The Facebook Ads or Instagram account is still alive, but captchas are popping up at every turn, and ad conversions have halved for no apparent reason. This is a classic picture of a “burned” residential IP — a proxy that the platform has already blacklisted, but the account has not yet been blocked. If no action is taken within 24-48 hours, a ban or shadowban will follow. In this article, we present 5 specific signals of IP degradation and a step-by-step action plan that will save the account before disaster strikes.
What Does "Burned IP" Mean and Why Does It Happen
A “burned” residential IP is an address that has already accumulated a negative reputation in the platform's anti-fraud systems: Facebook, Instagram, TikTok, Google Ads, or a marketplace. The reputation of an IP is formed not only by your actions — if the proxy provider uses this IP for hundreds of other clients, and one of them gets banned, the entire pool of addresses, including yours, comes under suspicion.
For arbitrageurs, this usually manifests as follows: a Facebook Ads account worked steadily for 2-3 weeks, and then suddenly started receiving Checkpoint after Checkpoint without any change in behavior. For SMM specialists, Instagram starts requiring SMS confirmation at every login, whereas previously the session lasted for weeks. For sellers, Wildberries or Ozon start showing captchas instead of competitor price data.
The reason is almost always the same: the IP has “lit up” due to suspicious activity — either yours (too fast actions, atypical patterns) or someone else's (if the IP is shared, not dedicated). The static binding of “one IP — one account” without rotation accelerates this process: the platform manages to collect enough signals to blacklist the address.
Signal 1: Sudden Increase in Captchas and Security Checks
The first and most obvious sign is an increase in captchas during login, posting, or launching ads. If a captcha appeared once a week before, but now pops up with every second action — this is a direct signal that the platform's anti-fraud system has raised the suspicion level for your IP address.
In anti-detect browsers like Dolphin Anty, AdsPower, or Multilogin, this can be easily tracked through profile logs: open the activity history of a specific profile and see when security checks started appearing. If this coincides with a specific proxy in rotation — the likelihood that the problem lies with the IP exceeds 80%.
For TikTok Ads and Google Ads, the pattern is similar: the system starts requesting confirmation via email or phone more frequently than usual, even for actions that previously went through without questions — for example, when editing an already launched ad campaign.
Signal 2: Decline in Ad Reach and Impressions
For arbitrageurs, this is the most painful signal because it directly impacts ROI. If CPM has increased 2-3 times with the same audience settings, and reach has dropped by 40-60% without changes in creatives — the platform has started limiting ad impressions from the account associated with a “suspicious” IP.
Facebook Ads and TikTok Ads use what is called shadow throttling — hidden limitations on impressions without official notification. The account is formally active, the ad is running, but the algorithm deliberately cuts distribution. This is an intermediate stage before a complete account ban, and you have a window of a few days to react.
A verification test: launch an identical campaign with the same creative on a fresh account through another IP. If reach and CPM on the new account are significantly better — the problem is definitely in the combination of the old account + burned IP, not in the ad itself.
Signal 3: Requests for Phone or Document Verification
When the platform is unsure of the legitimacy of the account but is not yet ready to block it, it requests additional verification — phone number, passport details, or a selfie video. This is a typical pattern for Instagram, Facebook, and TikTok when operating through an IP with a suspicious reputation.
For SMM specialists managing 20-30 client accounts, it is important to track this en masse: if 3-4 accounts from different profiles in Dolphin Anty received a verification request simultaneously in one day — this is not a coincidence, but a systemic signal of a problem with a specific pool of IP addresses used for all these profiles.
An important nuance: passing verification does not solve the problem with the IP. You may confirm the phone number, but the account will continue to receive increased attention from the anti-fraud system while using the same burned address.
Signal 4: Connection Speed and Stability Have Dropped
A less obvious but important technical signal is the degradation of the connection itself. If the proxy has started disconnecting more frequently, page loading speed has dropped, and API requests to the platform are taking 2-3 times longer — this may indicate that the proxy provider is overloading the specific IP with too many simultaneous connections, or the address is already being throttled by the target server.
Checking this is simple: measure the response time (ping) and speed through the built-in test in the anti-detect browser or through a third-party proxy checking service. Compare with the metrics of the same IP from a week ago. A speed drop of more than 30% under the same load is a strong argument in favor of replacing the address.
For parsing Wildberries, Ozon, and Avito, this is especially critical: a degraded IP starts returning timeouts or incomplete data instead of clean information about prices and stock levels, distorting competitor monitoring results.
Signal 5: Blacklist by IP Reputation (blacklist check)
The most direct way to confirm the diagnosis is to check the IP through reputation services: IPQualityScore, Scamalytics, or similar tools that show the fraud score of the address. If the risk score is above 75-85 out of 100 — the IP is already under increased scrutiny by most major platforms.
