- Most free plans flag datacenter or open proxies; residential proxy detection is usually paid, from $19 a month or MaxMind’s $0.002 a query, as each vendor’s own pages showed on 10 October 2026.
- Free residential detection is documented by proxycheck.io (results expire after 48 hours by default), GetIPIntel (an optional flag in beta) and Maskbreak’s live-visit check; for IPQualityScore, read the plan as well as the feature page.
- No free plan documents mobile or ISP proxies as a type of their own; a mobile carrier flag says the network is mobile, not that the visit is a proxy.
- Decide on the input first: an IP API answers from what is known about the address you send, while Maskbreak’s proxy verdicts need a live visit; its bare
GET /v1/lookupchecks only Tor exits and published cloud ranges. - Read the free-tier terms: ipapi.is allows commercial use explicitly, while vpnapi.io and ipdata limit their free tiers to non-commercial use.
On this page
- Proxy detection APIs compared: what each free plan covers
- Where the free line stops: residential proxy detection is usually paid
- Can residential proxies be detected? Why IP reputation lists miss them
- IP address or live visit: what you send to a proxy detection API
- Can mobile proxies be detected? A 4G/5G proxy, blocked on its first visit
- How Maskbreak answers a proxy visit
- How to test a proxy detection API in an afternoon
- Notes on each proxy detection API
- Which proxy detection API should you choose?
A proxy detection API tells you whether a visitor reached you through a proxy. Most free plans flag datacenter or open proxies but few flag residential ones: for those, try proxycheck.io’s free plan, which also names the operator when known, or pay, from $19 a month at ipgeolocation.io or $0.002 a query at MaxMind. For a signup or login in a browser, Maskbreak’s live-visit check reads the exit the visitor actually came through on your page and adds a device check. This page compares twelve IP-based APIs and that check, from each vendor’s own pages as I read them on 10 October 2026.
Maskbreak publishes this page and is one of the thirteen, so read it as a vendor’s comparison: every other row links to that vendor’s own pages. It covers APIs that detect visitors arriving through a proxy, not the “proxy checker API” tools that test proxies you own; the VPN side has its own free VPN detection API comparison.
Proxy detection APIs compared: what each free plan covers
| Service | Residential proxies | Datacenter, open proxies | Names the service |
|---|---|---|---|
| Maskbreak, live visit | Yes, when recognised: the same flag on every plan | Yes: network.proxy for a recognised proxy, network.datacenter for a cloud server | network.service, when known |
| Maskbreak, bare IP | No | Nine providers’ published cloud ranges only; no proxy verdict | No |
| proxycheck.io | Yes; results expire after 48 hours by default | Yes: SOCKS, HTTP and hosting types | Yes: an operator object, when known |
| IPHub | Paid: Professional tier | Yes: open proxies, Tor, datacenter IPs, commercial VPNs | No |
| GetIPIntel | Optional flag, in beta, IPv4 only | Inside one proxy, VPN or bad-IP score | Only Apple’s relay and two Google VPNs, in VPNType |
| IPQualityScore | From SMB+ in its plan data; its product page says its scoring covers them | Yes: a proxy flag and a Data Center connection type | Not in the documented fields |
| ipinfo | Paid: Max | No: proxy and hosting data start on Core, $31 a month or $310 a year | On Max: residential proxy service names |
| MaxMind | Paid: GeoIP Insights | No: public proxy and hosting flags start on GeoIP Insights | On Insights: some VPN and residential proxy providers |
| IP2Location.io | Paid: Plus | Open proxies only; datacenter ranges from Security, $499 a month | On Security: the proxy provider |
| ipapi.is | No, in its own words | Yes: a datacenter flag; a proxy flag for SOCKS and HTTP exits | VPN services, privacy relays, security proxies |
| ipdata | Not documented | Proxy and datacenter fields; which reach the free tier is not stated | No |
| Scamalytics | Paid add-on, on a paid plan | Yes: public proxies and datacenter on every plan | With the add-on: the provider name |
| vpnapi.io | Enterprise plans only | A proxy flag; no datacenter field | No |
| ipgeolocation.io | Paid plans | No security data on the free plan | On paid plans: proxy_provider_names |
| Service | Free allowance | You send | Commercial use, free |
|---|---|---|---|
| Maskbreak, live visit | 10,000 visitor checks a month, up to 1,000 an hour | A browser token from your page, via your server | Yes, production use within the allowance |
| Maskbreak, bare IP | 100,000 address lookups a month, within the same 1,000 an hour | IP address | Yes |
| proxycheck.io | 1,000 queries a day (100 without an account) | IP address | No non-commercial clause; no resale |
| IPHub | 1,000 requests a day (Basic tier) | IP address | No non-commercial clause; no resale |
