Security

What is Anonymity?

Anonymity, in proxy terms, is how much a destination server can learn about the client behind a connection. Proxy listings grade it by whether the proxy forwards your real IP or announces itself in request headers, though DNS, WebRTC and TLS details can give away the same information a header would.

The classic grading comes from what a proxy does with request headers. A transparent proxy passes your real address onward, normally in X-Forwarded-For, and announces itself with Via. An anonymous proxy drops or fakes the client address while still sending proxy headers. An elite proxy sends neither, so the request reads as though it came straight from the proxy's own address. RFC 7239 standardised a Forwarded header for this purpose, though X-Forwarded-For, X-Real-IP and Client-IP are what most software still writes.

That grading only describes plaintext HTTP, or a proxy that terminates TLS itself. For an HTTPS site the client issues CONNECT and the proxy relays encrypted bytes it cannot read or modify, so it has no place to append a header. Nearly every proxy looks elite over TLS. Detection therefore moved to the exit address: which ASN owns it, whether the range belongs to a hosting company, whether it appears in commercial reputation feeds, and how many sessions have arrived from it recently.

Header hygiene is one layer of several. A browser can resolve names through your own ISP resolver while its traffic goes through the proxy, which puts your real network in someone's DNS logs. WebRTC can report local and public addresses through STUN unless the browser is configured otherwise. A TLS fingerprint such as JA3 or JA4 describes the client library, and a fingerprint that disagrees with the advertised User-Agent is a strong signal on its own. Timezone and language settings that contradict the IP's geolocation do the same work.

Anonymity toward a website is separate from anonymity toward the proxy operator. Whoever runs the exit sees your destinations and, on plain HTTP, your payloads. A proxy controls what a destination server observes; it is not a privacy system of the kind Tor aims to be. The practical test is empirical. Send a request through the proxy to a service that echoes back every header it received, then compare that against the same request sent directly, and the difference is what a target can act on.

Where you meet it

This comes up when a target starts flagging traffic that used to pass and you need to work out which layer is talking. Check the headers a server receives before assuming the address is burned. Anonymity level also appears as a field in proxy listings and checker output, reported as transparent, anonymous or elite, and that label describes header behaviour and nothing else.

Common questions

How do I check a proxy's anonymity level?

Send a plain HTTP request through it to a service that echoes back the headers it received, then look for Via, X-Forwarded-For, X-Real-IP and Proxy-Connection. Your own address in any of them means transparent. Proxy headers without your address means anonymous. Neither present means elite.

Does a high-anonymity proxy make me anonymous online?

It hides your address from the site you visit. The proxy operator still sees your destinations, browser fingerprinting still identifies the client, and any logged-in account identifies you directly. Anonymity here is a property of one connection toward one server rather than general privacy.

Does HTTPS change how proxy anonymity works?

Yes. Over an HTTPS CONNECT tunnel the proxy relays encrypted bytes and cannot insert headers, so header-based grading stops applying and almost any proxy looks elite. Servers then judge the exit IP itself, its ownership and reputation, and the TLS fingerprint of the client behind it.

Related terms

Proxy Server
A proxy server is an intermediary that accepts your connection, makes its own request to the destination, and relays the response back. The destination logs the proxy's IP address instead of yours. Proxies are used for anonymity, geographic routing, access control, caching, and spreading a workload across many addresses so no single one is rate limited.
IP Address
An IP address is the numeric identifier a device presents on an IP network so packets can be routed to and from it. IPv4 writes 32 bits as four decimal octets, such as 203.0.113.7. IPv6 writes 128 bits as hexadecimal groups, such as 2001:db8::1. Every request a server logs is tied to one.
Anonymous Proxy
An anonymous proxy hides the client's real IP address from the destination server but still identifies itself as a proxy, typically through a Via or Proxy-Connection header. The site learns that an intermediary is in the path and can act on that, without ever learning where the request originated.
Elite Proxy
An elite proxy, also called a high-anonymity or level 1 proxy, forwards requests without adding Via, X-Forwarded-For or any other header that reveals an intermediary. To the destination server the traffic reads as an ordinary direct connection from the proxy's own IP address. That address can still be classified.
Transparent Proxy
A transparent proxy intercepts traffic without any client configuration and passes the client's real IP to the destination, usually in an X-Forwarded-For header alongside Via. ISPs, schools and corporate networks deploy them for caching and content filtering. They give the user no privacy and are visible to any server that reads headers.
IP Reputation
IP reputation is the trust score a website, mail server or anti-bot system assigns to an IP address based on the traffic it has produced before. Spam complaints, request patterns, past abuse reports, hosting type and ASN ownership all feed that score. A poor one earns CAPTCHAs where a good one passes, or a refusal with no explanation.
Blacklist
A blacklist is a list of IP addresses, domains or ranges that a service refuses or restricts. Public DNS blacklists such as Spamhaus target mail abuse, while anti-bot vendors, CDNs and individual sites keep private ones. An address lands on a list after abuse reports, spam or automated traffic, and removal ranges from automatic expiry to a manual delisting request.
Whitelist
A whitelist is an explicit list of IP addresses, ranges or identities that a system allows, with everything else denied by default. Firewalls, admin panels, API gateways, database hosts and proxy providers all use them. On the proxy side, whitelisting your server's public IP lets it connect without sending a username and password.

Real 4G/5G mobile and residential IPs

PROXIES.SX runs carrier IPs in 100+ countries with HTTP and SOCKS5 on every endpoint. $4/GB down to $2.40/GB at volume, free endpoints and rotation, and your GB never expire.