Residential proxy fraud on offerwalls: how to spot traffic that IP blocklists miss
Residential proxies give a fraudster a clean home IP in any country they want. IP blocklists see an ordinary internet customer and let them through. This guide explains why that happens, which signals still give the traffic away and how to act on it.
Short answer
Residential proxies route traffic through real home connections, so IP blocklists see an ordinary internet customer. They are exposed by what the proxy does not change: a browser timezone or language that does not fit the IP country, one IP seen with many timezones, WebRTC leaks, the device and the offer timing.
- Why IP lists miss them
- The IPs belong to consumer providers, rotate fast and are shared with real people.
- Strongest cheap checks
- Browser timezone and language compared with the IP country.
- IP-level signal
- The same IP seen with 3 or more unrelated browser timezones in a week.
- What to do
- Hide high-paying walls at the offer click, review at cashout, block IPs only briefly and act on the account and device.
What a residential proxy is
A residential proxy routes traffic through a real home or mobile connection. The exit IP belongs to a normal internet provider, not a data center. Many of these IPs come from people who installed a free app or browser extension that quietly shares their bandwidth.
Proxy sellers rent access to huge pools of these IPs. A buyer can pick a country, a state or even a city, and get a fresh IP for every request or every session. For a fraudster on a rewards site this is ideal. They can appear as a US user, then a UK user, then another US user, all from the same laptop.
On an offerwall the motive is simple. High-paying offers are targeted at a few countries. A user in a low-payout market can earn several times more per offer by looking American. And a multi-account farmer can give each fake account its own home IP so the accounts do not look connected.
Why IP blocklists do not catch them
IP reputation lists are built to find VPN servers, hosting ranges and Tor exits. Those IPs are shared by many users, sit in known data centers and stay the same for months. They are easy to list.
Residential proxy IPs are different in every way that matters:
- They belong to consumer providers. The ASN is a cable company or a mobile carrier, the same as your honest users.
- They rotate fast. A proxy IP may be used for a few minutes and then not again for weeks.
- They are shared with real people. The same IP may be a proxy exit at 3 pm and a family watching TV at 8 pm. Blocking it blocks them too.
- There are too many. Proxy pools are sold by the million. No list keeps up.
Signals that expose a residential proxy
The proxy changes the IP. It does not change the browser, the device or the person. The trick is to compare what the network says with what the browser says, and to watch each IP over time.
| Signal | What you see | Why it works |
|---|---|---|
| Timezone vs IP geo | Browser clock set to Asia/Manila, IP in Texas | Users rarely change the system clock to match the proxy |
| Browser language vs country | Language list starts with ar-EG or id-ID on a US IP | The regional language tag names the real country |
| One IP, many timezones | The same IP seen with 3 or more unrelated browser timezones in a week | A real household has one clock; a proxy exit serves many strangers |
| WebRTC leak | WebRTC reports a second public IP in another country | Some proxy setups do not route WebRTC traffic |
| ASN or carrier mismatch | A mobile carrier IP on a desktop browser, or the carrier changes between click and conversion | Proxy pools mix carriers and connection types freely |
| Offer speed | Offers completed far faster than real users manage | Proxy users are often professionals working a list |
Timezone and language are the strongest cheap checks
Read the browser timezone with JavaScript and compare its country with the IP country. If the clock says Manila and the IP says Dallas, and the UTC offsets differ, you are almost certainly looking at a proxy or VPN.
Language works the same way. Browsers send a list such as ar-IQ, ar, en-US. The region part of a tag names a country. en-US and en-GB are defaults everywhere, so ignore them. But a first language of ar-EG on a US home IP is a strong hint that the user is not in the US.
Watch the IP, not only the user
The most telling proxy signal is at the IP level. Store the browser timezone of every event with its IP. If one IP address shows up with Europe/Berlin, Asia/Dhaka and America/Sao_Paulo in the same week, it is serving strangers on different continents. That is what a proxy exit looks like.
Checks you can run on your own data
If you already log the browser timezone and languages with each click, you can find proxy traffic with a few queries.
- Group events by IP and count distinct browser timezones over the last 7 days. Anything with 3 or more deserves a look.
- List accounts whose browser timezone country differs from the IP country on offer clicks, sorted by earnings.
- Compare the IP country of the offer click with the IP country at conversion. A proxy that rotated in between shows up here.
- Look at the device. Accounts that share a device but arrive from different home IPs in the same country are a farm using a proxy pool.
-- IPs seen with many unrelated browser timezones in the last 7 days
SELECT ip,
COUNT(DISTINCT browser_tz) AS timezones,
COUNT(DISTINCT user_id) AS accounts
FROM events
WHERE created_at >= NOW() - INTERVAL 7 DAY
GROUP BY ip
HAVING COUNT(DISTINCT browser_tz) >= 3
ORDER BY timezones DESC;What to do when you find it
Residential proxy signals are softer than a Tor exit. That shapes the response. The goal is to stop proxy earnings from reaching a payout, not to ban every mismatch you see.
- At the offer click, hide high-paying walls when the timezone, language or WebRTC checks point to a hidden location. Honest users rarely notice. Proxy users lose the reason to be there.
- At conversion, flag clicks and conversions from different countries. Keep the evidence for when the network asks.
- At cashout, review, do not auto-ban. Look at how much of the balance was earned while the signals were firing.
- Block the IP only for a short time, if at all. Tomorrow it may belong to a real family.
- Link the accounts. If the same device keeps appearing with different proxy IPs, treat the accounts as one cluster.
How CashoutGuard automates it
CashoutGuard reads the browser signals with a small JavaScript collector and scores each event through one server call to /v1/evaluate. The result is a score from 0 to 100 with the reasons behind it.
timezone_mismatchwhen the browser clock and the IP point to different countries.locale_country_mismatchwhen the browser language names another country than the IP.ip_multi_timezonewhen one IP has been seen with several unrelated timezones in a week.webrtc_ip_leakwhen WebRTC reveals a public IP in another country.click_conversion_country_mismatchwhen the offer was clicked in one country and converted in another.
These sit next to the usual VPN, Tor, datacenter and iCloud Private Relay checks, plus device and payout address linking. Start in shadow mode to see how much of your traffic is affected before anything is blocked. The docs list every reason code, and the free plan covers up to 1,000 monthly active users. See pricing for the paid plans.