Knowledge

How Residential Proxy Providers Ethically Source Their IPs

The addresses are real people's home connections, so the question that matters is whether they agreed. Here is what good sourcing looks like and how to check.

James Meadow

James Meadow

August 30, 2026 · 7 min read

Every residential proxy request travels through a real person’s home internet connection. That is the entire value of the product, and it is also the thing that makes sourcing the most important question a buyer can ask. If the people carrying your traffic never agreed to it, you are relying on a supply chain that is at best questionable and at worst built on compromised devices.

The awkward part is that sourcing is invisible in a specification sheet. Two providers can advertise similar pool sizes and country coverage while sourcing them completely differently, and nothing in the marketing distinguishes them. So here is what legitimate sourcing actually looks like, what the bad versions look like, and how to check which one you are buying.

The legitimate model: participation in exchange for something

The mainstream ethical mechanism is a disclosed exchange. A developer builds an application, and instead of charging for it or filling it with advertising, they offer the user a choice: share a small portion of your unused bandwidth and get the paid features, the ad-free tier, a subscription credit, or a direct payment. The proxy network provides the SDK that makes that sharing possible and compensates the developer, and the user gets something they wanted in return for something they had spare.

Four properties make that arrangement defensible.

Disclosure that a normal person would notice. Not a clause buried on page eleven of terms nobody reads, but a clear statement at the point of installation or activation that the connection will be shared.

A genuine exchange. The participant receives something of real value, which is what makes it a transaction rather than an extraction.

Working opt-out. The ability to stop, easily, without losing access to the device or having to uninstall through obscure steps, and with the sharing actually ceasing when they do.

Ongoing awareness. The participant can tell that it is happening and turn it off later, rather than agreeing once and forgetting forever.

Reasonable networks also add operational limits that protect the participant: not consuming metered mobile data, not running while the device is on battery, capping bandwidth so the household connection is not degraded, and excluding sensitive traffic categories.

What bad sourcing looks like

The failures cluster into three shapes, in ascending order of seriousness.

Buried consent. Technically disclosed, practically hidden. A line in a long agreement, or a pre-ticked box, or wording vague enough that nobody understands what they agreed to. This is the most common failure and the hardest to detect from outside, because the provider can honestly say consent was obtained.

Bundled installers. Software that installs the sharing component alongside something else the user actually wanted, with no meaningful separate choice and often no easy removal. The user has software running they did not ask for.

Compromised devices. Addresses drawn from malware or botnets, where there was never any consent at all. This is the category that turns a procurement question into a legal and reputational one, and it does exist in this market.

There is a practical tell that connects ethics to performance. Pools assembled without genuine consent tend to include devices that behave oddly, get flagged, and accumulate poor reputation, so the same opacity that should worry your legal team also predicts worse success rates. Ethics and quality are correlated here, which is unusually convenient.

Why this is your problem, not just the provider’s

It is tempting to treat sourcing as the vendor’s business. Three reasons it is not.

Supply chain due diligence. If your organisation audits suppliers, a data-collection vendor whose inputs come from unconsenting individuals is exactly the sort of thing an audit is meant to catch, and “we did not ask” is a weak answer.

Regulatory exposure. Consent, transparency and data-handling obligations do not stop at your vendor’s boundary, and the relevant considerations are laid out in residential proxies and GDPR compliance.

Reputational risk. This industry has had public incidents involving proxy networks built on software users did not understand they were running. Being a customer of a provider named in one of those is not a comfortable position, particularly for a company whose own brand depends on trust.

And, again, the practical one: a badly sourced pool performs worse.

How to actually check

You cannot inspect a provider’s supply chain directly, but you can ask questions whose answers are revealing, and how they answer tells you as much as what they say.

Ask where the addresses come from, expecting a specific description of the mechanism rather than an assurance that everything is compliant. A provider running a clean supply chain can describe it.

Ask what the participant receives and whether you can see the consent flow. Some providers publish the participant-facing side, or name the SDK or programme, and that is a strong signal because it is checkable.

Ask how opt-out works and how long it takes to take effect.

Ask what protections exist for participants, such as excluding metered connections or capping usage.

Ask what happens to a device that stops participating, since a network that keeps routing through a withdrawn participant has a serious problem.

Ask about audits, certifications, or independent review, and about the abuse-handling process, since a provider that never removes anyone is not policing its own network.

Then weigh the non-answers. Deflection to “all our IPs are ethically sourced” without describing the mechanism, or an inability to name how participants are recruited, is itself information.

Cheap pools and where the price comes from

A useful heuristic: genuinely consented residential supply has a real cost floor, because participants have to be compensated and developers have to be paid. When a residential offer is dramatically below the market, something is subsidising it, and the candidates are a diluted pool with datacenter space mixed in, exhausted addresses with poor reputation, or a sourcing model that does not involve paying anyone. The first of those is checkable directly, per spotting datacenter IPs sold as residential, and the general argument is in free versus paid proxies.

Your side of the bargain

Ethical sourcing gets you a defensible input. What you do with it is a separate obligation, and it is worth stating plainly: collect public data, respect each site’s terms and robots directives, pace politely so you do not degrade the sites you depend on or the participants’ connections, and handle personal data under the applicable rules. A well-sourced network used carelessly still produces harm, and the participant whose connection carries an aggressive job is the one whose home internet suffers for it. The broader framing is in are residential proxies safe.

The bottom line

The addresses in a residential pool belong to real households, so the only question that matters is whether those households knowingly agreed and can stop. Legitimate sourcing looks like a disclosed exchange with a genuine benefit, a working opt-out, ongoing awareness, and operational limits that protect the participant. The failures range from consent buried in unreadable terms, through bundled installers, to devices compromised outright. You cannot inspect the supply chain, but you can ask specific questions and read the quality of the answers, and you should treat a residential price far below the market as evidence that someone in the chain is not being paid. Conveniently, the ethical answer and the performance answer point the same way, because pools built without consent are also the ones that get flagged.

Those are the questions worth putting to any provider, including this one. The product is residential proxies, with per-GB pricing that reflects what genuinely sourced residential supply costs.

Ready to get started?

Try Shifter's residential proxies, 205M+ IPs, 195+ countries, from $0.75/GB.

Get Started