Learn How Proxies Work: The Protocol-Level Guide
A vendor-neutral, protocol-first guide to proxy servers: how intermediaries route packets, why IP origins matter, HTTP versus SOCKS5 wire specs, and when a proxy is the wrong tool entirely.
The Four Explainers
Numbered in reading order rather than by popularity: define the term, then the address, then the protocol, then the alternative. Every page after the first defines itself against vocabulary the first one sets — but each stands on its own if you already know what you came for.
Definition & Provenance
What a proxy server is at the protocol level, what changes on the wire, and the four network origins an address can come from.
What Is a Proxy Server?
In HTTP, a proxy is a message-forwarding intermediary chosen by the client. What actually changes on the wire, forward proxy vs reverse proxy, transparent vs anonymous vs elite, and what a proxy is not.
Read the explainerTypes of Proxies by IP Origin
Datacenter, ISP static residential, peer residential and mobile proxies compared on provenance: who owns the address, who else shares it, and a 4-lookup recipe for proving what you were sold.
Read the explainerProtocol & Scope
Which protocol to speak to the proxy, how authentication and DNS behave, and how a proxy differs from a system-wide VPN tunnel.
HTTP vs SOCKS5 Proxy
HTTP CONNECT and SOCKS5 compared at the byte level: round trips before the first byte, the ATYP byte behind socks5h, how each authenticates, and why neither encrypts the hop to the proxy.
Read the explainerProxy vs VPN Differences
Scope, threat model, and plumbing: where each attaches in the OS, what is really encrypted on which hop, why only a proxy gives you several concurrent identities, and which one your task needs.
Read the explainerFour Axes, One Overloaded Word
Almost every argument about “proxy types” is really four separate questions sharing one name. They are independent: the same IP address is routinely sold over both protocols, and rotation says nothing about where the address came from. Two of these axes are settled here; two are buying decisions and are settled in the commercial hub.
Forward vs Reverse
Who picked the intermediary. A forward proxy is picked by the client to change its egress identity; a reverse proxy is picked by the site to protect and balance its origin.
Forward vs reverse guideWhere the IP Originates
Who registered the address: a hosting company, a consumer ISP in a datacenter rack, a real household, or a mobile network operator behind CGNAT.
Four IP origins comparedWhich Protocol You Speak
HTTP CONNECT or SOCKS5. Both tunnel TCP, but SOCKS5 can relay UDP and negotiates its credentials in binary rather than HTTP headers.
HTTP vs SOCKS5 breakdownSocket vs System Scope
Whether traffic is routed per application socket (proxy) or captured system-wide into a virtual network interface (VPN).
Proxy vs VPN differencesWhere Should You Start?
Find the sentence that sounds like you and follow it. Some of these routes lead off this pillar entirely — that is the point of it.
| Where you are right now | The short answer | Read this |
|---|---|---|
| You are asking what a proxy is for the very first time | Start with the protocol definition and forward vs reverse architecture | What Is a Proxy Server? → |
| You need to choose between datacenter, residential, ISP or mobile IPs | Compare the four IP origins by ASN reputation and verify what you bought | Types of Proxies by IP Origin → |
| Your client asks for HTTP or SOCKS5 and you do not know which to pick | Follow the 4-step decision tree and check for DNS leak risks | HTTP vs SOCKS5 Proxy → |
| You want to protect multiple accounts without getting your device banned | A VPN gives one identity; learn why automation requires proxy sockets | Proxy vs VPN Differences → |
| You already know you need a mobile proxy on a real SIM | Skip fundamentals and read how mobile carrier IP rotation works | What Is a Mobile Proxy? → |
Why Mobile Carrier IPs Stand Apart
Once you understand the four axes above, the reason mobile carrier addresses are treated differently by anti-bot systems becomes mechanical rather than mysterious.
Carrier addresses sit behind Carrier-Grade NAT, shared with thousands of real subscribers. To a target server, your traffic looks identical to ordinary mobile browsing — because the IP block actually is used by ordinary mobile browsers.
A modem can shed its current address and acquire a new one from the carrier pool in under 15 seconds via a simple API call. No fixed address means no persistent block: a flagged IP is replaced, not retired.
Fraud detection models trained on ASN, ASN type, and IP reputation consistently score mobile carrier ranges higher than datacenter ranges, because they genuinely are used by millions of legitimate users every day.
The protocol choice is yours, not the modem's. Every PXM2 port answers on both HTTP CONNECT and SOCKS5, so you configure the protocol your stack needs without ordering a different SKU for each one.
The deeper argument — how carrier CGNAT compares to datacenter, ISP, and residential provenance — is made in: What Is a Mobile Proxy?, Datacenter vs Mobile Proxies, Proxy Types Hub.
Get Started with Real Carrier Proxies
Ready to test a real carrier IP? PXM2 runs dedicated 4G and 5G modems across multiple countries:
France
India
Poland
Frequently Asked Questions
What is the difference between a proxy and a VPN?
A proxy works per application or socket, routing only the traffic from programs explicitly configured to use it (such as a browser profile or scraping script). A VPN operates at the operating system level, capturing and encrypting all device traffic through a virtual network interface. Proxies excel at multi-identity automation; VPNs excel at whole-device encryption.
What is the difference between HTTP and SOCKS5 proxies?
HTTP proxies operate at the application layer and can parse or tunnel HTTP/HTTPS traffic using the CONNECT method. SOCKS5 operates at the session layer (Layer 5), relaying arbitrary TCP streams and UDP datagrams without inspecting payload contents. SOCKS5 with remote DNS (socks5h) also prevents local DNS leaks.
Why do websites detect and block datacenter proxies?
Datacenter proxies belong to Autonomous System Numbers (ASNs) owned by cloud hosting providers (e.g. AWS, Hetzner, DigitalOcean). Anti-bot systems consult IP intelligence databases and immediately assign high risk scores to requests originating from server racks rather than residential or mobile internet providers.
What makes mobile proxies more trustworthy than residential proxies?
Mobile proxies route through real cellular carrier modems sharing Carrier-Grade NAT (CGNAT) pools with hundreds of thousands of smartphone users. Target sites cannot easily ban a mobile IP address without blocking innocent cellular subscribers, giving mobile proxies the highest trust score of any proxy type.
Can a proxy server see my passwords and credit card details?
When you connect to an HTTPS website through a proxy using the HTTP CONNECT method or SOCKS5, an end-to-end encrypted TLS tunnel is established directly between your browser and the destination server. The proxy only sees the destination host and port; it cannot decrypt or read your passwords, tokens, or form submissions.
Once the Vocabulary Is Settled
These pages assume the definitions above and get specific about mobile carrier IPs: how they work, which type to buy, and how to test one.
Decided a Mobile IP Is What You Need?
Dedicated 4G and 5G modems on real carrier SIMs, with unlimited bandwidth, unlimited rotations, and both HTTP and SOCKS5 answering on every port.
Browse Mobile Proxies