Two accounts, two proxies, two browser profiles — and the second is still restricted within a week. The usual conclusion is "the proxy was dirty." That is rarely the whole story. Swapping an exit changes one signal out of dozens, and the systems deciding your fate do not score signals in isolation. They score coherence.
The mental model: linking, not detecting
Fraud systems rarely ask "is this a proxy?" They ask "do these sessions plausibly belong to one human, or to a coherent new one?" Every session emits signals, the system builds an entity graph, and two nodes get merged when their signals are consistent in a way random users would not be.
That flips the objective. You are not trying to look clean. You are trying to look consistent — and consistently uninteresting.
Signals cluster into four layers: network (exit IP, ASN class, TLS/JA3, DNS resolver, WebRTC), environment (canvas, fonts, screen metrics, timezone, locale), behaviour (cadence, request ordering, local hours), and data (payment, phone, recovery email). The network layer is the one a proxy can change surgically. The others follow it — or betray it.
Where the mismatch actually shows up
The classic failure is a layered contradiction: a residential exit in Frankfurt, a browser on Asia/Shanghai, Accept-Language: zh-CN, a resolver in Virginia, a library-like TLS handshake. Each field is defensible alone; together they describe nobody.
| Layer | Signal | A mismatch looks like | Align by |
|---|---|---|---|
| Network | Exit + ASN class | Residential exit, datacenter behaviour | One exit class per identity, held sticky |
| Network | Timezone vs. IP geo | IP in DE, clock on Asia/Shanghai | Derive TZ from the exit's geolocation |
| Network | Accept-Language |
German exit, Chinese-only language list | Match locale ordering to the exit region |
| Network | DNS resolver | IP in EU, resolver in US | Resolve through the exit's network |
| Network | TLS / JA3 | Browser-like UA, library-like handshake | Use a real browser stack, not a bare client |
| Network | WebRTC | Real ISP leaked behind the proxy | Disable it, or force it through the exit |
| Environment | Fingerprint drift | Canvas hash changes every session | Freeze the profile; never randomise per run |
The two rules that do most of the work
One identity, one exit, held sticky. Rotating per request is the fastest way to look automated: no human changes city between two page loads. Rotation belongs to stateless fetching, where there is no identity to preserve — a different problem, covered in the proxy IP knowledge base.
Coherence beats cleanliness. An exit scoring a steady 20 for a month beats one scoring 0 today and 80 next Tuesday: only the first is predictable. If the IP changes character, every locale assertion built on it becomes a lie at once.
A workable procedure
- Pick the exit first — region and class (consumer broadband for anything identity-bound), then pin it. Verify the ASN operator name, not a "residential" label.
-
Derive the environment from the exit — timezone, locale,
Accept-Language, and date formats come from the exit's geolocation, not your workstation. - Freeze the profile — one per identity, no per-session randomisation. Drift within an identity is as suspicious as a clone across identities.
- Close the leaks — WebRTC, DNS, and any extension that can route around the proxy.
- Warm up — log in, browse, wait. High-risk actions on a cold session are the most common self-inflicted wound.
- Measure before you scale — run the check below on a handful of identities, not the whole fleet.
A coherence check you can run daily
Assert that the network and environment layers agree before a session starts. Standard library only.
import json
import urllib.request
GEO_API = "https://ipapi.co/json/"
def probe(proxy=None):
# Always probe *through the exit*. A local lookup tests the wrong hop.
opener = urllib.request.build_opener(
urllib.request.ProxyHandler({"http": proxy, "https": proxy})
if proxy else urllib.request.ProxyHandler({}))
with opener.open(GEO_API, timeout=15) as r:
return json.loads(r.read().decode("utf-8"))
def coherence(g, expect):
"""Compare what the exit claims against what the profile asserts."""
problems = []
if g.get("country_code") != expect["country"]:
problems.append(f"geo {g.get('country_code')} != {expect['country']}")
if g.get("timezone") != expect["timezone"]:
problems.append(f"tz {g.get('timezone')} != {expect['timezone']}")
if not (g.get("org") or "").strip(): # ASN operator is the field people skip
problems.append("ASN operator missing — checker returned a stub")
return problems
for name, cfg in ACCOUNTS.items(): # {"acct-1": {"proxy": "socks5://...", "expect": {"country": "DE"}}}
issues = coherence(probe(cfg["proxy"]), cfg["expect"])
print(name, "OK" if not issues else "MISMATCH: " + "; ".join(issues))
Keep one expected-value record per identity; treat drift as a stop condition, not a warning.
Four mistakes that cost the most
Rotating per request for account work. It turns a stable identity into a high-velocity pattern; nothing else compensates.
Mixing exit classes inside one identity. Residential one hour, cloud the next, is a stronger signal than either alone.
Trusting a single score. Checkers disagree because they read different databases at different rates. Agreement between two sources is the signal; one number is a hint.
Forgetting the leaks. DNS, WebRTC, and timezone quietly undo an otherwise correct setup. Check them every session.
FAQ
Doesn't a residential IP alone solve account linking?
No. It removes one failure mode — ASN-based classification. Environment, behaviour, and data signals still do the linking.
How many accounts per exit is safe?
No universal number. The defensible rule is one identity per exit for anything identity-bound, and retiring an exit once an identity on it has failed.
Is a fingerprint browser mandatory?
For multi-account work on one machine, yes in practice: you need per-profile isolation of storage, fingerprint, and routing.
How do I verify the setup before committing?
Complete a real login and a normal session on the target, repeat over several days, and watch variance rather than the first reading.
The full guide this distils — proxy basics, scenario-to-IP-type mapping, protocol and tool choices, plus the router-level and fingerprint-browser setups — is at 代理IP与工具配置全方位指南. To check an exit before pinning it, use the IP check center. Both are maintained by socks5ip.com.cn; confirm current terms with each platform directly for purchase details.
Top comments (0)