
Proxy GuidesPokemon Center Proxies: Best Setup for TCG Drops 2026
Pokemon Center Proxies: Best Setup for TCG Drops 2026 Home › Blog › Pokemon Center Proxies 2026 Pokemon Proxies Pokemon Center Proxies: The Best Proxy Setup for TCG Drops in 2026 Bots bought 42,000 Phantasmal Flames items before the public even saw the restock. Here’s what it actually takes to get through Pokemon Center’s virtual queue. August 2026 · 11 min read · Akila Kavinda · Operational Manager TL;DR Pokemon Center’s restocks are one of the hardest retail targets in collectibles right now. In September 2025, a scalper operation reportedly bought around 42,000 Phantasmal Flames items before the public restock even went live. The company has since added a virtual queue and tighter purchase limits, but bots have repeatedly been reported bypassing both. ISP proxies are the stronger choice for the virtual queue itself. Pokemon Center’s own support guidance says to keep the queue tab open without refreshing, which favors a stable, non-rotating IP over one that changes mid-session. Rotating residential proxies matter for multi-account setups. Purchase limits are enforced per account, so scaling past one unit means unique IPs across accounts, not one IP doing all the work. Datacenter proxies are the wrong call on any modern e-commerce checkout running bot protection, Pokemon Center included. The queue does not guarantee a win. Pokemon Center says so directly, and reporting has found bots getting through while queued human shoppers do not. Pokemon Center has not named its specific anti-bot vendor. Treat any claim naming a specific WAF as unconfirmed community speculation, not fact. Not every restock needs this level of setup. If you want one Elite Trainer Box for personal collecting, a normal single-account checkout is fine. Most “Pokemon proxies” content online is a thin list of provider names with no real explanation of what Pokemon Center’s checkout actually does or why bots keep winning restocks that sell out in minutes. This guide goes deeper: what’s actually documented about Pokemon Center’s virtual queue, what happened in the largest reported bot incident to date, which Pokemon Center proxies fit which part of the checkout flow, and where the honest gaps in public information are. One thing up front: Pokemon Center has not publicly confirmed the specific bot-detection technology behind its site. Anywhere this guide can’t point to an official statement or credible reporting, it says so directly instead of presenting a guess as settled fact. Why Pokemon Center Restocks Are So Hard to Win in 2026 The scale of the problem is best illustrated by one incident. In September 2025, a Discord-organized scalper operation reportedly bought roughly 42,000 units of the Phantasmal Flames Elite Trainer Box directly from Pokemon Center’s backend, exploiting products that had been loaded into the system ahead of the public launch date. TheGamer reported that Pokemon Center subsequently canceled the illegitimate orders once the exploit was identified, but the incident happened before a single legitimate customer had a chance to buy. That’s not an isolated event. Earlier in 2025, The Pokemon Company issued an official statement addressing the broader Prismatic Evolutions shortage: “We understand this inconvenience can be disappointing for fans, and we are actively working to print more of the impacted Pokémon TCG products as quickly as possible and at maximum capacity,” per GameRant’s coverage from January 2025. Kotaku has covered the shortage as an ongoing situation through 2025 and into 2026, not a one-time blip. The underlying dynamic is genuine collector demand colliding with constrained print runs, and scalpers concentrating buying pressure into the first seconds a restock goes live. That combination is what makes Pokemon Center meaningfully different from a standard e-commerce restock: it’s not just about being fast, it’s about a checkout flow that’s actively trying to slow bots down while real fans wait in line behind them. 🃏 Pokemon Center Virtual Queue An official waiting-room feature on pokemoncenter.com, documented in Pokemon Center’s own support pages, added to the US site in early 2025 after fans spotted it during a TCG restock. Shoppers are placed in line before reaching checkout, and Pokemon Center’s guidance is not to refresh the queue tab, since it does not guarantee product availability. What’s Actually Confirmed About Pokemon Center’s Defenses It’s worth separating what Pokemon Center has confirmed from what fans have guessed, because most “Pokemon Center proxy” content online blurs the two together. Confirmed: The Virtual Queue Pokemon Center maintains an official support article describing the virtual queue directly. ScreenRant reported in February 2025 that the feature had appeared on the US site