Just a year ago, the choice of proxies boiled down to three questions: type, price, and speed. In 2026, a fourth question was added, and it is more important than the others β where these IP addresses come from. After the FBI, along with Google and Lumen, dismantled the residential network NetNut in 2026, and prior to that β IPIDEA (January 2026), the "origin of the pool" transformed from an abstraction into a real business risk. Buying proxies from a provider whose pool is half composed of infected malware devices means signing up for someone else's attacks and receiving bans where a clean IP would have passed without issues.
At the same time, the market has stratified into clear price tiers, traffic prices have risen for the first time in years, and the number of vendors has exploded. Let's break down step by step how to choose a proxy in this new reality: first, the type for the task, then the market tier, and finally β how to check the provider to avoid paying for a botnet.
What Changed in the Proxy Market in 2026
Three shifts that change the logic of choice:
- Consolidation and big money. Proxies have ceased to be a niche tool and have become infrastructure for AI training. Bright Data reached $300M ARR with a growth of ~50% year over year; Oxylabs attracted its first external investments in 11 years in July 2026. According to Proxyway, at least 56 new companies emerged in the market from 2025 to March 2026 β and about 60% of them sell residential proxies, most often under a white label (reselling someone else's pool).
- Cleaning up criminal networks. In 2026, Google, together with the FBI and Lumen, systematically dismantled malicious residential networks β over 10 Chinese providers (IPidea, LunaProxy, ABCproxy, and others) and the Israeli NetNut were targeted. The market has split into "clean capital" and "botnets in disguise."
- Prices have turned upwards. For several years, residential traffic was getting cheaper, but at the beginning of 2026, prices jumped by 22β33%. Currently, the average price per gigabyte is: ~$4.16 for 5 GB, ~$3.00 for 50 GB, ~$2.28 for 500 GB, and ~$1.94 for 1000 GB (data from Proxyway). The era of "residentials for a dollar" is over.
Step 1. Choose the Type of Proxy for the Task
The type is fundamental: it determines both the price and survivability. Briefly, for what task to choose in 2026:
| Type | What it is | Stealth | Price | For what |
|---|---|---|---|---|
| Datacenter | IP on hosting servers | Low (ASN on blacklists) | Lowest | Non-hostile targets, large volume, SEO monitoring, API |
| Residential (rotation) | Real IPs from home ISPs | High | Medium | Scraping marketplaces, social networks, bypassing geo |
| ISP (static residential) | Hosting IPs, but registered to ISPs | High + static IP | Above average | Accounts, sneaker drops, long sessions |
| Mobile (4G/5G) | IP from operators via CGNAT | Maximum | Highest | Social networks, multi-accounting, most hostile targets |
The logic is simple: the more hostile the target and the more expensive the account, the "more alive" the IP needs to be. Datacenter proxies trigger captchas and ASN bans on aggressive sites but are ideal for budget parsing of loyal resources. Residential proxies are a versatile workhorse. Mobile proxies are "heavy artillery": due to CGNAT, hundreds of live users share one operator's IP, and the platform is reluctant to block it without collateral damage.
If the task is narrow, dig deeper into specialized analyses: we have compared residential vs mobile proxies and IPv4 vs IPv6 in detail β scenarios are outlined point by point. You can choose the product itself on the pages of residential, mobile, and datacenter proxies.
Step 2. Understand Which Market Tier You Are Buying From
In 2026, the market split into three price segments. They differ not so much in "IP quality" (though that too), but in support, compliance, granularity of targeting, and whether the pool is owned or resold.
| Tier | Examples of Providers | Residential Price | What Really Distinguishes |
|---|---|---|---|
| Enterprise | Oxylabs (175M IP), Bright Data, NetNut (85M) | ~$30β$2500/month | Own pool, SLA, lawyers and compliance documents, success rate 99.9%+, fine targeting by city/ASN |
| Mid-market | Decodo (115M), DataImpulse (90M), SOAX, IPRoyal, Rayobyte | ~$4β$800/month | Balance of price and quality, decent support, often a mix of own and partner pools |
| Budget / entry | Webshare (80M), Evomi, ProxyEmpire (30M) | from ~$1.75/GB and self-service tariffs | Cheap and quick to start, but the pool is often resold, support and compliance are minimal |
The size of the pool from marketing is a deceptive metric. "400 million IPs" on a landing page does not mean that you have access to 400 million clean addresses: according to Proxyway measurements, the actual unique IPs available are orders of magnitude fewer β for example, Oxylabs had about 3.24 million unique IPs in a test with 3.6 million requests over three weeks. Look not at the number in the header, but at the success rate for your goal and the overlap of pools between providers.
