A mobile proxy routes your traffic through a real phone on a cellular network, so the destination sees a genuine 4G/5G carrier IP — Vodafone, Turkcell, Türk Telekom, T-Mobile, Verizon, EE — instead of a datacenter address. Mobile networks use carrier-grade NAT (CGNAT), which places thousands of real subscribers behind every public IP. That crowd of ordinary people makes the address virtually impossible for anti-bot systems to ban without collateral damage to genuine customers.
TL;DR — mobile proxies are the highest-trust IP class for any task that has to look like a real phone user. Below you'll find exactly how Nodetonet delivers them, how they compare with other proxy types, what you can build with them, and how to get started.
How Nodetonet delivers mobile proxies
Nodetonet is a self-hosted platform: you pair your own Android phones using our agent app (or use capacity we provide), and each phone becomes a controllable proxy exit. There is no opaque shared pool. You know which device is serving which request, you set when IPs rotate, and you decide how each customer authenticates — from inside your own panel.
The platform runs a lightweight agent on each Android handset. That agent opens an encrypted tunnel back to an edge server in our data plane, and the panel routes customer proxy connections through it. Because the agent uses the phone's live SIM, the egress IP is always a genuine mobile-carrier address — not a residential ISP, not a VPS.
To verify what any proxy looks like to a target, use our free What is my IP tool or run a quick check with the proxy checker.
Mobile vs residential vs ISP vs datacenter
All four proxy types differ in where their exit IP comes from, and that origin determines how much a target trusts them:
| Type | IP source | Trust / block-resistance | Typical billing | Best for |
|---|---|---|---|---|
| Mobile (4G/5G) | Real phone on carrier CGNAT | Highest — shared with real subscribers | Per device or prepaid | Hardest anti-bot targets |
| Residential | Home ISP, often SDK-recruited | High, but increasingly detected | Per GB (typically $5–15) | Broad geographic coverage |
| ISP / static residential | Datacenter with ISP registration | Medium-high, stable | Per IP / month | Speed + stable identity |
| Datacenter | Cloud servers (AWS, OVH, etc.) | Low — blocked by ASN | Cheapest per IP | Unprotected or internal targets |
The key insight is CGNAT: banning a mobile IP would block thousands of paying carrier subscribers, so anti-bot vendors leave carrier ranges alone far longer than they tolerate residential or datacenter blocks. See a full provider comparison at Nodetonet vs Bright Data, vs Oxylabs, or vs Smartproxy.
Rotating or sticky — choose per proxy
The same device pool supports both modes simultaneously:
- Rotating — a fresh carrier IP on every request, or on a fixed timer (e.g. every 30 seconds). Best for large-scale scraping, price monitoring, and broad ad verification where you want maximum IP diversity.
- Sticky sessions — append
-session-XXXXto your proxy username to pin a single device to that session for a configured time-to-live. Ideal for account logins, checkout flows, multi-step forms, and any workflow where changing IP mid-flow looks like a takeover attack. - On-demand rotation — trigger a fresh IP from the panel, a public reset link, or the management API whenever your workflow needs it, without waiting for a timer.
Read when to use rotating mobile proxies and sticky sessions explained for deeper guidance on choosing between the two.
Token groups — fleet-level pooling and failover
A token group bundles any number of phones into a single proxy endpoint. When a request arrives, the platform routes it to the healthiest available device using least-connections selection, with automatic failover if a device goes offline. You can set bandwidth quotas, expiry dates, per-client thread limits, IP allowlists, and domain allow/deny rules on each group. Read more at creating token group pools and rotating proxies.
Geo-targeting by country, city and carrier
Nodetonet exposes geo and carrier targeting through a clean username-modifier syntax — no endpoint changes required. You can target a country with -country-tr, a city with -city-istanbul, or a specific carrier. That means you can serve requests through a Turkcell, Vodafone or Türk Telekom exit in Istanbul, all from the same proxy URL. See the full syntax at geo-targeting.