during a small TCG restock, and that Japan’s Pokemon Center site “has had this feature for a few years,” where, per that reporting, “the system seems to be working well.” The queue’s stated purpose is to manage traffic and give shoppers “a smooth browsing and shopping experience” during high-demand windows, not to individually verify each visitor as human. Confirmed: Purchase Limits Pokemon Center enforces per-account purchase limits on high-demand SKUs, commonly one unit per customer on the most contested items. This is standard practice across the collectibles and sneaker retail space and is the reason multi-account setups exist in the first place: a single account can only ever buy the limit, no matter how fast or well-configured the connection behind it is. Unconfirmed: The Specific Anti-Bot Vendor This is where a lot of guides overstate what’s known. Several fan troubleshooting sites attribute Pokemon Center’s “Error 15” and “Error 17” access-denied messages to an Imperva/Incapsula web application firewall. That claim shows up repeatedly across community sources, but none of them are primary or trade-press sources, and it has not been confirmed by The Pokemon Company, Pokemon Center, or any credible technical reporting. Treat it as community speculation tied to an error code, not a confirmed fact. Be skeptical of any guide that states a specific vendor name with more confidence than that. A Akila Kavinda — Operational Manager The most common mistake I see in this category is people treating the proxy as the entire solution, then getting confused when a “clean” IP still
Proxy GuidesHow to Tell If a Proxy Provider Is Ethical | TorchProxies
How to Tell If a Proxy Provider Is Ethical | TorchProxies Home / Blog / How to Tell If a Proxy Provider Is Ethical Buyer’s Guide How to Tell If a ProxyProvider Is Ethical Two of the residential proxy industry’s largest networks, IPIDEA and NetNut, were both dismantled in 2026 after researchers tied their IP pools to non-consensual device enrollment. Here’s the checklist that would have flagged both before you ever signed up, plus what actually happened in each case. Amasha Vidumini | August 19, 2026 | 15 min read TL;DR An ethically sourced proxy provider can show you, not just tell you, how its IP pool was acquired: documented consent from device owners or a direct ISP lease, a self-serve way to test before you buy, independent benchmark data instead of only self-reported numbers, and clear ownership of whatever brand you’re actually signing up with. Two of the industry’s largest networks failed that test in 2026. Google disrupted IPIDEA, which turned out to be 13 outwardly separate brands run from shared infrastructure, on January 29, 2026. The FBI and IRS Criminal Investigation seized NetNut’s domains on July 2, 2026, after researchers tied its infrastructure to a botnet called “Popa,” and NetNut had itself absorbed a wave of customers displaced by the IPIDEA takedown months earlier. Both failures trace back to the same root cause: IP pools built from devices enrolled without meaningful disclosure. Check how the IP pool is sourced, not just whether the provider says “ethical.” Ask for documentation of device-owner consent or a direct ISP lease agreement, not just marketing copy. Check who actually owns the brand. Google identified IPIDEA as controlling 13 ostensibly independent proxy brands from shared Hong Kong-registered infrastructure (Google Cloud Blog, Jan 29, 2026). Check for self-serve access and independent benchmarks. A provider that requires a sales call before you can test anything is harder to audit and harder to walk away from quickly. Treat this as an ongoing check, not a one-time decision. NetNut passed enough of a basic trust bar to absorb IPIDEA’s displaced customers, then failed the same underlying test five months later. “Ethically sourced” appears on nearly every residential proxy provider’s homepage. It’s rarely backed by anything a buyer can actually verify. That gap matters more after 2026 than it used to: two networks that used the phrase, or something close to it, in their own marketing were dismantled within six months of each other, both for the same underlying reason. This is a working checklist for telling the difference between a provider that can substantiate its sourcing claims and one that can’t, built directly from what investigators and independent researchers found wrong with IPIDEA and NetNut. The checklist comes first. The two case studies that produced it follow, along with what to do if you had an active subscription with either network. The Checklist: Six Signals of an Ethically Sourced Proxy Provider A provider is worth trusting with your traffic if it can show verifiable consent for how it acquired its IPs, let you test that pool before committing money, and stand behind its numbers