SpoofProxies logo
Use case

SEON Fraud Checks and Carrier IP Traffic

SEON is a fraud prevention platform used by fintech, gaming, travel and online retail companies. It enriches each event with data about the email address, phone number, IP address and device, then runs the merchant's own rules and machine-learning models to decide whether to approve, review or decline. Teams who manage legitimate accounts through a SpoofProxies line, and teams who run SEON and want to know how their rules treat genuine mobile traffic, both benefit from understanding where the IP sits in that stack. Short version: it is one input among several, and rarely the loudest.

What the IP module reports

For an address, SEON's IP analysis returns a connection type, location data, the ISP, and flags for Tor, VPN, web proxy, public proxy and data-centre hosting, along with whether the address appears on spam or abuse lists. It produces a risk contribution that feeds the overall fraud score. On an AT&T, T-Mobile or Verizon line you would expect a mobile connection type, the carrier as ISP and a data-centre flag that reads false. As with any shared CGNAT pool address, a proxy or abuse flag can sometimes appear because of something another device on that address did earlier.

What makes SEON different is what happens next. The IP result is combined with the other modules, and the merchant decides how much each one counts.

The signals the network never touches

SEON is known for its digital footprint checks, which look at whether an email or phone number has a real online presence. A proxy has no effect on any of that. The list above is where most of the weight in a typical SEON setup comes from, and all of it is outside the network path. That is a useful reality check for anyone who assumes an address decides the outcome.

Why mobile addresses are handled carefully

A fraud team that declines every event from a flagged mobile address would decline a meaningful slice of its genuine customers, because carrier addresses are shared across many phones. So in practice mobile traffic is usually judged on the other modules, with the IP result used to catch contradictions, such as a phone number from one country and a network location in another, or a declared billing state far from the login region. Those contradictions matter much more than whether the address has ever been flagged.

This is also why SEON rules often use the IP's location more than its reputation. A US line in the right metro, paired with account details that genuinely belong to that region, removes the contradiction.

Legitimate setups that go smoothly

Agencies and operations teams who manage accounts they are authorised to run tend to have a calm time if each account keeps a single browser profile, a single metro and a sticky session. The line provides a real mobile network in the region the account belongs to; the account's own details do the rest. For QA teams testing a checkout or onboarding flow that uses SEON, a dedicated line per metro lets you reproduce what a real mobile customer in that region experiences, and free location moves let you test several regions from one line over time.

What a line must not be used for is anything SEON exists to stop: synthetic identities, stolen payment details, bonus abuse or bypassing KYC. Those are fraud, the network path does not change that, and we do not support it.

Reading a review or decline

If an event you believe is legitimate lands in review, the useful question is which module contributed most. Merchants can see this in SEON's case view; end users usually cannot. From the user side, check the obvious contradictions first: does the time zone match the line, does the billing region match, is the device the same one the account usually uses? If all of that is consistent, the address is seldom the deciding factor, and contacting the merchant's support is the right next step.

Setting up a SEON proxy on SpoofProxies

  1. Pick a line in the metro that matches the account or test region.
  2. Pair it with one browser profile per account and set the profile's time zone to that metro.
  3. Configure the profile with the line's host, port, username and password.
  4. Confirm the exit address and carrier through an IP checker.
  5. If you run SEON yourself, send test events and review which modules contribute to the score.
  6. Keep sessions sticky for signed-in work and record any review outcomes with times and addresses.

SEON proxy questions

Does a carrier IP lower a SEON fraud score?

It removes the data-centre and hosting signals, and a correct region avoids location contradictions. The rest of the score comes from email, phone, device and velocity data the network does not affect.

Why was a legitimate event sent to review?

Check for contradictions such as a mismatched time zone or billing region first. If those are consistent, the merchant's rules weighed another module, and only the merchant can see which.

Can a proxy help pass KYC checks?

No, and it should not. Identity verification is about the person, not the network, and trying to evade it is fraud. Use lines only for accounts and tests you are authorised to run.

Real US carrier IPs for SEON

Dedicated 4G and 5G lines in eight US metros. Sticky sessions, unlimited rotation, HTTP(S) and SOCKS5. From $6/day.

View plans See all locations

More SpoofProxies use cases

All SpoofProxies use cases →