Skip to content
ProxyForge

Dedicated vs shared proxies: what you actually get

ProxyForge engineeringUpdated 7 min read

Dedicated vs shared proxies is a question of who else sends traffic through the same address. A dedicated proxy is assigned to one customer for the whole billing period, so its reputation and its share of each target's rate limit are yours alone. A shared proxy is used by several customers at once, which makes it cheaper but means their traffic affects how targets treat yours. Which one you need depends on the target, whether anyone must allowlist the address, and how much you trust the vendor's definition of "dedicated".

Most of the difference is invisible from your side of the connection. This guide covers what each arrangement actually gives you, where co-tenants cause problems, how to tell whether a dedicated address really is dedicated, and when shared is the sensible choice.

What dedicated and shared actually mean

In the dedicated vs shared proxies decision, the terms apply mainly to static addresses, the datacenter and ISP proxies described in our comparison of proxy types.

  • Dedicated. One customer holds the address for the whole assignment period. No other customer's traffic leaves through it while it is yours.
  • Shared. The vendor sells the same address to an open-ended number of customers at the same time. You receive credentials to a list of addresses that other accounts also use.
  • Semi-dedicated. A middle tier where the vendor caps the number of concurrent customers per address, commonly at a small number.

Rotating residential and mobile pools sit outside this vocabulary. Every customer draws from the same population of peers, so they are shared by nature, and the relevant question is how the vendor manages the pool's reputation rather than who holds a given address.

"Dedicated" also says nothing about the address's past. An address can be exclusively yours today and have been abused by someone else last month. That history is the part buyers most often miss.

Reputation contamination from co-tenants

Targets judge addresses by what they have seen from them. On a shared address you inherit the sum of every co-tenant's behavior:

  • a co-tenant running aggressive scraping gets the address challenged or blocked on sites you also use;
  • a co-tenant sending spam or credential-stuffing traffic gets the address onto blocklists that affect targets you never interact with;
  • a co-tenant's abuse report can lead the vendor to pull the address from service, taking your workload with it.

You cannot see any of this happening. What you see is a block rate that changes for no reason you can find, on a target your own traffic has not changed against. When debugging 403 and 429 errors, shared addresses add a variable you cannot control or even observe.

A dedicated address removes co-tenants from the equation for as long as you hold it. It does not remove history, which is why the prior-use questions below matter.

Rate limits are shared too

Many targets rate-limit per address. If a target allows a certain number of requests per minute from one address and three customers are using it, the allowance is split three ways, and nobody knows the split. Your job can be throttled while sending well under the limit you measured, because someone else's job started.

This makes capacity planning unreliable. On a dedicated address you can measure a target's per-address tolerance once and size your address count from it. On a shared address the same measurement is only a snapshot of whatever the co-tenants happened to be doing that day.

Allowlisting only works with dedicated addresses

When a partner, a customer's API or your own firewall allowlists your egress address, it is granting access to whoever sends traffic from it. On a shared address that includes every other customer of the vendor who holds the same address. That is a security problem, not a performance one: you would be asking a partner to trust strangers.

For any workload where an address is allowlisted, the address must be dedicated, and the vendor must commit to how long it stays yours and how much notice you get before it changes. Our guide to IP allowlist vs username and password authentication covers the related case of allowlisting your own servers with the proxy vendor.

Dedicated vs shared proxies on cost

Shared addresses are cheaper because the vendor sells each one several times. The price difference buys you:

  • a reputation that reflects only your traffic from the assignment date;
  • the whole of each target's per-address allowance;
  • an address you can put in an allowlist;
  • a clear line of accountability when something goes wrong.

Whether that is worth paying for depends on what a block costs you. Compare cost per successful request, not cost per address. A cheap shared address that is challenged on a third of requests may cost more per usable result than a dedicated one; our guide to proxy pricing per GB and per IP shows how to run that comparison.