with data it didn’t generate itself. Everything below breaks that down into checks you can actually run. What to Check Why It Matters How the IP pool is sourced Ask directly whether IPs come from consenting device owners or partner ISPs, and whether that’s documented anywhere public, not just asserted in marketing copy. Whether the “brand” is actually independent IPIDEA operated as 13 outwardly separate brands from shared infrastructure. A cheap or unfamiliar name isn’t automatically suspect, but check who actually operates it before assuming it’s unrelated to a known bad actor. Self-serve dashboard and API access A provider you can sign up for, test, and cancel yourself, without a mandatory sales call, is easier to audit and exit quickly if something changes. Independent benchmark data Look for third-party testing (Proxyway and similar) rather than relying only on a vendor’s self-reported success rate and latency numbers. Free trial before commitment Test the actual pool against your real target sites before paying for volume, rather than trusting a sales pitch. Billing transparency Clear per-GB or per-IP pricing you can see without a quote request is easier to budget and easier to walk away from. Red Flags That Show Up Before the Takedown Neither IPIDEA nor NetNut collapsed without warning signs a careful buyer could have caught. Enrollment disclosure buried inside an app’s terms rather than a clear opt-in prompt, “ethically sourced” claims with no linked policy or documentation behind them, and a pool size that only ever gets described in cumulative “nodes since [year]” terms rather than a concurrently active figure are all patterns that showed up in the reporting on both networks. Provider Trust Criteria: Illustrative Comparison Provider Trust Criteria Scorecard Sourcing Transparency Self-Serve Access Billing Transparency Independent Benchmarks TorchProxies NetNut (pre-shutdown) Editorial synthesis based on sourced facts below, not a separately measured index Verdict A provider that lets you sign up, test with a free trial, and see published pricing without a sales call is easier to verify and easier to leave quickly if you ever need to. That’s a lower bar than “prove your sourcing is perfect,” but it’s the bar NetNut’s self-serve tiers cleared while its underlying sourcing model apparently did not. TorchProxies Residential & ISP Proxies Ethically Sourced, Self-Serve, No Sales Call Required. TorchProxies runs a self-serve dashboard and full API today, with a free 1GB trial and no credit card required, so you can test against your own target sites before committing to volume. ✓ Free trial, no card required✓ Self-serve dashboard✓ 195+ countries Start Your Free Trial ✓ Instant self-serve signup Why This Checklist Exists: Two 2026 Case Studies The timeline runs faster than most infrastructure stories, and it doesn’t start with NetNut. Google disrupted IPIDEA, a network controlling 13 ostensibly independent proxy brands, on January 29, 2026. NetNut absorbed a meaningful share of the customers displaced by that takedown. Five months later, NetNut was seized
Proxy GuidesHow Many Accounts Per Mobile Proxy? Real Limits by Platform | TorchProxies
How Many Accounts Per Mobile Proxy? Real Limits by Platform | TorchProxies Home / Blog / How Many Accounts Per Mobile Proxy Multi-Account Management How Many Accounts Per Mobile Proxy?Real Limits by Platform Most of the “accounts per proxy” numbers people quote don’t come from the platforms at all. Here’s what’s actually published policy, what’s just a device switcher’s UI ceiling, and what a shared mobile IP changes about the real risk. Amasha Vidumini | August 18, 2026 | 13 min read TL;DR There is no universal “accounts per mobile proxy” number, because most platforms don’t regulate proxy usage directly, they regulate account ownership and behavior. What looks like a proxy limit is usually one of three different things: a device switcher’s UI ceiling (Instagram’s 5-account switcher), an account-ownership policy with no proxy angle at all (Facebook and LinkedIn’s one-real-identity rule), or a number nobody has actually published (TikTok, Discord, X, and Snapchat’s device limits are all secondary-sourced, not official). Meanwhile, the mobile IP itself is already shared by hundreds to thousands of real subscribers before you add a single account to it. Instagram is the only platform with a clearly documented device-switcher number: up to 5 accounts, addable and switchable from the app (Instagram Help Center). Facebook and LinkedIn cap accounts by policy, not by device: one real-identity account per person, full stop, regardless of proxy or device (Meta Terms of Service; LinkedIn User Agreement). TikTok, Discord, X, and Snapchat have no independently verifiable, officially published device-switcher number. The “3,” “5,” and “10” figures circulating online trace back to proxy-vendor and anti-detect-browser blogs, not platform documentation. The “1 account, 1 dedicated proxy” rule practitioners repeat is industry consensus, not platform policy, a reasonable inference from how detection works, but not a number any platform has confirmed. Detection vendors are shifting budget toward account-level fraud detection rather than IP-level blocking, which matters more to your risk than any accounts-per-IP ratio (Kasada, Feb 2026; DataDome, Sep 2025). Search “how many accounts per mobile proxy” and you’ll find a number almost everywhere: 1, 2, 3, sometimes 5. What you won’t find, in almost every case, is a link back to the platform actually saying so. Most of what circulates as an “accounts per proxy” limit is proxy-vendor content repeating itself, not something Instagram, TikTok, or Discord ever published. That distinction matters because it changes what you’re actually managing. If a platform has a real, documented device-switcher ceiling, going past it just breaks the app’s UI. If a platform has no published number at all, the real constraint isn’t a count, it’s behavior, device fingerprinting, and how a shared mobile IP looks to a detection system that’s watching hundreds of other real subscribers on that same address. We covered the mechanics of that shared-IP exposure in detail in why mobile proxy IPs get burned; this guide is the platform-by-platform companion to that piece, sorting what’s actually policy from what’s folklore, and pointing to the deeper platform-specific guides where they exist. The Honest Answer: There Isn’t One Universal Number Every platform in this guide falls into one of three buckets, and conflating them is where most of the confusion about “accounts per proxy” comes from. 📡 Three Different Kinds of “Limit” Policy limit: the platform’s terms of service state a hard cap on accounts per person, independent of device or proxy (Facebook, LinkedIn). UI/switcher limit: the app’s built-in account switcher has a technical ceiling on how many logins it displays at once, which is a software constraint, not a rule against owning more (Instagram’s documented 5). No published limit: the platform regulates behavior, not account count, and any specific number you see online is a third party’s estimate (TikTok, Discord, X, Snapchat). None of the three buckets say anything about proxies specifically. A policy limit applies whether you’re on your home Wi-Fi or a mobile proxy. A UI switcher limit is about the app, not your IP. And where no limit is published, a proxy doesn’t change that absence, it just changes how each account you do run gets scored for risk. Verdict “How many accounts per mobile proxy” is the wrong question for most platforms. The right one is “does this platform cap accounts at all, and if not, what actually gets flagged.” Platform-by-Platform: What’s Actually Published This table separates confirmed platform policy from widely-repeated but unverified secondary claims. Where a number is marked unverified, treat it as informed estimate, not confirmed fact. Platform Stated Limit Type Source and Notes Instagram 5 accounts UI switcher “Add up to 5 Instagram accounts and quickly switch between them” (Instagram Help Center). This is a device-switcher ceiling, not a rule against owning more accounts elsewhere. Facebook 1 account Policy “Only create one account (your own) and use it for personal purposes,” with real-name requirements (Meta Terms of Service, §3.1). Since September 2023, up to 4 additional profiles are allowed under that one account. WhatsApp 2 accounts Device feature Two accounts logged in simultaneously on one phone, each requiring its own phone number and SIM or eSIM (WhatsApp official blog, Jun 1, 2026). LinkedIn 1 account Policy “You will only have one LinkedIn account, which must be in your real name” (LinkedIn User Agreement, §2.1). No device or proxy exception. TikTok ~3 (unverified) UI switcher (claimed) No official TikTok page states an exact switcher number. Community Guidelines target “spam, fake engagement, and coordinated inauthentic behavior,” not account ownership. The commonly cited figure comes from third-party proxy and browser-automation blogs, not TikTok itself. Discord No cap (unverified switcher #) Behavior-based Terms restrict operating multiple accounts to evade enforcement, but ownership itself isn’t capped. The “5 in the switcher” figure circulating online is secondary-sourced, not confirmed against Discord’s own documentation. See our dedicated Discord multi-account guide for the platform-specific playbook. X (Twitter) ~10 owned / ~5 logged in (unverified) Policy (claimed) X’s authenticity policy distinguishes owning multiple accounts (generally allowed) from coordinating engagement between them (a suspension risk). The specific “10” and “5” figures are consistently repeated across
