How Proxy Networks Are Built: IP Pools, ASNs, and Sourcing
Behind every proxy provider is a network of IPs with different sources and reputations. Here is how pools are assembled and why ASN diversity matters.
- proxy-basics
- networking
- ip-quality
A proxy provider's homepage lists a number of IPs. That number tells you almost nothing useful on its own, because what matters is where those addresses come from, how they are distributed across networks, and how much of the pool is actually usable against the sites you need.
This is a look at how the plumbing works, so you can evaluate a network rather than a marketing figure.
What an ASN is and why it matters
Every IP address is announced by an Autonomous System, identified by an ASN. A telecom operator has one. A cloud provider has one. A small regional ISP has one.
Anti-bot systems lean on ASN information because it is a reliable proxy for what kind of connection an address represents. Hosting ASNs behave differently from consumer ISPs, which behave differently from mobile carriers. That hierarchy is the foundation of every IP-type comparison, including our own in Datacenter vs Residential vs Mobile Proxies.
So when a provider says it has residential proxies, the meaningful question is: which ASNs are represented, and how many distinct ones?
Pool size versus pool diversity
A million IPs concentrated in a handful of ASNs is worse than a hundred thousand spread across thousands of consumer networks.
Why: blocking is often done at the ASN or subnet level. If a defender classifies a hosting range, every address in it becomes less useful at once. Diversity means that a block affecting one network does not remove your entire capacity in a region.
Diversity also matters for targeting accuracy. If you need addresses in a specific city, the pool behind that city needs enough distinct networks to satisfy requests without reusing the same addresses repeatedly.
How IPs get into a pool
There are a few sourcing models, with different trust and compliance profiles.
Consumer SDKs and opt-in apps. Users agree to share unused bandwidth in exchange for a service, typically free or discounted software. The IPs are real consumer connections. The quality of the consent model varies enormously between providers, which is why we argue sourcing transparency is the most important question to ask in Residential Proxy Sourcing and Consent.
ISP partnerships. The provider contracts with internet providers directly for access to address space. This tends to produce cleaner, more stable addresses with clearer provenance.
Hosting and datacenter ranges. Directly allocated from cloud and hosting providers. Fast and cheap, but visibly server-class to any defender that checks ASNs.
Mobile carriers. Addresses routed through cellular networks, which is why they carry the strongest reputation and the highest cost. The mechanics are in Carrier-Grade NAT and Mobile Proxies.
Why filtering changes the usable pool
A raw count includes addresses that are unsuitable for real work: ones with abuse history, ones blocklisted by major sites, ones from networks that will never pass a trust check. A provider that filters its pool is selling fewer addresses, but a higher proportion of them work.
This is the argument against equating size with quality, and the reason we describe our own pool as pre-filtered rather than simply large. If you are comparing providers, ask what proportion of the advertised count is eligible for your target markets, not just how many exist.
What this means when you buy
Three practical consequences:
- Test the specific market and ASN mix you need, not just the global pool size. Our IP lookup tool shows the network an address belongs to, so you can inspect what you actually receive.
- Expect quality to vary by region. Coverage is rarely uniform, and a provider strong in one country may be thin elsewhere.
- Distrust round numbers without breakdown. A count with a country-level and ASN-level distribution behind it is credible. A bare total is not.
The role of the gateway
One more piece: most providers expose a single gateway hostname that routes to the pool, rather than one endpoint per IP. Your credentials select the country, region and session, and the gateway picks the exit. That is why your proxy address stays constant while the exit IP changes, a distinction we clarify in What Is a Proxy Address.
LightningBytes routes through a single gateway with country, state and city targeting and automatic sticky sessions. The products are described on the residential and mobile pages, and How to Choose a Proxy Provider lists what to verify before committing.