← Back to Blog

Proxies for Journalists: How to Protect Sources and Collect Information Anonymously

Journalists working with sensitive topics risk exposing sources through IP addresses. We analyze which proxies and tools effectively protect during information gathering.

📅August 2, 2026
```html

Every time a journalist opens a source's website, visits a forum, or requests a document, they leave a digital footprint. The IP address is recorded in server logs, by providers, and in analytics systems. For a reporter working with sensitive topics—corruption, investigations, whistleblower sources—this poses a direct threat to security. In this guide, we explore how proxies help journalists work anonymously and protect those who trust them.

Why Journalists Need Proxies: Real Risks

Journalism is one of the few professions where anonymity online is not paranoia but a professional necessity. This is especially true for those engaged in investigative journalism, covering the activities of law enforcement agencies, writing about corruption, or working with sources who risk their careers or freedom by passing on information.

Let's consider specific scenarios where unprotected online work creates a direct threat:

  • Visiting websites of organizations you are investigating. If you are studying the activities of a company or agency, your IP may end up in their analytics system. An experienced system administrator will see who is interested in specific pages and to what extent.
  • Corresponding with sources through web interfaces. Even if the content of emails is encrypted, metadata—who, when, from which IP—can reveal the identity of the source or journalist.
  • Working with leaked documents. Downloading files over an unsecured connection leaves a trace that can establish who accessed the materials.
  • Monitoring closed forums and communities. Registering and being active on forums from a real IP is a direct path to de-anonymization.
  • Working from countries with internet censorship. Journalists sent to regions with strict traffic filtering cannot access necessary resources without additional tools.

According to the Committee to Protect Journalists (CPJ), a significant portion of cases of persecution of reporters began with digital footprints—IP addresses, file metadata, connection histories. A proxy server is one of the basic protection tools that masks the real IP and creates an intermediary layer between the journalist and those who may be monitoring.

It is important to understand:

Proxies are one element of protection, not a panacea. For complete security, they need to be combined with other tools: encryption of communications, secure messengers, and proper work habits.

What Exactly Leaks During Regular Internet Use

Before choosing protection tools, it is important to understand what data is recorded during standard browser use. Many journalists underestimate the amount of information they leave online.

Type of Data Who Sees It Risk for the Journalist
IP Address Any website, forum, service Identification, geolocation
DNS Queries Provider, public DNS History of visited sites
HTTP Headers Web servers Browser type, OS, referrer
Cookies and Trackers Ad networks, analytics Session linking between sites
File Metadata Document recipients Name, device, creation time
Provider Logs Internet provider, regulators Complete connection history

Metadata poses a particular danger. A journalist who downloads documents from leaks or receives files from sources must understand: every Word document, PDF, or photo contains data about the creator, editing time, and device. Proxies do not solve this problem—separate tools for cleaning metadata (such as MAT2 or ExifTool) are needed.

Nevertheless, masking the IP through proxies closes one of the main leakage channels—the direct connection between the journalist and the resources they visit during the investigation.

Which Types of Proxies Are Suitable for Journalistic Work

Not all proxies are equally useful for the tasks journalists face. The choice of type depends on the specific scenario: anonymous information gathering, bypassing geo-blocks, or protection when working with sources.

Residential Proxies

Residential proxies use IP addresses of real home users. From the perspective of any website or service, the request comes from an ordinary person, not from a server or anonymizing tool. This makes them the least detectable by detection systems.

For a journalist, this means: visiting the website of the subject of the investigation, registering on a forum, studying public registries—all of this happens on behalf of an "ordinary user," without red flags. Residential proxies also allow for geolocation selection—for example, viewing regional versions of websites or accessing content available only from a specific country.

Mobile Proxies

Mobile proxies operate through IP addresses of mobile operators (4G/5G). This is one of the "cleanest" types of traffic from the perspective of anti-fraud systems, as one mobile IP can hide hundreds of real users (NAT at operators). Blocking such addresses is difficult—it would lead to disconnecting real subscribers.

For journalists, mobile proxies are especially useful when working with social networks—Instagram, TikTok, Telegram channels—where it is necessary to study closed communities or monitor accounts without the risk of being blocked.

Datacenter Proxies

Datacenter proxies are fast and cheap but less anonymous. Their IP addresses are easily identified as belonging to hosting providers. For tasks where speed is critical rather than maximum anonymity—for example, mass collection of public data from open sources—they are quite suitable.