Proxy GuidesMulti-Account Management in 2026 Proxies, Browsers, and Behavior TorchProxies
Multi-Account Management in 2026: Proxies, Browsers, and Behavior | TorchProxies Home / Blog / Multi-Account Management in 2026: Proxies, Browsers, and Behavior Multi-Account Management Multi-Account Managementin 2026: Proxies,Browsers, and Behavior Running more than one account per platform means passing three independent checks, not one. Here’s how the network, browser, and behavioral layers fit together, and where to go deeper on each. Hirusha Sasanka | Junior Developer | August 17, 2026 | 13 min read Key Takeaways Multi-account bans rarely trace back to one mistake. Platforms now score three independent layers, network, device, and behavior, and a strong two layers won’t cover for a weak third. Bots and automated traffic made up 53% of global web traffic in 2026, up from 51% in 2024, and platforms increasingly reuse the same composite-scoring infrastructure to catch linked accounts, not only automation (Thales/Imperva 2026 Bad Bot Report). Proxy architecture still decides the network layer. One dedicated IP per account, permanently, is the rule that holds across platforms; sticky-rotating and datacenter IPs fail it in different ways. Antidetect browsers have gone mainstream for account isolation. AdsPower alone reports serving over 9 million users worldwide as of April 2026 (AdsPower). Behavioral realism is the layer most platforms now weight heaviest, and the one a clean proxy and a stealth browser profile can’t fix on their own. Running a handful of Discord servers, a dozen TikTok accounts, or a client roster of Instagram profiles used to come down to one question: do you have enough proxies. That question still matters, but it stopped being the only one a while ago. Platforms now build a session score out of three layers that operate independently of each other: the network connection, the browser executing the page, and the behavior happening inside it. A session can pass two of the three cleanly and still get flagged on the third. This guide is the starting point for multi-account management in 2026. It covers what each layer actually checks, where operators most often get the architecture wrong, and which of our deeper technical guides to read next depending on which layer is giving you trouble. If you want the full mechanics of the composite scoring model itself, our complete anti-detection stack guide goes further into the code-level detail than fits here. Why Multi-Account Management Got Harder in 2026 Detection used to run almost entirely on IP reputation: one flagged IP meant one banned account, you’d buy a new proxy, and move on. That model broke down as platforms folded multi-account detection into the same bot-defense infrastructure built to fight automated traffic at scale. Bots accounted for 53% of global web traffic in 2026, up from 51% in 2024, while AI-driven bot attacks grew 12.5-fold year over year (Thales/Imperva 2026 Bad Bot Report). Every major bot-management vendor responded by combining network, device, and behavioral signals into one composite score rather than checking any single one in isolation, and multi-account detection piggybacks on that same architecture. The practical effect for anyone running more than one account per platform: your proxy is no longer the whole defense. It’s one input into a score that also weighs your browser’s fingerprint and how you actually behave once you’re logged in. Our companion piece on how platforms build that composite score breaks down each signal layer in detail; the summary here is the version you need to plan a multi-account setup, not build a bot. 2026 Global Web Traffic: Bot vs. Human Bots accounted for 53% of global web traffic in 2026, up from 51% in 2024, while human traffic fell to 47%. Source: Thales/Imperva 2026 Bad Bot Report. 2026 Global Web Traffic Composition Bot traffic 53% Human traffic 47% Up from 51% bot traffic in 2024, alongside a 12.5x year-over-year increase in AI-driven bot attacks. Source: Thales/Imperva 2026 Bad Bot Report Source: Thales/Imperva 2026 Bad Bot Report. Layer One, the Proxy: Getting Your Network Identity Right The network layer is still the foundation, and it still fails predictably. The rule that holds across LinkedIn, Instagram, TikTok, Telegram, and most other platforms is one dedicated IP per account, permanently, not shared and not rotating. Sticky residential sessions fail that rule because the IP eventually expires and reassigns, creating IP inconsistency the platform reads as suspicious. Datacenter proxies fail it differently: hosting-provider ASNs are an easy signal to flag regardless of how the session behaves otherwise. Our full breakdown of that one rule walks through the platform-by-platform mechanics; this section is the short version. 