< Back

Residential Proxy Provider Evaluation Checklist: Pool Size, Ethical Sourcing, and Uptime SLAs That Actually Matter

Tech

A data team signs an annual contract on the strength of a headline number: 80 million residential IPs, 195 countries, 99.9% uptime. Six weeks later the success rate against their primary target sits at 43%, the German pool recycles the same few hundred addresses every hour, and the support ticket asking for an SLA credit gets closed with a note explaining that the gateway was up the whole time, so nothing was breached.

Nothing in that story is fraud. Every claim on the marketing page was technically defensible. The problem is that the buyer evaluated the wrong metrics, in the wrong order, using definitions supplied by the seller.

This checklist is about fixing that. It covers how to interrogate pool size claims, what verifiable ethical sourcing actually looks like in a procurement conversation, and how to read an uptime SLA so you know what it does and does not protect. The goal is a repeatable evaluation you can run in a week and defend to whoever signs the purchase order.

Why Pool Size Is the Most Misleading Number in the Industry

Pool size is quoted because it is easy to quote. It is also the metric with the loosest definition anywhere in this market, and it correlates weakly with whether your jobs succeed.

Total historical IPs vs concurrently available IPs

Most large numbers describe IPs seen over some observation window, often 30 days or longer. Residential nodes are consumer devices: they go offline, change addresses, and leave the network. What matters for your workload is how many usable, distinct exit addresses are reachable at the moment your requests fire, in the location you need.

Ask directly: what is the average concurrently online pool, measured over the last 30 days, and how is "online" defined? A provider with operational maturity has this number. A provider that deflects to the headline figure is telling you something.

Country depth beats global country count

Coverage of 195 countries is close to meaningless if 90% of the pool sits in five markets. The relevant question is depth in your specific targets. If your work is retail price monitoring in Spain, Poland, and Brazil, you need per-country concurrent counts for those three markets, ideally broken down by city or region if your targets are geo-sensitive.

This is where many evaluations quietly fail. Aggregate performance looks fine because the test traffic defaulted to a deep pool such as the United States, while the markets that actually drive the project were thin all along.

ASN and subnet diversity

A pool of 50,000 IPs concentrated across a handful of autonomous systems behaves, from a defender's point of view, like a much smaller pool. Anti-bot systems increasingly score at the ASN and subnet level rather than the individual address. Ask how many distinct ASNs contribute to the country pools you care about, and whether the routing logic avoids issuing consecutive requests from the same /24.

Duplication and recycling behaviour

Run a simple experiment during your trial: issue several thousand requests through the rotating endpoint in a single country and count unique exit IPs. Then repeat an hour later and measure the overlap. High overlap means aggressive recycling, which shortens the effective life of any IP-based session and raises your ban exposure on sensitive targets.

Ethical Sourcing: What to Ask and What Proof Looks Like

Sourcing has moved from an ethics footnote to a genuine commercial risk. Enforcement actions against networks built on unwitting devices have shown that buyers inherit reputational and continuity exposure when the supply chain collapses. Your evaluation should treat sourcing as a compliance item, not a values statement.

Ask how consent is obtained. The credible answers are paid opt-in panels, clearly disclosed SDK integrations where the host application explains the exchange of value, or contracted ISP and carrier arrangements. Vague phrasing about a "partner ecosystem" without describing the consent mechanism should trigger follow-up questions.

Ask what the peer sees and controls. Can a participant see that traffic is being relayed, opt out at any time, and cap bandwidth? Providers who run genuine panels can describe the user experience in detail because they built it.

Ask about traffic and abuse controls on the exit side. Ethical sourcing is only half the picture. A network without category blocking, abuse reporting, and know-your-customer checks on buyers will accumulate poor IP reputation regardless of how the nodes were acquired, and you will feel that as degraded success rates.

Ask for documentation, not assurances. Reasonable artefacts include a written sourcing policy, the consent language shown to participants, a data processing agreement, evidence of GDPR and CCPA handling, and any third-party audit or penetration test summary. You are also entitled to know where logs live, what is retained, and for how long.

