IP provenance is the documented chain of custody of an IP address, from its origin to the address your proxy traffic exits from. It answers two questions: where did this address come from, and who gave permission for it to carry your traffic? For a datacenter address the chain is short and largely public; for a residential or mobile address it runs through a partner app and an individual's recorded consent.
The term borrows from art and supply-chain auditing, where provenance means an unbroken, documented history of ownership. Applied to proxies, it turns "is this network ethically sourced?" from a question of trust into a question of records.
IP provenance, defined
A complete provenance chain for a proxy address has four parts:
- Origin. The registry allocation that created the address block and the organization that holds it: a hosting company, an ISP, a mobile carrier.
- Custody. Every step between the holder and the proxy provider: a lease, an announcement agreement, a partner integration, or the provider's own registration.
- Authority. The document that grants the right to route third-party traffic through the address. For owned ranges, that is registration. For leased ranges, a contract. For peer addresses, the consent of the person whose connection it is.
- Current state. Whether that authority is still in force today, and what happens when it is withdrawn.
Provenance is distinct from the attributes that proxy dashboards usually show. Geolocation says where an address appears to be. The ASN says which network announces it. Reputation scores summarize how it has behaved. All three describe the address. Provenance describes how it came to be sold to you, which none of the others can establish.
How IP provenance differs by proxy type
The evidence that establishes provenance depends on the proxy type, because the chain of custody is different for each. For a fuller comparison of the types themselves, see residential vs ISP vs datacenter proxies.
| Proxy type | Origin | Evidence of authority | Can you check it yourself? |
|---|---|---|---|
| Datacenter | Block registered to the provider by a regional internet registry | Registry record and the provider's own ASN announcing the range | Yes, with a public registry lookup |
| ISP | Block allocated to a consumer ISP | Lease contract with the ISP, plus the routing announcement | Partly: the holder and announcement are public, the lease is not |
| Residential | Peer's home ISP connection | A consent record for each peer device | No: records are held by the provider and its partners |
| Mobile | Carrier-assigned address | A consent record per peer device, or the provider's own modem and SIM contracts | No, beyond identifying the carrier |
Datacenter: registry and ASN
Every IP block traces back through a regional internet registry to IANA's global number allocation. When a provider holds datacenter ranges in its own name and announces them from its own autonomous system, the provenance chain is two links long and public. You can confirm it with a registry query using the Registration Data Access Protocol; ARIN's RDAP documentation shows the lookup, and the other registries offer equivalents. If the registered holder or the announcing ASN is a third party, ask why.
ISP: lease plus announcement
ISP proxies, sometimes called static residential, are addresses allocated to consumer ISPs and leased to the provider, which hosts them on its own hardware. The public record shows the ISP as holder. What connects the ISP to the provider is a commercial lease, which you will not see without asking. A provider can usually confirm the lessor and show that the announcement matches the contract, under NDA if needed.
Residential and mobile: consent for each peer
Residential and mobile peer addresses belong to real people's connections. The registry tells you only which ISP or carrier holds the block, which is true of every subscriber on that network, consenting or not. The only thing that separates a legitimate peer from a compromised device is a record that the person agreed, knowingly, to carry third-party traffic. That record exists only if the provider and its partners created and kept it. This is why residential provenance is the hardest to verify and the most important to ask about.
What a provenance record contains
A provenance record is the document a provider returns when you name a specific address. For peer addresses, a useful record has at least these fields:
| Field | What it establishes |
|---|---|
| Pool | Which named pool the address serves, so the scope of any audit is unambiguous |
| Exit address and ASN | That the address is what was sold, on the network claimed |
| Acquisition channel | How the address entered the network, for example a consented SDK partner, a direct ISP lease, or an operated modem |
| Partner | Which partner application or supplier brought the peer in |
| Disclosure | What the peer was shown before joining, and where they can change their mind |
| Consent timestamp | When the peer agreed, and when that agreement was last reaffirmed |
| Compensation | That the peer received something in return |
| Attestation | The audit cycle in which that partner's records were independently reviewed |
| Withdrawal behavior | How quickly the address leaves rotation once consent is withdrawn |
Datacenter and ISP records are shorter: the range, the registry record or lease reference, and the announcing ASN. The test for any record is the same. Each field should point at something checkable, such as a document, a timestamp or a public registry entry, rather than restating a policy.
Why IP provenance became a procurement question in 2026
For most of the industry's history, buyers evaluated proxies on coverage, success rate and price, and sourcing was a line in the marketing copy. Three things changed that.
The first was enforcement. In July 2026, a top-tier residential provider was seized by federal authorities after its network was found to be built on compromised devices. Its customers lost service overnight and inherited questions about traffic that had run through victims' devices. The risk a residential proxy botnet passes to the buyer covers that exposure in detail.
The second was vendor risk practice catching up. Security questionnaires, privacy impact assessments and supplier codes of conduct increasingly ask where a supplier's inputs come from. For a proxy provider, the inputs are addresses.
The third was downstream pressure. Teams that sell data, or feed it into models, are asked how it was collected. "Through a proxy network whose sourcing we verified" is an answer; "through a proxy network" invites the next question.
The result is that provenance moved from the marketing page to the procurement file. Verifying a proxy provider's IP sourcing sets out the method most teams now use.
How to check IP provenance for addresses you already use
You do not need a new vendor to start. A short exercise against your current traffic:
- Export a sample of exit addresses from your own request logs, across pools and proxy types.
- For datacenter addresses, run a registry lookup and confirm the holder and announcing ASN match the provider.
- For residential and mobile addresses, send several to the provider and ask for the full record for each.
- Compare each record's acquisition channel against the provider's written supply-chain policy.
- Note any address the provider could not trace, and how long each answer took.
A provider with complete records can answer within days. One that cannot answer at all has told you something important.
How ProxyForge documents IP provenance
ProxyForge generates a provenance record on request for any address active in your pools. Our datacenter proxies use ranges registered to us and announced from our own ASN, so their provenance is checkable with a registry lookup before you contact us. ISP proxies are leased directly from consumer ISPs, and residential peers join through a disclosed, compensated and reversible opt-in via partner apps.
The sourcing page shows the full record schema with an example, and explains the twice-yearly independent audit that samples addresses and traces each one to its acquisition record.