HTTP, HTTPS and SOCKS5 — one pool, any protocol
The same device pool is reachable over HTTP/HTTPS and SOCKS5. HTTP is perfect for browsers, scrapers, and most automation tools. SOCKS5 forwards raw TCP traffic for game clients, custom network tools, and any non-HTTP workload. Both support username/password authentication. See SOCKS5 and HTTP proxies and the blog post on HTTP vs SOCKS5 to pick the right one.
Per-client controls and reselling
Every customer gets an isolated proxy credential with its own settings:
- Username/password authentication or IP whitelist — lock the proxy to specific IPs so no credentials are needed.
- Domain allow/deny lists — restrict which destinations clients can reach.
- Bandwidth quota and expiry — cap usage and auto-expire access on a date, with configurable thread limits to prevent a single client from flooding the pool.
- Upstream chaining — when your phone fleet can't cover a geography, chain an external residential provider behind Nodetonet's single stable endpoint for seamless overflow. See upstream residential forwarding.
If you run an agency or resell proxy access, Nodetonet supports white-label reselling through WISECP integration. See the reseller feature for details.
What can you build with mobile proxies?
- Web scraping at scale — crawl protected e-commerce, travel and social sites without triggering CAPTCHAs. Pair with token groups and rotating sessions for sustained throughput.
- Ad verification — confirm the creative, landing page and price a real mobile user in a specific city or carrier actually sees, and catch geo-fraud or cloaked ads.
- Social media management — each account gets its own device identity, matching the trust posture platforms expect.
- Price and SERP monitoring — read the exact prices and rankings a local shopper reads, not a datacenter-skewed view.
- Mobile app QA — test against real carrier networks, including features that behave differently over cellular versus Wi-Fi.
- Release and ticket automation — match the clean mobile fingerprint these platforms require.
Pricing: prepaid, not per-gigabyte
Nodetonet runs on prepaid credit with no monthly subscription. You pay for active proxies and the bandwidth you actually move; idle proxies cost nothing. For steady workloads that move a predictable volume of traffic, this is dramatically cheaper than a per-GB residential plan. See the pay-as-you-go pricing guide for a worked cost comparison.
Get started in minutes
- Sign up at /auth/register and top up prepaid credit.
- Download the Android agent at /download and pair one or more phones using a token.
- Create a token group in the panel, then create an HTTP or SOCKS5 proxy bound to it.
- Point your tool at the proxy URL — rotation mode, geo-targeting and auth are all configured in the panel, no code changes needed.
For a step-by-step walkthrough, see setting up a rotating mobile proxy from scratch. Browse the full proxy glossary for any term above, or read what is a mobile proxy for a deeper conceptual guide.
TCP/IP fingerprint spoofing
Many advanced anti-bot systems now inspect the TCP/IP fingerprint of incoming connections — subtle differences in TCP window size, TTL, and option ordering that reveal whether a connection is really from a mobile OS or from a desktop Linux server pretending to be one. Nodetonet supports TCP/IP fingerprint spoofing at the edge, so the low-level packet signature matches the Android device that owns the SIM, not the server relaying the traffic. This is the last layer most proxy services skip, and the first thing top-tier bot defences check. See how TCP fingerprint spoofing works for a full technical explanation.
Common mistakes to avoid
- Rotating mid-session. Swapping IPs during a login or checkout flow looks exactly like an account takeover to fraud systems. Always switch to a sticky session for stateful steps.
- Hammering one IP. Even a mobile carrier IP has risk thresholds. Spread heavy workloads across a token group pool and use rate-limiting inside your scraper to avoid request spikes.
- Ignoring the carrier and city. Some targets — especially ad networks, local e-commerce, and streaming platforms — inspect not just the country but the exact carrier and city. Match these to the audience you are emulating.
- Confusing a mobile proxy with a VPN. A VPN tunnels your whole device through one IP primarily for privacy. A mobile proxy routes a specific connection through a carrier IP for trust and geo-targeting, with per-request control. They solve different problems — read the VPN vs proxy guide if you are unsure which you need.
- Skipping the backconnect endpoint. Always connect to the backconnect (rotating) endpoint rather than a single device's IP directly, unless you specifically need a pinned device. This gives you automatic failover when a device goes offline.