🔐 One-IP-Per-Account Rule Each account gets its own dedicated IP address, assigned once and never changed, rather than sharing an IP with other accounts or rotating through a shared pool. Static ISP proxies satisfy this natively; rotating residential and datacenter proxies generally don’t. Which proxy type fits depends on whether the account is meant to last. For accounts you’re building a real history on, ISP static proxies are the natural fit: a fixed IP registered to a consumer ISP, starting at $2.30 per IP per month at volume, with unlimited data and no rotation by design. For tasks that need volume across many accounts in a fixed window, like batch signups or sneaker drops, a hybrid rotating pool such as Plan X blends residential, ISP, and mobile sources to reduce subnet-level flagging when one range gets identified. Neither replaces the other; they cover different stages of an account’s life. Our hybrid proxies decision guide goes deeper into exactly when the hybrid pool earns its cost over a straight ISP setup. Real Signal From Our Support Queue Buyers setting up multi-account operations consistently ask to verify fraud scores on scamalytics.com and ip2location.com before committing to an IP block, and a meaningful share of ISP Proxies orders pair the product with Standard Residential in the same request, one for account persistence, one for general scraping or research tasks. The two products are doing different jobs even inside a single operator’s stack. Layer Two, the Browser: Fingerprints, Profiles, and Isolation A clean IP doesn’t help if every
Proxy GuidesBehavioral Bot Detection: How Platforms Score Your Sessions | TorchProxies
Behavioral Bot Detection: How Platforms Score Your Sessions | TorchProxies Home / Blog / Behavioral Bot Detection: How Platforms Score Your Sessions Bot Detection & Fingerprinting Behavioral Bot Detection:How Platforms ScoreYour Sessions Cloudflare, Akamai, and DataDome don’t run one bot check, they run a composite score. This is how the network, device, and behavioral layers underneath that score actually work, with the real numbers behind each one. Hirusha Sasanka | Junior Developer | August 13, 2026 | 16 min read Key Takeaways A platform doesn’t run one bot check, it runs a composite score. Cloudflare’s Bot Score (1-99) and Akamai’s Bot Manager score (0-100) both combine network/protocol, device, and behavioral signals into one number before deciding whether to allow, challenge, or block a session. TLS/JA4 fingerprinting alone is already strong. A 2026 study trained classifiers on 227,404 JA4 fingerprints and hit 98.63% accuracy, but its own authors flag the ceiling: it can’t catch tools that fully emulate a real browser’s TLS stack. That ceiling is why the behavioral layer exists. DataDome’s own documentation describes collecting 35+ behavioral signals per session, mouse trajectory, scroll velocity, keystroke timing, scored against known human and bot baselines in real time. Bots made up 53% of global web traffic in 2026, and AI-driven bot attacks grew 12.5x year over year (Thales/Imperva 2026 Bad Bot Report). As static signals get cheaper to fake, behavioral scoring carries more of the classification weight. A clean IP does not offset a bad behavioral score. The composite model weighs session realism, not just network reputation, which is why two requests from the same IP can score differently. Half the requests hitting a website in 2026 aren’t from a person. Bots accounted for 53% of global web traffic this year, up from 51% in 2024, while AI-driven bot attacks grew 12.5-fold year over year, with the daily average of blocked AI-related incidents climbing from roughly 2 million to 25 million (Thales/Imperva 2026 Bad Bot Report). Every major bot-management platform, Cloudflare, Akamai, DataDome, HUMAN Security, responded to that shift the same way: not with a single yes/no check, but with a composite risk score assembled from multiple independent layers of evidence. This piece is about how that score actually gets built, at the signal level. It’s written for developers evaluating or building automation, not for someone deciding which proxy to buy, so if you’re specifically working through “my IP is clean, why am I still blocked,” our companion piece on why a clean IP still gets flagged by Cloudflare, DataDome, and Akamai covers that angle directly. Here, the question is different: what specific signals go into the score, how are they weighted, and why did the industry converge on behavioral biometrics as a load-bearing layer instead of a nice-to-have. 2026 Global Web Traffic: Bot vs. Human Bots accounted for 53% of global web traffic in 2026, up from 51% in 2024, while human traffic fell to 47%. Source: Thales/Imperva 2026 Bad Bot Report. 