Proxy Type Anonymity Speed Best Scenario for a Journalist
Residential High Medium Studying target sites, working with sources
Mobile Very High Medium Social networks, Telegram, account monitoring
Datacenter Low High Collecting public data, open registries

Specific Scenarios: Information Gathering, Sources, Investigations

Abstract "anonymity" says little about practical application. Let's break down specific situations journalists face and how proxies help in each.

Scenario 1: Studying the Website of the Investigation Subject

Imagine: you are investigating a large company's activities. You regularly visit their corporate website, study pages of specific employees, download public reports. Without a proxy, your IP ends up in their analytics (Google Analytics, Yandex.Metrica, their own systems). If the company is cautious enough, it can track that someone from a specific city and provider is systematically interested in certain sections of the site.

Solution: connect through a residential proxy with an IP from another region or country. Change the IP for each session of study. This breaks the chain of "one researcher—multiple visits."

Scenario 2: Working with Closed Communities and Forums

Journalists often monitor closed Telegram channels, forums, social media groups. Registering with a real IP and device creates a direct link between your identity and the account. Administrators of closed communities often collect the IPs of participants.

Solution: create separate "work" accounts for monitoring, using mobile proxies in combination with a browser with isolated profiles. Each account is a separate browser profile with a separate proxy. Anti-detect browsers like Dolphin Anty or GoLogin allow you to create isolated environments where each profile looks like a separate device.

Scenario 3: Checking Geo-Blocked Content

A journalist working on material about regional politics or foreign events often encounters content available only from certain countries. News websites, government registries, regional databases—all of this may be inaccessible from Russia or, conversely, available only from Russia.

Residential proxies with geo-targeting allow you to select an IP from the desired country or even city. This is especially valuable for fact-checking: you can see how a particular resource appears to the local audience, what ads are shown, what content is available.

Scenario 4: Monitoring Public Registries and Databases

Investigative journalism often requires systematic monitoring: changes in legal entity registries, property data, court decisions, tender databases. Manual checks take hours—automated data collection through proxies allows for real-time tracking of changes.

Here, proxies solve two tasks: anonymity (sites do not see systematic requests from one IP) and bypassing request frequency limits (rate limiting). For such tasks, rotating residential proxies can be used—each request comes from a new IP.

Tools and Setup: Step-by-Step Guide

Let's consider the practical setup of proxies for the most common working scenarios for journalists. No code—just specific steps in the interfaces of the tools.

Option 1: Setting Up Proxy in the Browser (for One-Time Tasks)

Suitable for: one-time visits to websites, checking geo-blocked content.

  1. Obtain proxy data: host (IP or domain), port, username, and password.
  2. In Firefox: open Settings → General → Network Settings → Settings.
  3. Select "Manual proxy configuration."
  4. In the "HTTP Proxy" or "SOCKS Host" field, enter the IP and port.
  5. If the proxy requires authentication, the browser will prompt for the username and password upon the first connection.
  6. Check the connection on the site whatismyip.com—it should display the proxy IP, not your real one.

Tip:

Use a separate browser (or profile) for working through the proxy. Do not mix "work" and "personal" browsers—this will eliminate accidental leaks.

Option 2: Anti-Detect Browser (for Systematic Work with Multiple Accounts)

If you need to maintain several "work" accounts on social networks for monitoring, an anti-detect browser is the optimal solution. Tools like Dolphin Anty, AdsPower, or GoLogin allow you to create isolated browser profiles, each with a unique digital fingerprint and linked to a separate proxy.

Step-by-step setup in Dolphin Anty:

  1. Install Dolphin Anty and create an account.
  2. Click "Create Profile"—give it a name (e.g., "Monitoring Telegram").
  3. In the "Proxy" section, select the type: SOCKS5 (for mobile proxies) or HTTP.
  4. Enter the host, port, username, and password of the proxy.
  5. Click "Check Proxy"—the system will show which IP and country the site sees.
  6. Save the profile and launch the browser—you are working in a fully isolated environment.

The same logic applies in AdsPower and GoLogin: create a profile → link a proxy → launch the browser. Each profile is a separate "device" with a unique fingerprint. Sites cannot link two profiles together.

Option 3: Setting Up Proxy in System Settings

If you need to route all traffic from your computer through a proxy (not just the browser):

  1. Windows: Settings → Network & Internet → Proxy → Use a proxy server. Enter the address and port.
  2. macOS: System Preferences → Network → Advanced → Proxies. Select the type and enter the data.
