| Address shared with real subscribers | Usually, via CGNAT | Rarely | The handset’s own address |
| Cost of a hard block to the site | High, hits real subscribers | Low to moderate | High, hits a real subscriber |
| Exposure to rate limiting | Elevated, 3× per Cloudflare 2025 | Baseline | Same as any consumer address |
| Connection type visible to the target | Labelled Cellular | Labelled Cable/DSL | Whatever the handset actually uses |
| Browser fingerprint | Whatever your stack emits | Whatever your stack emits | Genuine handset |
| Geographic granularity | Coarse, carrier-region bound | Fine, often city level | 175+ countries |
| Best at | Targets that block by address and rarely inspect above it | Geographic spread and plain HTTP fetching | Logged-in, fingerprinted, session-bound work |
What does neither option change?
Neither one changes the browser. Both products terminate at the IP layer, and the process rendering your pages is still the one you started in your own cloud.
That gap is measurable. Gómez-Boix, Laperdrix and Baudry found in Hiding in the Crowd, WWW 2018, that only 18.5% of mobile fingerprints were unique, because real handsets form a homogeneous crowd of identical hardware. A carrier address paired with headless Chrome on a Linux VM does not join that crowd. The address says Android phone on a mobile network, the fingerprint says something else, and a detector records the mismatch.
We walked through the fingerprint mechanics in why real devices beat emulators. Buying a better IP does not answer a question asked above the IP.
Where do real devices fit, and why aren’t they a mobile proxy?
Archonum is not a mobile proxy, because there is no relay in the path. Archonum runs Chrome on a network of 250,000+ real consumer smartphones across 175+ countries, one network hop from the target, as a drop-in for existing Playwright and Puppeteer scripts.
A mobile proxy gives you a phone’s address. A real device gives you the phone, so the address and the fingerprint come from the same handset and there is no split to reconcile.
Cost is the honest counterweight. Archonum’s published plans start at $24.99 per month with browser runtime at $0.09 to $0.12 per hour and bandwidth at $4.00 to $5.00 per gigabyte, which sits above per-gigabyte proxy pricing. If the only thing your target inspects is the address, you are paying for a browser you did not need.
So which should you buy?
Buy a mobile proxy when the target enforces at the address, a residential proxy when you need geographic reach on mostly-static pages, and real devices when the target scores the browser itself.
Ad verification, app store and carrier-billing checks, mobile pages served differently to cellular clients, and any target whose main control is an IP ban. CGNAT sharing makes that ban expensive for them to keep, and no other product buys you that leverage. If this describes your workload, mobile wins outright and the rest of this post is academic.
Regional pricing and availability checks, SERP collection, catalog scraping. Fixed-line exits are cheaper per gigabyte, finer-grained by city, and unremarkable to a site whose users are mostly on broadband. Do the supply-chain diligence on the pool before you sign.
Logged-in accounts, checkout and booking flows, anything behind Cloudflare, DataDome, Akamai or Kasada, and agent workloads that carry a session across many steps. That is the band Archonum is built for. When the block came from canvas entropy or a headless check, a carrier address changes nothing about it.
Automated requests passed 53% of all web traffic in 2025, up from 51% the year before, per the 2026 Imperva Bad Bot Report published in April 2026. Detection budgets are going up, so the question worth answering first is which layer your target actually inspects. If it stops at the address, buy the address that is hardest to switch off. If it reads the browser, the address was never the argument, and that is the case Archonum exists to answer by running the browser on a real handset instead of behind one.