2026 Global Web Traffic 53% bot traffic Bot traffic: 53% Human traffic: 47% Source: Thales/Imperva 2026 Bad Bot Report Bots overtook nearly half of all measured web traffic in 2026. Source: Thales/Imperva 2026 Bad Bot Report. What “Behavioral Bot Detection” Actually Means 🔐 Behavioral Bot Detection The practice of classifying a session as human or automated by analyzing how a visitor interacts with a page over time, mouse movement, scroll physics, keystroke timing, click cadence, rather than only what the visitor’s request looks like at a single point in time (IP, headers, TLS handshake). That distinction matters because it separates behavioral detection from the two layers it usually sits on top of. Network and protocol signals (IP reputation, TLS/JA4 fingerprint) describe the connection. Device signals (headless-browser tells, canvas/WebGL rendering, execution timing) describe the client software. Behavioral signals describe the person, or the absence of one, driving that client across an entire session, not just a single request. A request can pass every network and device check and still fail behaviorally if the mouse path is too straight, the keystrokes are too evenly timed, or there’s no scroll jitter at all. The Three Layers a Composite Score Actually Combines No major platform scores behavior in isolation. Cloudflare’s machine learning engine ingests request headers, session characteristics, and browser signals together to produce its 1-99 Bot Score; Akamai explicitly combines multiple detection layers into one score rather than relying on any single one (Cloudflare Bot solutions docs; Akamai Bot Manager documentation). The practical architecture looks like this: How a Composite Bot Score Gets Built How a Composite Bot Score Gets Built Network and protocol signals (IP reputation, JA4 TLS fingerprint, HTTP/2 fingerprint), device and browser signals (headless detection, canvas and WebGL, execution timing), and behavioral signals (mouse dynamics, keystroke cadence, scroll physics) each feed into a single composite score, which a platform then maps to an allow, challenge, or block action. Editorial synthesis based on Cloudflare, Akamai, and DataDome public documentation. Network / Protocol IP reputation, JA4, HTTP/2 Device / Browser Headless tells, canvas, timing Behavioral Mouse, keystroke, scroll Composite Score e.g. 1-99 / 0-100 Allow / Challenge / Block Editorial synthesis based on Cloudflare, Akamai, and DataDome public documentation. Each layer catches what the layer before it misses. That’s the actual reason behavioral detection exists as a distinct discipline, not just a marketing category: network and device signals are the easiest to fake with enough engineering effort, and behavioral signals are, so far, the hardest. Layer One: Network and Protocol Fingerprinting (JA3 to JA4) TLS fingerprinting was the first widely deployed layer, and it’s still doing real work. The idea is simple: when a client opens a TLS connection, it sends a Client Hello packet listing its cipher suites, extensions, and supported versions, in a specific order. Different TLS libraries and browser builds produce different orderings, so the fingerprint of that handshake can identify the client software independent of whatever User-Agent header it sends. JA3, the original version of this fingerprint, broke in 2023: Chrome 110 shipped ClientHello extension order
Proxy GuidesHow Mobile Proxy IP Rotation Actually Works on Carrier Networks | TorchProxies
How Mobile Proxy IP Rotation Actually Works on Carrier Networks | TorchProxies Home / Blog / How Mobile Proxy IP Rotation Works on Carrier Networks Proxy Fundamentals How Mobile Proxy IPRotation Actually Workson Carrier Networks “Rotate” looks like a button. Underneath it is a real network procedure: a carrier tearing down and rebuilding a session, a gateway deciding when to release an address, and a shared IP pool that was never exclusively yours. Here’s how mobile IP rotation actually works, layer by layer. Amasha Vidumini | August 12, 2026 | 14 min read Key Takeaways Mobile IP rotation isn’t proxy-provider magic; it rides on real carrier engineering. A new IP usually means a device went through a fresh PDP context (4G) or PDU session (5G) setup, per 3GPP standards TS 23.401 and TS 23.502. Quick reconnects often don’t change your IP. Carrier gateways use address hold timers, documented as short as 120 seconds in Cisco’s P-GW configuration guides, so a subscriber who reconnects fast gets the same address back. CGNAT is why a carrier IP was never really “yours” alone. Per IETF RFC 6888, carriers share one public IPv4 address across many subscribers; NFWare’s deployment guidance caps this around 128 subscribers per IP, while Cloudflare has observed real-world sharing reach into the hundreds or thousands. “Rotate” buttons trigger provider-side session routing, not carrier commands. SOAX, Oxylabs, and