| GetIPIntel | 500 a day, 15 a minute; contact email required | IP address; returns a probability | Credit the source; no selling without consent |
| IPQualityScore | 1,000 lookups a month, 35 a day | IP address | No non-commercial clause; no resale; one free account |
| ipinfo | Lite: unlimited requests, country and ASN only | IP address | Lite: yes, with attribution |
| MaxMind | GeoLite: 1,000 queries a day, no proxy data | IP address | GeoLite: attribution required |
| IP2Location.io | 50,000 queries a month | IP address | Attribution required |
| ipapi.is | 1,000 requests a day, the same data as paid | IP address | Yes, explicitly |
| ipdata | 1,500 requests a day | IP address | No: non-commercial use only |
| Scamalytics | 5,000 lookups a month | IP address | No non-commercial clause; no resale |
| vpnapi.io | 1,000 requests a day | IP address | No: personal, non-commercial use only |
| ipgeolocation.io | 1,000 credits a day, no security data | IP address; paid plans add a browser script | For “testing and small projects” |
“Not documented” means I did not find it on the vendor’s public pages, not that the vendor cannot do it. Neither table rates detection quality: no vendor here, Maskbreak included, publishes an independent benchmark I could cite, so test on your own traffic. ip-api.io is left out: on 10 October 2026 its pages gave no free API allowance and no terms of use I could find.
Two proxy types have no column, because no free plan documents either as a type of its own:
- Mobile (4G/5G) proxies. proxycheck.io’s “Wireless” network type, IPQualityScore’s Mobile connection type and ipapi.is’s
is_mobileflag say what kind of network an address is on, not that the visit is a proxy (proxycheck.io’s Wireless includes satellite). The only mobile marking for proxies I found is in ipinfo’s paid residential dataset, where a mobile service’s name ends in_mobile. - ISP proxies, residential addresses run from a datacenter, are not documented as a separate type by any of the thirteen, Maskbreak included.
Where the free line stops: residential proxy detection is usually paid
Datacenter and open proxies are the easier half: their addresses belong to hosting networks and published cloud ranges, as the datacenter IP detection guide explains. Residential detection is where most vendors start charging:
- MaxMind: GeoIP Insights, $0.002 a query, pay as you go.
- ipgeolocation.io: security data, including
is_residential_proxy, on every paid plan, from $19 a month. - IPHub: the Professional tier, 5,000 requests a month from €25 or $29 before VAT, depending on where you view the page.
- Scamalytics: a residential add-on at $100 a month, on top of a paid plan from $25 a month.
- ipinfo: Max, $196 a month or $1,960 a year; ipinfo calls residential detection “a standalone dataset, separate from Privacy Detection”.
- IP2Location.io: Plus, $249 a month.
- IPQualityScore: residential detection from SMB+ in its plan data, $1,149.99 a month or $11,988 a year.
- vpnapi.io: enterprise plans, by request.
Of the thirteen, three free options document residential detection on the free plan. proxycheck.io puts every feature on its free plan (“we do not gatekeep features behind our paid plans”), GetIPIntel has an optional residential flag in beta, and Maskbreak’s live-visit check flags a residential or mobile proxy it recognises on the Free plan as on every paid one. IPQualityScore is the case for reading the plan as well as the feature page: its product page says its IP reputation scoring includes “residential proxy detection”, while the plan data behind its plans page switches residential_proxy on only from SMB+. ipapi.is says it “cannot reliably detect residential and mobile proxies”, and ipdata documents no residential field. So test a free plan on residential exits you rent before relying on it. Maskbreak’s paid plans add volume, not checks.
See it on your own connection: the free live check on the homepage shows the network reading, the browser check and a decision for your visit, with every reason listed.
Open the live checkCan residential proxies be detected? Why IP reputation lists miss them
Most proxy detection APIs answer from data the vendor gathers over time: vpnapi.io, for one, “scans hundreds of public and private proxy listing sites every day”. Such databases “can only be populated over time”, as ipapi.is puts it, so a proxy nobody has reported yet looks clean. A list judges an address by who owns it and what it has been seen doing, and residential, mobile and ISP proxies defeat both:
- The address is shared with real customers. A residential exit is someone’s home line, often enrolled through a bandwidth-sharing SDK in a free app or by malware (residential proxy botnets), and a mobile exit sits behind a carrier’s shared addresses. Cloudflare’s researchers wrote in October 2025 that “a single IPv4 address may represent hundreds or even thousands of users” and that “Blocking the shared IP therefore penalizes many innocent users along with the abuser.”