Dedicated Semi-dedicated Shared
Concurrent customers per address One A small, capped number Open-ended
Reputation reflects Your traffic, plus prior history You and a few co-tenants Every co-tenant
Per-address rate limit All yours Split among co-tenants Split among an unknown number
Safe to allowlist Yes, with a notice commitment No No
Predictable capacity Yes Partly No
Relative cost Highest Middle Lowest

How to tell whether "dedicated" is really dedicated

You cannot observe exclusivity from the outside, so it has to come from the vendor's commitments and records. The word appears in plenty of product names where the underlying assignment is looser. Ask these questions in writing and keep the answers with the contract.

Questions to send your vendor

  1. Exclusivity period. Is the address assigned to our account alone for the full billing period? Can it be assigned to anyone else during that time for any reason, including capacity shortages?
  2. Prior-use history. Was this address previously assigned to other customers? If so, for how long, and was it ever withdrawn because of abuse?
  3. Reassignment cool-down. When a customer releases an address, how long does it rest before it is assigned to someone else? Is that period fixed or discretionary?
  4. Blocklist screening. Do you check addresses against public blocklists before assignment? What happens if one we receive is already listed?
  5. Replacement. If an address is blocked on our targets in the first days, will you replace it? How many times, and from a different /24?
  6. Your own use. Does the vendor, or any partner, route traffic through the address while it is assigned to us, for example for health checks or testing?
  7. Contractual wording. Where in the terms or order form is exclusivity stated, and what remedy applies if it is breached?

A reassignment cool-down deserves particular attention. An address released by an abusive customer and reassigned the same day brings that customer's reputation straight to you. A vendor with a defined resting period and a screening step is managing that risk; one without has left it to you.

Checks you can run yourself

You can gather circumstantial evidence even without the vendor's records:

  • query public blocklists and reputation services for your addresses on the day you receive them, and keep the result as a baseline;
  • run a small test against targets you have never used and note any immediate challenges, which suggest history you did not create;
  • watch for unexplained shifts in block rate on targets where your own traffic pattern is flat.

None of these proves co-tenancy. Together they tell you whether to ask harder questions.

When shared proxies are fine

Dedicated is not always the right answer. Shared addresses are a reasonable choice when:

  • the targets are tolerant, such as public documentation, open data portals or APIs that do not rate-limit per address;
  • the workload is low volume and a block simply means a retry through another address;
  • you are prototyping or benchmarking and do not yet know which targets matter;
  • nobody needs to allowlist the address and no account or session depends on it staying clean.

Shared addresses are not appropriate for logged-in sessions, allowlisted integrations, or anything where an unexplained block rate would be expensive to debug. When in doubt, run the same sample of real traffic through both and compare validated success, as described in our guide to benchmarking proxy providers.

Current assignment options at ProxyForge

Whatever you decide on dedicated vs shared proxies, ask the questions above of the vendor and keep the answers with the contract; they belong in any proxy provider due diligence checklist.

For how ProxyForge assigns static addresses today, see the ISP proxies and datacenter proxies product pages. If the answers you need are not there, send us the questions from this guide and we will answer them in writing, the same as we would expect of any vendor.

FAQ

Related questions

What is a semi-dedicated proxy?

A static address the vendor sells to a small, fixed number of customers at once, often two or three. It costs less than a dedicated address, but every co-tenant still affects its reputation and its rate limits on shared targets.

Are residential proxies shared or dedicated?

Rotating residential pools are shared by design: many customers draw from the same peers, and the address you get depends on who is online. Some vendors offer exclusive access to a slice of a pool, which is a different arrangement from a dedicated static address.

Can I test whether a proxy address is being used by someone else?

Not directly. You can watch for signs, such as blocks or captchas on targets you have never sent traffic to, or reputation-database listings that predate your purchase, but only the vendor's assignment records can show exclusivity.

Is a dedicated proxy more secure than a shared one?

Not in the sense of protecting your traffic; encryption and the vendor's own controls decide that. The difference is reputational and operational: a dedicated address carries only your history and your request rate.

Start with the evidence

Ask us to trace an address, send you the sourcing attestation, or price your current volume at our published rates. A named engineer will help with your technical and procurement review.

One business day, from a named engineer.