  3. Ensure that DNS queries also go through the proxy (otherwise, a DNS leak may occur).

⚠️ DNS Leaks:

When setting up a proxy system-wide, DNS queries may continue to go through the provider, revealing which sites you visit. Check for DNS leaks on the site dnsleaktest.com. If a leak is detected—switch to DNS over HTTPS or use a SOCKS5 proxy with DNS support.

Common Mistakes That Expose Journalists

Even when using proxies, mistakes can be made that nullify protection. Here are the most common ones.

Mistake 1: Mixing Personal and Work Accounts

You connected through a proxy but logged into your personal Google account. Now Google knows that you (by account) visited certain sites, despite the proxy. Rule: work "anonymous" sessions—only in profiles without authorization in personal services.

Mistake 2: Using Free Proxies

Free proxies are one of the main sources of risk. Operators of such services may log all traffic, sell data, or intentionally intercept unencrypted connections. For a journalist working with sensitive information, using a free proxy is worse than having none at all—you add another potential observer.

Mistake 3: Forgotten Browser Extensions

Browser extensions have access to your browsing history and can transmit data to their developers. An extension for "conveniently" saving articles or a password manager with cloud synchronization can become a leakage channel. When working through a proxy, use a browser with a minimal set of extensions or none at all.

Mistake 4: Ignoring WebRTC Leaks

WebRTC is a technology built into browsers for video calls. It can reveal your real IP even when a proxy is active. Check for WebRTC leaks on the site browserleaks.com/webrtc. In Firefox, WebRTC can be disabled through settings about:config, setting media.peerconnection.enabled to false.

Mistake 5: Sending Files Without Cleaning Metadata

You anonymously received a document through a proxy but forwarded it to a colleague without cleaning the metadata. The file may contain the author's name, organization name, printer serial number (for PDFs), GPS coordinates (for photos). Proxies do not help with this—use metadata cleaning tools before sending any files.

Mistake 6: Working with the Same IP for Too Long

If you use a static proxy IP for long-term monitoring of one resource, this IP accumulates a "history" of visits. It is better to use rotating proxies or change the IP manually every few sessions.

Digital Security Checklist for Journalists

Use this checklist before each sensitive work session. It covers not only proxies but also related protection tools.

✅ Before Starting Work:

  • Proxy is connected and checked on whatismyip.com
  • DNS leaks checked on dnsleaktest.com
  • WebRTC disabled or checked on browserleaks.com
  • No personal authorizations in the browser (Google, social networks)
  • Browser extensions minimized
  • A separate browser profile or anti-detect browser is used

✅ When Working with Sources:

  • Communication through encrypted channels (Signal, ProtonMail)
  • Do not mention the source in unencrypted messages
  • Agree with the source on using SecureDrop or similar
  • Do not open received files on the main working device without checking

✅ When Working with Documents:

  • Clean metadata before publication or forwarding (MAT2, ExifTool)
  • Do not publish original files—only cleaned copies or screenshots
  • Check if the document contains hidden identifiers (steganography)

✅ After Completing Work:

  • Clear the browser history and cache of the work profile
  • Change the proxy IP if planning the next session
  • Delete temporary files related to the investigation
  • If using an anti-detect browser—close the profile

Additional Digital Security Tools

Proxies are an important but not the only tool in a journalist's arsenal. Here’s what else to use depending on the sensitivity level of the task:

Tool Purpose Level of Protection
Proxies (Residential/Mobile) IP Masking, Bypassing Blocks Basic
Signal Encrypted Communication with Sources High
ProtonMail / Tutanota Encrypted Email High
SecureDrop Anonymous Document Submission from Sources Very High
MAT2 / ExifTool Cleaning File Metadata High
Anti-Detect Browser (Dolphin, GoLogin) Isolated Profiles for Monitoring High
Tails OS Working Without Traces on the Device Maximum

Conclusion

Digital security for journalists is not a one-time action but a system of habits and tools. Proxies close one of the key leakage channels—the IP address—and allow for working with sources, visiting investigation subjects' websites, and monitoring closed communities without the risk of de-anonymization. But only in conjunction with other measures: encrypted communications, metadata cleaning, and proper work habits.

The main takeaways from this guide: use separate browser profiles for work tasks, do not mix personal and work accounts, always check for DNS and WebRTC leaks, and never trust free proxies when working with sensitive information.

If you are engaged in investigative journalism, monitoring sources, or regularly working with geo-blocked content, we recommend starting with residential proxies—they provide a high level of anonymity, appear as traffic from ordinary users, and support geo-targeting by countries and cities. For work in social networks and Telegram—consider mobile proxies: they are virtually impossible to block without disconnecting real subscribers of the operator.

```