Such services also show whether the IP has been flagged in known spam activity lists, VPN detectors, or as part of a data center (even if the provider sells it as “residential”). If the check shows that the address is identified as a datacenter or hosting instead of residential — this is a direct sign that the proxy provider is using not genuine home IPs, but a fake that burns out much faster.
| Signal | What to Check | Criticality |
|---|---|---|
| Increase in Captchas | Profile logs in the anti-detect browser | High |
| Decline in Reach | CPM and Reach in Ads Manager | Critical |
| Verification Requests | Frequency across all profiles in one day | High |
| Connection Speed | Ping and latency test | Medium |
| Blacklist Status | IPQualityScore / Scamalytics | Critical |
How to Quickly Diagnose a Proxy Before Replacement
Before changing the IP, it is important to ensure that the problem is indeed with the proxy and not with the account behavior or anti-detect browser settings. Here is a diagnostic checklist that takes 10-15 minutes:
- Check the fraud score of the IP through IPQualityScore — a value above 75 requires replacement.
- Compare account behavior on different IPs — if the problem only occurs with a specific address, the issue lies with the proxy.
- Check the type of IP — ensure that it is indeed residential and not a datacenter disguised as residential.
- Evaluate the history of IP usage — ask the provider how many clients have used this address simultaneously (shared vs dedicated).
- Check the geolocation — a mismatch between the declared city/country and the real one can itself trigger anti-fraud.
If at least 2 out of 5 points show a problem — do not waste time trying to “heal” the current IP. Proceed to replacement.
Step-by-Step Action Plan: What to Do Right Now
If you have identified 2 or more signals from the list above, follow this algorithm to preserve the account:
- Stop active actions on the account — do not post, change ad settings, or log in again for 2-3 hours. Let the anti-fraud system “calm down”.
- Change the IP to a new residential address with a clean reputation — ideally from the same region as the previous one, to avoid raising additional suspicions with a change in geolocation.
- Check cookie and fingerprint binding in the anti-detect browser — after changing the IP, it is important that other profile parameters (User-Agent, timezone, language) match the new address.
- Gradually resume activity — start with light actions (scrolling the feed, likes), rather than mass posting or launching a new campaign.
- Monitor for the next 48 hours — if captchas and checks do not resume, the IP has passed the test successfully.
For arbitrageurs working with Facebook Ads and TikTok Ads, it is critical to use not just “any new IP”, but an address with a verified history of cleanliness. This is why most professional teams switch to residential proxies with rotation — they take real IPs from home users that do not raise suspicions from anti-fraud systems, unlike cheap datacenter addresses.
If the task is specifically farming and warming up social networks with a direct link to mobile traffic (for example, Instagram or TikTok, where most real users log in from their phones), consider mobile proxies — they mimic the behavior of a real mobile operator and trigger security checks less frequently.
How to Prevent IP Burning in the Future
Prevention is cheaper than recovering a banned account. Here are key practices that reduce the risk of IP burning again:
- Use dedicated IPs instead of shared for critically important accounts — other people's activity on a shared address will not affect your reputation.
- Set up IP rotation wisely — changing the address too frequently looks more suspicious than maintaining a stable session with one clean IP.
- Maintain geographical consistency — the IP, account, and timezone of the profile in the anti-detect browser should match the region.
- Avoid peak loads — a sudden surge in activity (100 actions per hour instead of the usual 20) triggers anti-fraud by itself, regardless of the quality of the IP.
- Check the reputation of the IP before starting work, not after the first problems — this saves time and protects the account in advance.
For large-scale multi-accounting — for example, an SMM agency managing 30+ client profiles — it is critical to link the anti-detect browser (Dolphin Anty, AdsPower, or GoLogin) with a quality pool of proxies, where each profile is assigned a separate, non-overlapping IP address. This reduces the risk of chain-bans, where blocking one account pulls down the entire pool of linked profiles.
For parsing and monitoring prices on marketplaces, where speed and stability are more important than anonymity at the level of human behavior, a more budget-friendly solution is often sufficient — datacenter proxies, which provide high-speed data collection without the need to imitate a real user.
Conclusion
A burned residential IP rarely leads to an immediate ban — usually, it is a process of several warning signals: an increase in captchas, a decline in ad reach, verification requests, degradation of connection speed, and being blacklisted. The sooner you recognize these signs, the higher the chance of preserving the account without losing farming or advertising budget.
If you regularly encounter such situations when working with Facebook Ads, TikTok Ads, Instagram, or monitoring Wildberries and Ozon, it makes sense to switch in advance to a proven infrastructure with a clean IP reputation. Residential proxies with proper rotation and dedicated addresses mitigate most risks before the platform's anti-fraud system has a chance to notice anything.