- The address moves, and old answers go stale. Sellers offer “timed auto-rotation of your IP and instant IP changes” (IPRoyal), so answers age fast: proxycheck.io expires a residential result 48 hours after it last saw the address acting as a proxy (API documentation), and GetIPIntel advises against caching a score for more than 6 hours.
- The owner is a real ISP. A broadband or mobile carrier owns the network, so a hosting list does not match it. In ipinfo’s words, catching residential proxies “requires observing which IPs are actively participating in residential proxy networks over time, not just checking IP ownership” (ipinfo).
- ISP proxies are built to look residential. IPRoyal, which sells them, describes an ISP proxy as “a residential IP acquired directly from an Internet Service Provider” that is “hosted in data centers”, so that such proxies “seem like regular internet users” (IPRoyal).
The residential proxy detection guide covers the signals that survive rotation.
IP address or live visit: what you send to a proxy detection API
Every IP-based API here takes an address and answers from what its vendor already knows about it, which suits logs, batch jobs and traffic that never runs a browser.
Maskbreak’s proxy detection API has both kinds of endpoint. POST /v1/evaluate takes the token Maskbreak’s browser script collects on your page, so its network check reads the exit this visit actually came through, at the moment of the visit. Proxy verdicts come from there, with the service named when known. That reading still rests on Maskbreak’s network intelligence: like any such data, it catches exits already known as proxy exits, and a fresh exit reads as an ordinary connection (below). GET /v1/lookup/{ip} takes a bare address and checks only the Tor exit list and the published cloud ranges of nine providers. Its OpenAPI description says known: false “means neither list matched, not that the IP is safe”, and a carrier’s address is in neither list. A bare lookup of the mobile exit in the next section would read known: false, allow, risk 0, while the live visit through it was blocked.
The free IP lookup runs those two lists on an address you type, and a live check on your own connection. For using both in a signup flow, see proxy detection API vs IP lookup.
Can mobile proxies be detected? A 4G/5G proxy, blocked on its first visit
On 30 September 2026 I opened Maskbreak’s live check in Safari 26 on a Mac through a 4G/5G proxy on Telia’s Estonian network: a free one-hour trial from a seller on the iProxy Store, sold as running on real SIM cards. First visit: Block, with “Proxy” under network signals and a clean browser check, so the block came from the network reading alone.
The API answer for such a visit, computed with the code that answers customers:
That was one proxy, one seller and one evening: it shows the check working on that exit, not coverage of every mobile pool. service is null because a pool is named only when known, and residential is false because the field means only that neither the proxy nor the cloud-server flag fired. An exit not yet known as a proxy exit reads allow at 0 with residential: true; for those, the time zone and device checks below are the backstop. Never block the carrier itself: everyone behind its shared address goes with it. The full test is in mobile proxy detection.
How Maskbreak answers a proxy visit
On a live visit, a proxy that Maskbreak’s network intelligence recognises sets network.proxy: true. With one exception below, it also gets the reason code proxy_detected and a block by default. There is no proxy-type field: residential, mobile and datacenter proxies share the flag, and network.datacenter adds the cloud-server reading when it fires. Computed with Maskbreak’s response builder:
| The visit | decision | risk_score | reasons |
|---|---|---|---|
| A residential or mobile proxy Maskbreak recognises | block | 50 | proxy_detected |
| A proxy on a cloud server Maskbreak recognises | block | 80 | proxy_detected, datacenter_asn |
| Apple’s iCloud Private Relay, recognised | review | 35 | privacy_relay |
| A cloud-server address not recognised as a proxy | allow | 15 | datacenter_asn |
| A home or mobile exit not yet known as a proxy exit | allow | 0 | none |
| … and the browser’s clock, sent with the check, contradicts the address’s country | review | 25 | timezone_mismatch |
| … and the device check flags an automated browser | block | 40 | automation_detected |
| A VPN on its own | review | 35 | vpn_detected |
By default a VPN alone asks for review, not a block, and so does Apple’s iCloud Private Relay, the one exception among proxies: it carries network.privacy_relay: true and the reason privacy_relay in place of proxy_detected. If proxies should not block on your product, the Rules tab can turn them to review; the answer then keeps engine_decision: "block" and adds rule_matched: ["proxy"]. A rule speaks only for the signal it names, so an automated or fake browser the device check flags on the same visit still blocks.