IPRoyal documentation all describe rotation as choosing among IPs already available in a managed pool, layered on top of the carrier’s own churn. Proxyway’s 2026 market research puts advertised mobile proxy pool sizes anywhere from 5 million to 33 million IPs across major providers, with a median around 16 million, and notes that only 9 to 10 of the 13 providers it benchmarks even offer a mobile product at all; Bright Data discontinued its mobile proxy line entirely in April 2026 (Proxyway, “Proxy Market Research 2026”, published Mar-Apr 2026). Mobile proxies are a shrinking-provider, premium niche, even as the underlying thing that makes them valuable, a constantly churning pool of carrier-assigned IPs, hasn’t changed at all. That’s the gap this guide fills. Most explainers describe mobile IP rotation from the buyer’s side: click a button, set a session duration, get a new IP. Almost none explain what’s actually happening underneath that button, on the carrier’s own network. This piece walks through the real mechanism: how a phone gets an IP address in the first place, why that address changes when it does, why it sometimes doesn’t change even when you ask it to, and where a proxy provider’s “rotate” command actually sits in that chain. If you already know the difference between a rotating, sticky, and dedicated mobile session and just need to pick one, our comparison of rotating, sticky, and dedicated mobile proxies covers that buyer’s-guide ground; this piece is about the network layer underneath it. Advertised Mobile Proxy IP Pool Sizes (2026) Advertised Mobile Proxy IP Pool Sizes by Provider (2026) Proxyway’s 2026 market research found advertised mobile proxy IP pool sizes ranging from 5 million to 33 million across major providers, with SOAX leading at 33 million and a median around 16 million. Only 9 to 10 of the 13 benchmarked providers offer mobile proxies at all. Source: Proxyway, Proxy Market Research 2026. Millions of IPs, by provider SOAX 33M Market median ~16M Market low end 5M Providers offering mobile 9-10 of 13 benchmarked Source: Proxyway, “Proxy Market Research 2026.” What “Rotation” Actually Means at the Network Layer 🔄 Mobile Proxy IP Rotation The process by which a mobile device’s public-facing IP address changes, either because the underlying carrier network assigns it a new address as part of normal network operation, or because a proxy provider’s routing layer switches which device or session in its managed pool is currently handling your traffic. Those are two different events happening at two different layers, and conflating them is where most confusion starts. The carrier-side event is a real network procedure: a device disconnects from and reattaches to the mobile core, and as part of that reattachment, the network allocates it an address. The provider-side event is a routing decision made entirely inside the proxy provider’s own infrastructure: pick a different already-connected device or session ID to route your next request through. A “rotate” button can trigger either, or both, but they are not the same mechanism, and understanding the difference explains a lot of behavior that otherwise looks arbitrary, like why a rotation request sometimes hands you back an IP you just had. The Carrier Side: How a Phone Gets (and Loses) Its IP On 4G/LTE networks, a device’s IP address is tied to its PDN connection, formally an EPS bearer established during the network Attach procedure. When a device attaches, the Mobility Management Entity selects a Packet Data Network Gateway, and that P-GW allocates the PDN address, either statically from data the carrier already holds about the subscriber, or dynamically from an address pool, then delivers it to the device inside the Attach Accept message (3GPP TS 23.401, the governing 3GPP standard for LTE/EPS network procedures). A fresh Attach, triggered by something like toggling airplane mode, a full radio deregistration, or an explicit PDN connection release, restarts this allocation cycle and can hand the device a different address than it had before. 5G networks use the equivalent PDU Session instead of a PDP context, but the mechanism is structurally the same: the device sends a PDU Session Establishment Request through the base station and Access and Mobility Management Function to the Session Management Function, which selects a User Plane Function and allocates the session’s IP address or prefix, sometimes at establishment and sometimes deferred to a follow-up DHCPv4 exchange once the session is already up (3GPP TS 23.502, the 3GPP standard for 5G system procedures, ETSI mirror V18.5.0). The important distinction for rotation purposes: a handover, where an active session moves from one cell tower to another, is specifically designed to preserve the existing session and its address, while establishing
