CashoutGuard: fraud prevention for rewards, GPT, faucet, PTC and offerwall sites.

Residential proxy fraud on offerwalls: how to spot traffic that IP blocklists miss

Residential proxies give a fraudster a clean home IP in any country they want. IP blocklists see an ordinary internet customer and let them through. This guide explains why that happens, which signals still give the traffic away and how to act on it.

Short answer

Residential proxies route traffic through real home connections, so IP blocklists see an ordinary internet customer. They are exposed by what the proxy does not change: a browser timezone or language that does not fit the IP country, one IP seen with many timezones, WebRTC leaks, the device and the offer timing.

Why IP lists miss them
The IPs belong to consumer providers, rotate fast and are shared with real people.
Strongest cheap checks
Browser timezone and language compared with the IP country.
IP-level signal
The same IP seen with 3 or more unrelated browser timezones in a week.
What to do
Hide high-paying walls at the offer click, review at cashout, block IPs only briefly and act on the account and device.

What a residential proxy is

A residential proxy routes traffic through a real home or mobile connection. The exit IP belongs to a normal internet provider, not a data center. Many of these IPs come from people who installed a free app or browser extension that quietly shares their bandwidth.

Proxy sellers rent access to huge pools of these IPs. A buyer can pick a country, a state or even a city, and get a fresh IP for every request or every session. For a fraudster on a rewards site this is ideal. They can appear as a US user, then a UK user, then another US user, all from the same laptop.

On an offerwall the motive is simple. High-paying offers are targeted at a few countries. A user in a low-payout market can earn several times more per offer by looking American. And a multi-account farmer can give each fake account its own home IP so the accounts do not look connected.

Why IP blocklists do not catch them

IP reputation lists are built to find VPN servers, hosting ranges and Tor exits. Those IPs are shared by many users, sit in known data centers and stay the same for months. They are easy to list.

Residential proxy IPs are different in every way that matters:

  • They belong to consumer providers. The ASN is a cable company or a mobile carrier, the same as your honest users.
  • They rotate fast. A proxy IP may be used for a few minutes and then not again for weeks.
  • They are shared with real people. The same IP may be a proxy exit at 3 pm and a family watching TV at 8 pm. Blocking it blocks them too.
  • There are too many. Proxy pools are sold by the million. No list keeps up.

Signals that expose a residential proxy

The proxy changes the IP. It does not change the browser, the device or the person. The trick is to compare what the network says with what the browser says, and to watch each IP over time.

SignalWhat you seeWhy it works
Timezone vs IP geoBrowser clock set to Asia/Manila, IP in TexasUsers rarely change the system clock to match the proxy
Browser language vs countryLanguage list starts with ar-EG or id-ID on a US IPThe regional language tag names the real country
One IP, many timezonesThe same IP seen with 3 or more unrelated browser timezones in a weekA real household has one clock; a proxy exit serves many strangers
WebRTC leakWebRTC reports a second public IP in another countrySome proxy setups do not route WebRTC traffic
ASN or carrier mismatchA mobile carrier IP on a desktop browser, or the carrier changes between click and conversionProxy pools mix carriers and connection types freely
Offer speedOffers completed far faster than real users manageProxy users are often professionals working a list

Timezone and language are the strongest cheap checks

Read the browser timezone with JavaScript and compare its country with the IP country. If the clock says Manila and the IP says Dallas, and the UTC offsets differ, you are almost certainly looking at a proxy or VPN.

Language works the same way. Browsers send a list such as ar-IQ, ar, en-US. The region part of a tag names a country. en-US and en-GB are defaults everywhere, so ignore them. But a first language of ar-EG on a US home IP is a strong hint that the user is not in the US.

Watch the IP, not only the user

The most telling proxy signal is at the IP level. Store the browser timezone of every event with its IP. If one IP address shows up with Europe/Berlin, Asia/Dhaka and America/Sao_Paulo in the same week, it is serving strangers on different continents. That is what a proxy exit looks like.

Checks you can run on your own data

If you already log the browser timezone and languages with each click, you can find proxy traffic with a few queries.

  1. Group events by IP and count distinct browser timezones over the last 7 days. Anything with 3 or more deserves a look.
  2. List accounts whose browser timezone country differs from the IP country on offer clicks, sorted by earnings.
  3. Compare the IP country of the offer click with the IP country at conversion. A proxy that rotated in between shows up here.
  4. Look at the device. Accounts that share a device but arrive from different home IPs in the same country are a farm using a proxy pool.
-- IPs seen with many unrelated browser timezones in the last 7 days
SELECT ip,
       COUNT(DISTINCT browser_tz) AS timezones,
       COUNT(DISTINCT user_id)    AS accounts
FROM events
WHERE created_at >= NOW() - INTERVAL 7 DAY
GROUP BY ip
HAVING COUNT(DISTINCT browser_tz) >= 3
ORDER BY timezones DESC;

What to do when you find it

Residential proxy signals are softer than a Tor exit. That shapes the response. The goal is to stop proxy earnings from reaching a payout, not to ban every mismatch you see.

  • At the offer click, hide high-paying walls when the timezone, language or WebRTC checks point to a hidden location. Honest users rarely notice. Proxy users lose the reason to be there.
  • At conversion, flag clicks and conversions from different countries. Keep the evidence for when the network asks.
  • At cashout, review, do not auto-ban. Look at how much of the balance was earned while the signals were firing.
  • Block the IP only for a short time, if at all. Tomorrow it may belong to a real family.
  • Link the accounts. If the same device keeps appearing with different proxy IPs, treat the accounts as one cluster.

How CashoutGuard automates it

CashoutGuard reads the browser signals with a small JavaScript collector and scores each event through one server call to /v1/evaluate. The result is a score from 0 to 100 with the reasons behind it.

  • timezone_mismatch when the browser clock and the IP point to different countries.
  • locale_country_mismatch when the browser language names another country than the IP.
  • ip_multi_timezone when one IP has been seen with several unrelated timezones in a week.
  • webrtc_ip_leak when WebRTC reveals a public IP in another country.
  • click_conversion_country_mismatch when the offer was clicked in one country and converted in another.

These sit next to the usual VPN, Tor, datacenter and iCloud Private Relay checks, plus device and payout address linking. Start in shadow mode to see how much of your traffic is affected before anything is blocked. The docs list every reason code, and the free plan covers up to 1,000 monthly active users. See pricing for the paid plans.

Frequently asked questions

Can a residential proxy be detected from the IP alone?

Rarely. The IP belongs to a normal internet provider. Detection depends on comparing the IP with the browser timezone, language and WebRTC data, and on watching how many different users one IP serves.

Should I block IPs that were used as residential proxies?

Only briefly. These IPs belong to real households and rotate quickly. Blocking them for long mostly hurts honest users later. Act on the account and device instead.

Is a timezone mismatch enough to deny a cashout?

Not on its own. Travellers, expats and people with wrong clocks exist. Use it together with language, WebRTC, device and offer speed signals before denying money.

Why do fraudsters prefer residential proxies to VPNs?

Because most VPN servers are on known lists. A residential IP looks like an ordinary home customer, so it passes simple IP checks and lets each fake account appear in a different home.

Keep reading