How to test a proxy detection API in an afternoon
Run the same cases through every candidate, on connections you own or rent under terms that allow it:
| Case | How to get it | What to record |
|---|---|---|
| Your home line | Your own broadband, no proxy | Any proxy flag: a false positive |
| A phone on mobile data | Mobile data, no proxy | Any proxy flag; a carrier flag alone is expected |
| A cloud server | A small server you rent | Whether it reads as hosting or datacenter |
| A commercial VPN | Your own subscription | The VPN flag and the service name, if given |
| A residential proxy | A trial from a seller | Which exits get a proxy flag, and the operator name, if given |
| A mobile proxy | A trial on a real SIM; rotate the address and repeat | The same, exit by exit |
| Tor | Tor Browser | The Tor flag |
| No answer | A blocked script, a missing token, a timeout, a 429 | That your code never reads it as a clean result |
- Same exit, same minute: exits rotate, so send each one to every API within a minute and keep the raw answers; proxycheck.io answers a repeat check from its CDN cache for 10 seconds to 10 minutes on a free account.
- Live visits need a page load: open your page through the proxy in a real browser.
- Count false positives on real users: run the check in log-only mode on your signups for a week and read what it would have blocked.
Maskbreak’s public sandbox needs no account. The test token test_proxy returns a fixed proxy answer, which tests your handling, not detection:
curl -s https://maskbreak.com/v1/evaluate \
-H "Authorization: Bearer sk_test_sandbox" \
-H "Content-Type: application/json" \
-d '{"token":"test_proxy"}'
A live key, stored on your server as MASKBREAK_API_KEY, runs the real check; production code should refuse any answer that carries test or sandbox. The sandbox reference lists the other test tokens.
Notes on each proxy detection API
proxycheck.io
The operator object lists services such as residential_proxies, and &days= keeps residential results past 48 hours, to be weighed by their confidence score. The terms allow one free account per customer. See proxycheck.io alternatives.
IPHub
The API returns a block value of 0, 1 or 2, where 2 is “Suspicious IP address, lower confidence (may flag innocent users)”.
GetIPIntel
The contact email must be one that is “checked frequently”, and the residential flag, oflags=r, uses Layer3Intel data (documentation). See GetIPIntel alternatives.
IPQualityScore
On 10 October 2026 the plans page did not draw its table; the plan data in its source gives the prices, the 35-a-day cap and residential_proxy per plan (SMB+ comes to $999 a month billed yearly). The response fields include a proxy flag (“SOCKS, Elite, Anonymous, VPN, Tor, etc.”). See IPQualityScore alternatives.
ipinfo
The pricing page opens on yearly prices shown per month ($26 for Core, $163 for Max). The residential dataset adds last-seen and days-seen fields. See ipinfo alternatives.
MaxMind
The GeoIP Insights anonymizer object flags public proxies, hosting providers and residential proxies, and names VPN and residential proxy providers (“a subset”, in MaxMind’s words); the is_residential_proxy flag “does not include peer-to-peer proxy IPs”. See MaxMind minFraud alternatives.
IP2Location.io
The free plan stops when its queries run out (pricing); Plus adds VPN, Tor and web proxies besides residential ones. See IP2Location alternatives.
ipapi.is
The documentation describes a vpn object that names the VPN service and an egress_service object that names the operator of privacy relays (iCloud Private Relay, Cloudflare WARP) and corporate security proxies, but no operator field for residential or open proxies.
ipdata
The threat fields include is_proxy and is_datacenter; is_vpn is for Business and Enterprise users only.
Scamalytics
The residential add-on gives the provider’s name, last seen and days seen (pricing).
vpnapi.io
The response flags VPN, proxy, Tor and relay, with iCloud Private Relay as its relay example.
ipgeolocation.io
Paid plans add the IP Security API, with is_residential_proxy and proxy_provider_names, and a client-side detection script.
Which proxy detection API should you choose?
- You screen IP addresses for a business: ipapi.is allows commercial use on its free tier explicitly, and proxycheck.io and IPHub do not forbid it; GetIPIntel suits low volumes if you can credit it.
- You want a free residential proxy detection API for IP addresses: proxycheck.io documents residential proxies on its free plan, and GetIPIntel’s flag is in beta; elsewhere it is paid (prices above) or not on offer.