And here is the key point of 2026: the tier does not guarantee the pool's cleanliness by itself. NetNut was a publicly traded enterprise company β and turned out to be a botnet. Therefore, after choosing the type and tier, a third step is mandatory.
Step 3. Check the Provider as if It Were a Supplier Audit
The scale of pool contamination has ceased to be a theory. Analysts from GreyNoise, together with IPinfo, analyzed 4 billion malicious sessions over three months (report from April 2, 2026): 78% of addresses were invisible to reputation feeds, traffic went through 683 different ISPs, and 89.7% of residential IPs "lived" in malicious operations for less than a month. According to IPinfo, the number of observed proxy IPs over the year grew from 47 to 107 million across 126 providers; Spur records 230+ million unique anonymous IPs every 90 days. According to industry measurements, about 15% of outgoing nodes from residential networks are simultaneously flagged as infected with malware.
The practical conclusion: when purchasing residential traffic, you inherit someone else's IP reputation. Therefore, in 2026, providers are checked like suppliers in procurement β based on documents, not promises. A minimum checklist:
- Source of IP and consent. Ask directly: how do people end up in the network? A legitimate provider sources IPs through explicit opt-in (the user consciously agrees and receives compensation), allows exit at any time, and is ready to show a Data Processing Agreement. "We have a clean global residential pool" without describing the process is a red flag.
- KYC and compliance. Is there client verification before granting access? Does the provider block prohibited scenarios? Are policies, certifications (ISO), links to GDPR/CCPA published? The absence of a KYC policy is not "convenience," but a sign that anyone can use the pool for any purpose.
- Pool testing on your target. Donβt believe marketing success rates. Take a trial and measure on your sites: share of successful requests, retries, timeout frequency, is replacement of non-working IPs available. A good pool is stable under your specific load, not "on average."
- Targeting and management. Geo down to city/ZIP, targeting by ASN/ISP, support for sticky sessions, reasonable API and dashboard. Without this, you are not managing quality, but hoping for luck.
- SLA and support. Documented uptime, live technical support, assistance with migration. In an incident, this makes the difference between "switched in an hour" and "down for a day."
- Price transparency. Clear billing model, no hidden fees, refund for unused traffic. Suspiciously low prices are almost always a signal of resold or dirty pools.
A separate red flag is implausible pool growth: if a vendor suddenly has tens of millions of new IPs, ask where they came from. Against the backdrop of 56 new whitelabel players in a year, there is a high probability that you are buying resold access to someone else's (and possibly that very dismantled) network. How exactly residential proxies are detected and flagged has been discussed in our material on detecting residential proxies and IP intelligence β itβs useful to understand the signs by which you are identified on the other side.
How to Align All This with Your Budget
Letβs consolidate the tiers and prices into one solution:
- Budget is limited, target is loyal (scraping open data, price monitoring). Datacenter or budget residential proxies. Savings are justified β but at least check for opt-in and KYC.
- Work tasks: scraping marketplaces, social networks, bypassing geo. Mid-market residentials β the best balance of price, quality, and compliance for 2026.
- Expensive accounts, multi-accounting, most hostile platforms. Mobile or ISP proxies plus thorough provider verification. Here, the cost of a ban is significantly higher than the cost of traffic.
- Regulatory risks (EU data, personal data). Only enterprise/verified mid with documents on the origin of IPs. Proxies solve the technical aspect but do not provide a legal basis for data collection.
Conclusion
Choosing a proxy in 2026 is not about "where is the cheapest gigabyte," but a sequence of three decisions: type for the task β adequate tier β verified provider. The market has matured: prices have risen, the number of vendors has increased, and the line between legitimate residential services and botnets now runs through documents on the origin of IPs, not the beauty of the landing page. A clean, ethically sourced, and managed pool costs more β but it determines whether your traffic will pass or burn on the very first request.
At ProxyCove, we offer residential, mobile, and datacenter proxies with transparent billing and geo and operator targeting β so that for each of the tasks above, you have the right tool, not a compromise.
```