Security

What is Anonymous Proxy?

An anonymous proxy hides the client's real IP address from the destination server but still identifies itself as a proxy, typically through a Via or Proxy-Connection header. The site learns that an intermediary is in the path and can act on that, without ever learning where the request originated.

The proxy either omits X-Forwarded-For or fills it with a value that is not your address, while leaving Via or Proxy-Connection in place. Squid is the implementation most people have met, and out of the box it appends both X-Forwarded-For and Via, with the forwarded_for and via directives controlling that behaviour. Some anonymous proxies write their own software name and version into Via, which tells a server exactly what is sitting in the path and how old it is likely to be.

A server can act on any of it. Anti-bot scoring counts proxy headers as one input among many, so the usual result is a raised risk score rather than an outright refusal, though login flows and payment pages are stricter. Plenty of legitimate traffic looks like this, corporate egress proxies included, which is why few sites block on the header alone. The difference from an elite proxy is disclosure, since both keep your own address out of the request.

Classification applies only where the proxy can read the request. Over an HTTPS CONNECT tunnel there is nothing to append to, so an anonymous-class proxy and an elite one are indistinguishable at the header layer for encrypted traffic. Public proxy lists still label ports as anonymous or elite from a plaintext test, and that label says nothing about the exit address, its ASN, its reputation history, or how many other people are hammering the same port at that moment.

Testing takes one request. Send a plain HTTP GET through the proxy to a service that echoes the headers it received, then read the response for Via, X-Forwarded-For, X-Real-IP and Proxy-Connection. If your real address appears anywhere in that set, the proxy is transparent rather than anonymous. If proxy headers are present without your address, the anonymous label fits, and the next question is what the exit IP itself looks like to your target.

Where you meet it

You run into this term reading proxy lists, where every entry carries an anonymity flag. Take the flag as a claim to verify, since whoever scanned the port set it and it may be months stale. For scraping and account work the practical question is whether your target scores proxy headers at all, which one echoed request answers and no listing can.

Common questions

What is the difference between an anonymous proxy and an elite proxy?

Both keep your real IP out of the request. An anonymous proxy still announces itself, usually through a Via or Proxy-Connection header, so the server knows an intermediary is involved. An elite proxy sends nothing identifying the hop, so the request reads as a direct connection from the proxy's own address.

Can a website block an anonymous proxy?

It can. Proxy headers are trivial to spot, and anti-bot systems treat them as a risk signal, usually weighed alongside IP reputation and request behaviour rather than triggering an instant block. The exit address's reputation decides the outcome more often than the headers do.

Is an anonymous proxy safe to use?

The operator sees every destination you request and, on unencrypted HTTP, can read and rewrite the contents as well. A free public proxy of unknown origin can inject anything into a plain HTTP page. Keep traffic on HTTPS end to end, and treat any proxy you did not pay for and cannot identify as hostile.

Related terms

Elite Proxy
An elite proxy, also called a high-anonymity or level 1 proxy, forwards requests without adding Via, X-Forwarded-For or any other header that reveals an intermediary. To the destination server the traffic reads as an ordinary direct connection from the proxy's own IP address. That address can still be classified.
Transparent Proxy
A transparent proxy intercepts traffic without any client configuration and passes the client's real IP to the destination, usually in an X-Forwarded-For header alongside Via. ISPs, schools and corporate networks deploy them for caching and content filtering. They give the user no privacy and are visible to any server that reads headers.
Anonymity
Anonymity, in proxy terms, is how much a destination server can learn about the client behind a connection. Proxy listings grade it by whether the proxy forwards your real IP or announces itself in request headers, though DNS, WebRTC and TLS details can give away the same information a header would.
IP Reputation
IP reputation is the trust score a website, mail server or anti-bot system assigns to an IP address based on the traffic it has produced before. Spam complaints, request patterns, past abuse reports, hosting type and ASN ownership all feed that score. A poor one earns CAPTCHAs where a good one passes, or a refusal with no explanation.
Blacklist
A blacklist is a list of IP addresses, domains or ranges that a service refuses or restricts. Public DNS blacklists such as Spamhaus target mail abuse, while anti-bot vendors, CDNs and individual sites keep private ones. An address lands on a list after abuse reports, spam or automated traffic, and removal ranges from automatic expiry to a manual delisting request.
Whitelist
A whitelist is an explicit list of IP addresses, ranges or identities that a system allows, with everything else denied by default. Firewalls, admin panels, API gateways, database hosts and proxy providers all use them. On the proxy side, whitelisting your server's public IP lets it connect without sending a username and password.
IP Authentication
IP authentication authorizes a proxy client by the source address of its connection instead of a credential. You register the public IP of the machine that will connect, and the provider's gateway accepts sessions from it while refusing the rest. There is no Proxy-Authorization header to send and no password sitting in a config file.
Username Authentication
Username authentication identifies a proxy client with a username and password rather than by its IP address. HTTP proxies carry the credential in a Proxy-Authorization header, and SOCKS5 negotiates it during the handshake. Most providers also encode routing instructions - country, session identifier, rotation behaviour - inside the username string, so one endpoint can serve many configurations.

Real 4G/5G mobile and residential IPs

PROXIES.SX runs carrier IPs in 100+ countries with HTTP and SOCKS5 on every endpoint. $4/GB down to $2.40/GB at volume, free endpoints and rotation, and your GB never expire.