- You need the proxy’s name: proxycheck.io’s
operatorobject on every plan; ipinfo Max, MaxMind’s GeoIP Insights, IP2Location.io Security, the Scamalytics add-on and ipgeolocation.io’s paid plans; Maskbreak’snetwork.serviceon live visits, when known. - A hobby or other non-commercial project: the free tiers of vpnapi.io and ipdata are licensed for that use only.
- You protect a signup, login or checkout in a browser: check the live visit, which reads the exit this visitor actually came through, at the moment of the visit, and adds the device check. That is what Maskbreak is built for, and exits not yet known as proxy exits are why its time zone and device checks stay on.
Maskbreak’s Free plan includes 10,000 visitor checks a month with no card, and paid plans start at €29 a month, excluding VAT (pricing). To see the live check on your own connection, open the free IP lookup through a proxy you own; the API reference has the request and response.
Questions people ask
- Is there a free proxy detection API?
- Yes, several, for IP addresses: proxycheck.io gives 1,000 queries a day with the same features as its paid plans, IPHub and ipapi.is 1,000 requests a day, GetIPIntel 500 a day and Scamalytics 5,000 lookups a month. Maskbreak checks live visits to your page instead, and its Free plan includes 10,000 visitor checks a month. Each figure was read on the vendor’s own pages on 10 October 2026; read the terms as well, because the free tiers of vpnapi.io and ipdata are for non-commercial use only.
- Can a free API detect residential proxies?
- Sometimes. proxycheck.io documents residential proxy results on its free plan, which expire 48 hours after the address was last seen acting as a proxy unless you ask for longer; GetIPIntel has an optional residential flag, in beta and for IPv4 only; and Maskbreak’s live-visit check flags a residential proxy it recognises on its Free plan. IPQualityScore’s product page says its scoring covers residential proxies, while its plan data lists residential detection from SMB+. Elsewhere it is paid: IPHub’s Professional tier, ipinfo Max, MaxMind’s GeoIP Insights, IP2Location.io Plus, a Scamalytics add-on, ipgeolocation.io’s paid plans and vpnapi.io’s enterprise plans.
- How does a proxy detection API work?
- Most look an address up in data the vendor has gathered over time: public proxy lists, honeypots, hosting and cloud ranges, and addresses seen taking part in proxy networks, so an answer is only as fresh as the last sighting. A live-visit check applies that kind of data to the exit a visitor actually used on your page, at the moment of the visit, and adds evidence from the browser. Maskbreak offers both: its bare lookup, GET /v1/lookup, checks only the Tor exit list and nine providers’ published cloud ranges, and its proxy verdicts need a live visit through POST /v1/evaluate.
- Can mobile (4G/5G) proxies be detected?
- Rarely from the address alone. A mobile carrier puts many subscribers behind one public address, so a carrier flag says only that the network is mobile, and blocking the address blocks real customers with it; ipinfo’s paid residential proxy dataset is the one place I found that marks mobile proxy services. A live-visit check applies what is known right now about the exit the visitor actually used: on 30 September 2026 a 4G/5G proxy sold as running on Estonian SIM cards was blocked on its first visit to Maskbreak’s live check, on its network reading alone, with a clean browser check. That was one test of one proxy, not proof that every mobile exit is caught.
- Does IPQualityScore’s free plan detect residential proxies?
- Its pages differ. On 10 October 2026 IPQualityScore’s product page said its IP reputation scoring includes residential proxy detection and offered 1,000 free lookups a month, while the plan data in its plans page’s source marked residential proxy detection off on Free, Startup and SMB Basic and on from SMB+, at $1,149.99 a month or $11,988 a year. Test the free plan on residential exits you rent before relying on it.
- Which free proxy detection APIs allow commercial use?
- ipapi.is says explicitly that its free tier may be used commercially. proxycheck.io, IPHub, IPQualityScore and Scamalytics have no non-commercial clause but forbid reselling their data; GetIPIntel asks for credit and IP2Location.io for attribution, and ipinfo Lite allows commercial use with attribution but has no proxy data, like MaxMind’s free GeoLite. The free tiers of vpnapi.io and ipdata are for non-commercial use only. Maskbreak’s terms cover production use on its Free plan, within the allowance.
- Is a proxy checker API the same as a proxy detection API?
- Not always. Some proxy checker APIs test whether proxies you own are online and fast; a proxy detection API tells you whether a visitor reached your site through a proxy. This comparison covers the second kind.
Compare on your requests, not ours
A free key returns the decision, the network classification and the device fields for every visit, so two vendors can be judged on the same traffic. Free plan: 10,000 checks a month, no card. Or check any address now with the free IP lookup and the IP reputation API.



