SpoofProxies logo
Use case

Spur Context and Mobile Carrier Addresses

Spur takes a different approach from most IP reputation vendors. Rather than a single fraud score, it tries to describe what is actually running behind an address: which VPN or proxy services have been seen using it, what kind of infrastructure it is, roughly how many clients sit behind it and where they come from. Security teams like that because it replaces a mystery number with evidence. For a US mobile address, Spur's picture is shaped heavily by carrier-grade NAT, and knowing that makes its output far easier to read when you check a SpoofProxies line.

Infrastructure type first

Spur labels the kind of network an address belongs to, and mobile is one of the categories alongside data centre and residential. On an AT&T, T-Mobile or Verizon line the mobile label is the expected answer, and it is the most important field for anyone deciding how to treat the traffic. A data-centre label on a line you believe is mobile almost always means a misconfigured client that is not sending traffic through the proxy at all.

Alongside the type, Spur reports the autonomous system and organisation, a location, and, when it can, the device types and operating systems it has seen from that address.

Client counts on a CGNAT address

One of Spur's distinctive fields is an estimate of how many distinct clients it has observed behind an address, sometimes with a spread of the countries or regions they came from. On a home broadband connection that number is small. On a mobile carrier address it can be large, because a CGNAT address is shared by many subscribers at once and over the course of a day. That is not suspicious in itself; it is simply what a phone network looks like. Spur's customers know this and treat high client counts on mobile infrastructure very differently from high client counts on a hosting range.

A dedicated line does not make the carrier pool yours alone. It means the device and SIM are used by only one customer. Every other device sharing the public address is an ordinary subscriber on the carrier.

Tunnels, proxy services and risk tags

Spur maintains a catalogue of VPN operators and proxy services and records when an address is seen being used by one of them. It also attaches risk tags, for example that an address behaves like a callback proxy, where software on a consumer device relays traffic for a proxy network, or that it has been associated with tunnelling or spam. On a busy carrier pool address, one of those tags can appear because some other device behind the same address was enrolled in a proxy network, which unfortunately happens with free apps that bundle proxy software.

Reading such a tag honestly means asking whether it describes the address or you. On shared mobile addresses the answer is usually the address. A reviewer at a platform will look at that tag next to the account, the device and the behaviour, and weigh them together.

When a Spur result is worth acting on

Most of what Spur shows on a mobile line is context rather than a verdict. There are a few patterns worth acting on, and they are mostly about your own setup rather than the carrier.

What Spur does not claim

Spur describes infrastructure and observed use. It does not score intent, does not see your browser fingerprint unless the site pairs it with a device product, and cannot confirm who holds a particular session. Its coverage of callback proxies is strong on the large consumer proxy networks and naturally weaker on anything it has not observed. Treat its result as evidence about the network, then look at consistency where the network cannot help: one account per profile, one metro per account, and pacing that looks like a person. If you work on the defending side and want to know how your own rules treat genuine carrier traffic, a dedicated line gives you a controlled mobile source to test against.

Setting up a Spur proxy on SpoofProxies

  1. Add a line and record its metro and carrier from the dashboard.
  2. Configure your client with the line's host, port, username and password.
  3. Confirm the exit address through an IP checker.
  4. Look the address up in Spur's context lookup and note infrastructure type, organisation and location.
  5. Read any tunnel, service or risk tags and decide whether they describe the pool address or your setup.
  6. If a tag looks odd, rotate once and sample the next address before contacting support.

Spur proxy questions

Why does Spur show many clients behind my address?

Carrier-grade NAT puts many subscribers behind one public address. A high client count is normal on mobile infrastructure and is read differently from the same count on a hosting range.

What does a callback proxy tag mean on a carrier IP?

It means software on some device behind that shared address was seen relaying traffic for a proxy network. On a CGNAT pool that device is usually not yours.

Does a dedicated line keep Spur from tagging the address?

No. Dedicated means the device and SIM serve only you, but the public address is still shared with other subscribers on the carrier. Spur describes the address.

Real US carrier IPs for Spur

Dedicated 4G and 5G lines in eight US metros. Sticky sessions, unlimited rotation, HTTP(S) and SOCKS5. From $6/day.

View plans See all locations

More SpoofProxies use cases

All SpoofProxies use cases →