Bandwidth Supply

What is Exit Node?

An exit node is the device whose IP address a proxied request finally leaves from, so the destination site sees and logs that device's address instead of the customer's. In residential and mobile proxy networks the exit is usually a phone, computer or router running bandwidth-sharing software; in Tor the same term names a circuit's last relay.

The path runs from the customer to the provider's gateway, through a relay, to the exit, and from the exit to the destination. Everything that makes the request look ordinary belongs to the exit's connection: the ASN, the geolocation and the address's history. Google's Threat Intelligence Group put the commercial logic directly in January 2026: "the proxy provider sells access to the infected device's network bandwidth (and use of its IP address) to their customers". Remove the exit and there is nothing left to sell.

What an exit can see depends on the protocol. For HTTPS, the customer's client asks for a tunnel, the exit opens a TCP connection to the host and port it is given, and from then on it carries encrypted TLS bytes it cannot read. It knows the destination host and the volume, not the page. Plain HTTP is different: it is not encrypted end to end, and Cisco Talos noted in 2021 that unencrypted content "could be intercepted and manipulated in transit" by nodes in such networks. On PROXIES.SX the relay sends a tunnel_connect message with the host and port, and the device is required to forward bytes "raw, untouched, immediately".

The exit's owner is the first party a destination, an abuse desk or a carrier sees. Trend Micro's February 2023 research on proxyware set out the legal exposure that follows from an IP being associated with third parties' activity. Access to the owner's own local network is a separate question that depends on the network's controls; PROXIES.SX has not published a verified control for private IPv4 ranges, so run a peer on an isolated or guest network rather than alongside devices you care about.

PROXIES.SX sets rules for exits that customers can be routed to. A device serves one customer session at a time and is routed customers only at or above a minimum speed, 500 KB/s by default. Only residential and mobile IPs can be listed. Auto-approval needs at least an hour online and a quality score of 50 or more, automatically verified devices are re-checked hourly, and a device offline for an hour is unlisted. The composition of the peer fleet and its exit IPs are not published.

Where you meet it

You meet the term exit node on both sides of a proxy. Buyers see it as the address their request arrived from and the reason a session changed country. Suppliers meet it when they install bandwidth-sharing software, because at that point their connection has become the exit and everything that leaves through it carries their IP.

Common questions

Is a proxy exit node the same as a Tor exit node?

The role is the same: the last hop, whose address the destination sees. The networks differ. Tor exits are volunteer relays in a three-hop encrypted circuit with a public list of exit addresses; commercial proxy exits are consumer devices or servers enrolled by a provider, whose addresses are generally not published.

Can an exit node see my traffic?

For HTTPS, it sees the destination host and port and the amount of data, but not the content, because it only relays encrypted bytes. For plain HTTP it can see and alter everything, since nothing is encrypted. Use HTTPS through any proxy whose exits you do not operate yourself.

Who is responsible for traffic that leaves an exit node?

The exit's IP is what destinations and abuse desks see first, which is why Trend Micro flags legal exposure for owners. Contracts decide the rest: PROXIES.SX partners are responsible for their own devices and for their network being lawful. This is not legal advice; local law and your ISP's terms apply.

Related terms

Peer Relay
A peer relay is the server that bandwidth-sharing devices connect out to, and through which customer traffic is handed down to those devices. Because each device dials the relay and keeps the connection open, it needs no public address and no open port, which is how phones and home lines behind NAT or CGNAT can act as proxy exits.
Proxyware
Proxyware is software that turns a device into an exit point for a proxy network, relaying other people's traffic through that device's internet connection. The term comes from security research, where it covers legitimate bandwidth-sharing clients the owner chose to install and the same clients planted on machines without the owner's knowledge.
Backconnect Proxy
A backconnect proxy is a single hostname and port that fronts a pool of many IP addresses. The client keeps one connection string while the provider's gateway assigns a different exit IP per request, per session or on a timer. Rotation and pool health checks happen upstream, where the client cannot see them.
Residential Proxy
A residential proxy routes requests through an IP address that an internet service provider assigned to a home connection, so traffic appears to come from a consumer household. Lookups return the ISP's ASN and a residential classification. Pools are usually large and rotating, drawn either from real consumer devices or from ISP-registered ranges.
Bandwidth Sharing
Bandwidth sharing means letting a proxy network route other people's internet traffic through your connection, usually by running a small client on a phone, computer or server, in exchange for payment for the traffic carried. To the destination site, that traffic appears to come from your IP address, which is what the network actually sells.
Proxyjacking
Proxyjacking is installing proxyware on a machine you have broken into, so that its bandwidth and IP address can be sold through a proxy network for the attacker's benefit. Sysdig's Threat Research Team defined the term in April 2023, comparing it to cryptojacking: the attacker profits from stolen network access instead of stolen processor time.
Bandwidth-Sharing SDK
A bandwidth-sharing SDK is a library an app developer embeds so the app can relay proxy traffic through its users' connections, with the developer paid for the traffic carried. Google Play allows proxy services for third parties only in apps where that is the primary, user-facing core purpose, and holds developers responsible for the SDKs they ship.
Informed Consent
Informed consent, in bandwidth sharing, means the device owner understands that their connection will carry other people's internet traffic, what that involves and how to stop, and agrees before any traffic flows. It separates a bandwidth-sharing app a person chose to run from proxyware placed on their device without their knowledge.
USDC on Solana
USDC on Solana is Circle's dollar stablecoin issued as a token on the Solana blockchain, identified by the mint address EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v. A Solana wallet can hold it alongside native SOL, but they are different assets, so a payout setting has to name the currency and the network.

Real 4G/5G mobile and residential IPs

PROXIES.SX runs carrier IPs in 100+ countries with HTTP and SOCKS5 on every endpoint. $4/GB down to $2.40/GB at volume, free endpoints and rotation, and your GB never expire.