How to Check if a Proxy IP Is Clean: IP Type, Blocklists, Risk Scores and Leak Tests
A step-by-step checklist for vetting proxy IPs: ISP vs hosting lookups, DNSBL blocklists, risk scores, timezone consistency, WebRTC and DNS leaks, and real-target tests.
Instant verification prompts on login, store applications stuck in review, CAPTCHAs on every other request: often the problem isn't what you're doing, it's the IP you're doing it from. It may be classified as a datacenter address, sit on a blocklist, or carry someone else's abuse history.
This guide is a sequence of checks you can run in order, using free public tools and no code. We don't publish "pass rates" for providers here. Your own results on your own targets are the only numbers that matter.
Before you start
- Test samples, not promises. Most providers have a low-cost way in: Webshare gives every account 10 free proxies, and DataImpulse has a $5 intro plan (both checked on 2026-10-05).
- Check 5 to 10 IPs per batch. One IP tells you nothing about a pool.
- Test in the environment you'll actually use. For accounts, open the test sites inside the anti-detect browser profile. For scraping, test from your script.
- Log everything. IP, time, and each result. It makes comparisons, and support tickets asking for replacements, much easier.
Step 1: Confirm the IP type (ISP or hosting)
This is the check that matters most. Sites decide how much to trust a visitor largely by which network (ASN) the IP belongs to.
Run the IP through a lookup service such as ipinfo.io and look at:
- ASN and organization. A local broadband or mobile carrier, or a cloud provider or data center?
- Type. ipinfo classifies the company as ISP, hosting, business or education.
- Privacy flags. Some lookups also flag VPN, proxy or Tor detection.
| You bought | You want to see | Red flag |
|---|---|---|
| Residential / static ISP | ISP type, local carrier | Hosting or a cloud provider |
| Mobile | A mobile carrier ASN | Fixed broadband or hosting |
| Datacenter | Hosting is expected | None, but don't use it for social accounts |
IP databases disagree with each other, so check at least two and go with the majority. For background on the categories, see Residential vs ISP vs Mobile vs Datacenter Proxies.
Step 2: Check blocklists (DNSBL)
DNS-based blocklists started as anti-spam tools, but plenty of risk systems consult them too.
- MXToolbox Blacklist Check tests an IP against 100+ DNSBLs in one go.
- Spamhaus Reputation Checker shows whether an IP appears on Spamhaus lists.
How to read it: a rotating residential IP hitting one obscure list now and then is normal noise. A hit on a major list like Spamhaus, or many IPs from the same batch listed, means the range has been abused. Replace the IPs or reconsider the provider.
Step 3: Look at fraud and risk scores
Many IP lookup sites show a fraud or risk score alongside proxy, VPN and hosting flags. A few rules:
- Every vendor scores differently. Compare IPs relative to each other; don't treat any single number as a verdict.
- Be strict with static IPs, since you'll live with them for months. For rotating residential, look at the overall share of high-risk IPs.
- A high score plus a blocklist hit is a clear "don't use this for accounts."
Step 4: Check geolocation and timezone consistency
A clean IP can still get flagged if the environment around it doesn't match. Platforms compare:
- The IP's country and city against the market you're operating in
- The browser's timezone and language against the IP's location
- The Geolocation API result against the IP location
Pixelscan flags mismatches such as IP location versus system timezone. Most anti-detect browsers can set timezone and language from the proxy IP automatically; turn that on. More in How to Choose an Anti-Detect Browser.
Step 5: Test for WebRTC and DNS leaks
Even with a proxy configured, your real identity can leak through side channels:
- WebRTC leaks. WebRTC can expose your real public or local IP. Use BrowserLeaks' WebRTC test; the public IP shown should be the proxy's.
- DNS leaks. If name resolution bypasses the proxy, your local DNS resolver (and its location) becomes visible. BrowserLeaks and Pixelscan both include DNS leak tests. With SOCKS5, whether DNS goes through the proxy depends on configuration; see SOCKS5 vs HTTP Proxies.
Step 6: Run a full fingerprint check
Finish with an overall scan on Pixelscan or BrowserLeaks: Canvas, WebGL, fonts, TLS fingerprint and automation/headless detection. This tests the browser environment rather than the IP, but platforms evaluate both together.
Step 7: Test on the real target
Passing every checker doesn't guarantee the target platform will accept you. The last step is always a small real-world trial:
- Accounts: log in with one fresh profile, browse normally, and watch how often you're asked to verify.
- Scraping: send a small batch of requests and record status codes, CAPTCHA frequency and response times.
- When something fails, compare against other IPs from the same provider before blaming the provider as a whole.
The checklist
| # | Check | Tool | Pass condition |
|---|---|---|---|
| 1 | IP type / ASN | ipinfo.io or similar | Matches what you bought |
| 2 | Blocklists | MXToolbox, Spamhaus | No major-list hits |
| 3 | Risk score | IP lookup sites | Low relative to the batch |
| 4 | Location / timezone / language | Pixelscan | No mismatch warnings |
| 5 | WebRTC leak | BrowserLeaks | Only the proxy IP visible |
| 6 | DNS leak | BrowserLeaks, Pixelscan | Resolver isn't your local one |
| 7 | Fingerprint | Pixelscan | No obvious anomalies |
| 8 | Real target | Your workflow | Acceptable verification rate |
When the IPs fail
If a batch fails Steps 1 to 3, ask support for replacements first; many providers will swap non-working or misclassified IPs, but refund terms differ widely (Proxy-Seller, for example, refunds within 72 hours only for non-working proxies). If replacements fail too, move on. For long-lived accounts, dedicated static IPs such as IPFoxy's or Proxy-Seller's ISP proxies are easier to vet once and keep. Compare options in the proxy comparison table.
A note on responsible use
Checking IP quality protects your own accounts and infrastructure. Follow each platform's terms of service and local law, and keep multi-account operations and data collection within what the platform permits. Sourcing matters too: networks built on infected devices tend to be heavily abused, as Google's IPIDEA disruption showed.
Some links are affiliate links. We may earn a commission if you buy through them, at no extra cost to you and without affecting our ratings.




