Choosing a safe proxy provider: a sourcing checklist
How to choose a safe proxy provider after Google's IPIDEA takedown: an eight-point checklist for sourcing, consent, abuse handling, labels, meter and refunds.
A safe proxy provider can tell you where its residential IPs come from, and whether the people behind them agreed and are paid. It has an acceptable use policy and an abuse contact that answers, labels and a meter you can check yourself, and a named company behind it. If a provider cannot answer those, keep your money.
That is not an abstract point about ethics. Something that happened in January 2026 made it a concrete risk.
January 2026: the IPIDEA network is disrupted
On 29 January 2026, BleepingComputer reported that Google's Threat Intelligence Group (GTIG), working with industry partners, had disrupted a residential proxy network called IPIDEA. The action took down domains associated with IPIDEA's services, its management of infected devices, and its proxy traffic routing.
The report describes where those residential IPs came from. IPIDEA enrolled devices through at least 600 trojanised Android apps that embedded proxying SDKs, and more than 3,000 trojanised Windows programs posing as OneDriveSync or Windows Update. It also promoted VPN and proxy apps that, in the report's words, "secretly turned their devices into proxy exit nodes without their knowledge or consent."
The article lists brands Google tied to IPIDEA, including 360 Proxy, 922 Proxy, ABC Proxy, Cherry Proxy, IP 2 World, Luna Proxy, PIA S5 Proxy, PY Proxy and Tab Proxy, alongside several VPN apps. It adds that Google Play Protect now detects and blocks apps containing IPIDEA-related SDKs on up-to-date, certified Android devices.
All of that comes from the report. We make no claims about those brands beyond it.
What this means if you buy proxies
Even if you only use proxies to collect public data or check prices, a badly sourced pool hurts you directly:
- Your traffic runs through strangers' hijacked devices. The owners never agreed. That is a problem on its own, whatever you use the connection for.
- The service can disappear overnight. When domains are seized and infrastructure is pulled, your prepaid balance and the code you built around it stop together.
- The IPs are worse. The report describes attackers using exits from networks like this for account takeovers and credential theft. Share exits with them and those addresses end up on blocklists and fraud flags, and your ordinary requests get blocked too. How to check proxy IP quality shows how to test that yourself.
- The pool shrinks without warning. Once security software starts removing apps that carry the SDK, exits vanish in bulk.
For a buyer, sourcing is where stability and IP quality start.
How to choose a safe proxy provider: the checklist
What is a residential proxy covers the three ways residential IPs are sourced and the red flags of a bad network. Here is that turned into a list you can go through before you pay.
1. Sourcing, stated in one sentence
Ask: where do your residential IPs come from? A good answer is one specific sentence, such as "from people who installed an SDK, are paid for it, and can leave at any time." A vague "premium global resources", or no answer, is also an answer.
2. Consent and payment for the people sharing bandwidth
Ethically sourced residential proxies through an SDK are possible. What matters is how: the person sees a clear consent screen, gets real payment (money, or an app without ads), and can leave in one step. Follow up: which SDK do you use, and what does the user see in the app? Search the SDK's name. If what comes back is malware reports, the conversation is over.
3. An acceptable use policy that is enforced
Some providers verify identity at signup (KYC) and some do not. Either way, there should be a written list of banned uses and a clear statement of what happens to people who break it. A provider that asks nothing and bans nothing shares your exits with everyone.
4. An abuse contact that answers
A published abuse address shows a provider takes responsibility for its network. When site owners report problems and someone acts on it, the pool stays usable.
5. Honest labels you can verify
Residential, ISP or datacenter, and the country, should be things you can look up and confirm. How to check an IP's type walks through it. And when a label turns out wrong, does the provider say in writing what happens next?
6. A meter you can check
If you pay per GB, you should be able to export a request-level usage log and reconcile it with your own numbers. How to check your provider's usage meter covers the method.
7. Refunds in writing
Whatever the terms are, you should be able to read them before paying: when a refund applies, where it goes, and how long it takes. "Contact support and we'll discuss it" usually means no.
8. Who operates it, and where
The terms of service should name the company you are contracting with. A brand with a website and no company name leaves you with nobody to hold to account when something goes wrong.
Red flags
- "Unlimited" residential bandwidth. Paying real people for their bandwidth costs money per gigabyte. If the plan is flat-rate and unlimited, someone else is paying that cost, somewhere you cannot see.
- No sourcing statement. You search the whole site and find no sentence about where the IPs come from.
- A pool suspiciously large and suspiciously cheap. A big pool alone proves nothing; established providers have them. The warning sign is huge, very cheap and unexplained, all at once.
How we answer the checklist
Our answers are on the honesty page. On sourcing and where we draw the line, it says:
Our residential IPs come from people who opted in through an SDK, get paid, and can leave whenever. We do not buy pools from brokers who cannot say where the IPs came from.
The same section says: "Banned outright: credential stuffing, carding and fraud, spam, CSAM, harassment or stalking, and attacks on infrastructure." And: "We act on abuse reports from site owners, and we tell the customer why they were removed."
The rest of the list:
- Identity checks: an email and a password open an account; we do not run KYC. What we have instead is an acceptable use policy we enforce, and a process for reports.
- Abuse reports: the address and what happens to a report are in the acceptable use section of the FAQ.
- Labels and meter: how we label IPs, what we do when one is wrong, and how the meter counts and exports are all on the honesty page, for you to check.
- Refunds: the rules are in the refund policy.
- Operator: the company that runs the site is named on our about page and in the terms.
We also write down our weak spot: our pool is smaller than the big providers', and on heavily defended targets at high concurrency that gap is real. Cheap, clearly sourced and very large pull against each other, and we would rather say so up front.
Quick answers
Is my proxy provider safe? How can I tell? Check whether it can state its IP sourcing in one sentence, has an acceptable use policy and an abuse contact, and lets you verify labels and usage yourself. If it cannot, treat it as unsafe.
Are all SDK-sourced residential IPs a problem? No. If the person knowingly agreed, is paid, and can leave at any time, the source is legitimate. The problem is consent buried in terms, or never asked for.
Are cheap proxies always badly sourced? No. Low prices can come from thin margins and little marketing. But "unlimited residential" is a price structure that paid, willing bandwidth sharers struggle to support.
My current provider is named in the report. What should I do? Stop topping up, export any records you need, and move running jobs elsewhere. Then pick a new provider with the checklist above and start with a small top-up.
Next step
Take this checklist to every provider you are considering, us included. If you want to try us, read the honesty page first, choose a line on the pricing page, add a small top-up, and run the checks in how to test a proxy provider before a big order. Questions go to Discord, and we answer in the open.