One practical signal: providers with defensible supply chains tend to publish sourcing detail without being asked, and they are comfortable naming the mechanism. Opacity at this stage rarely improves after the contract is signed.

Uptime SLAs vs Success Rate: Read the Definitions First

This is where most buyers get less protection than they think. An uptime SLA and a performance guarantee are different instruments, and the industry standard clause covers the first while your business risk lives in the second.

What uptime usually measures. Typically it means the availability of the gateway or API endpoint: whether the provider's front door accepts your connection. Under that definition, a network can serve you 60% failures on live targets while remaining perfectly compliant with a 99.9% uptime commitment.

What a success-rate commitment measures. A meaningful commitment defines success at the response level: which status codes count, whether CAPTCHAs and soft blocks are treated as failures, and whether the measurement is taken against the provider's own test endpoints or your production targets. Ask for the definition in writing. If the number is measured against neutral test URLs, it tells you about network plumbing, not about scraping a hardened e-commerce site.

Remedies and how you claim them. Credits are usually the only remedy, they are usually proportional to the affected period, and they usually require you to file within a short window with your own logs as evidence. Check three things: who bears the burden of proof, whether credits apply to bandwidth or to the monthly fee, and whether there is any exit right if the network misses targets over consecutive months. For projects with real revenue attached, a termination right after repeated misses is worth more than a 10% credit.

Support and escalation. Response-time commitments matter more than uptime percentages in day-to-day operation. Ask for the target first-response time on a production-down ticket, the coverage hours, whether you get a named contact above a certain spend, and how long a typical geo-pool degradation takes to resolve. Ask for a recent example.

Running a Trial That Predicts Production

A trial that only checks whether the proxy works is wasted. Design it to mirror the job you are buying for.

Use your real targets, your real concurrency, and your real geographies. Run for at least 72 hours across different times of day, because residential pools breathe with consumer device activity and evening peaks in a given country can look nothing like 4am. Log per-request status codes, latency percentiles (p50 and p95, not averages), unique exit IPs, and bandwidth consumed per successful record.

That last metric is the one procurement usually forgets. Cost per gigabyte is not comparable across providers unless you also know how many gigabytes each one burns to deliver the same dataset. A cheaper pool that returns more retries, more challenge pages, and heavier responses can be the more expensive option. During setup, quick endpoint checks with a proxy testing tool help you separate credential and configuration faults from genuine network performance issues before you start attributing failures.

Also test session control explicitly: request a sticky session, confirm the IP actually holds for the advertised duration, and check what happens when the underlying node drops mid-session. Silent rotation during a logged-in workflow is a common cause of mysterious account flags.

Red Flags Worth Walking Away From

  • Pool size quoted with no time window, no concurrency figure, and no per-country breakdown.
  • No written answer on how consent is obtained from residential peers.
  • An SLA that mentions uptime but never defines success at the response level.
  • Pricing that requires an annual commitment before any meaningful trial.
  • Support that cannot describe an escalation path or produce a recent incident timeline.
  • Reluctance to discuss what happens to your logs and target URLs.

Where Proxies Fit In

Every item above exists because proxy infrastructure sits directly on the critical path of the work it supports. When a pool is thin in a given country, market research reports come back skewed. When sourcing is questionable, capacity can vanish overnight. When session control is unreliable, multi-account and logged-in workflows generate flags that take weeks to unwind.

That is why the evaluation should focus on structural properties rather than headline claims: how the pool is built, how deep it goes where you operate, how peers were recruited, and how much control you have over rotation. Providers running ethically sourced residential proxy pools alongside ISP, datacenter, and mobile options give you something valuable in practice, which is the ability to match pool type to task without renegotiating a contract each time requirements shift.

EnigmaProxy positions itself in that professional tier: multiple pool types under one account, residential and premium tiers, granular geo-targeting, and session controls that let teams choose between rotation and persistence per job. For teams building a cost model before committing, transparent plan structures from EnigmaProxy make it easier to forecast spend against measured bandwidth per successful record rather than against an optimistic estimate.

The broader point stands regardless of vendor: business-grade reliability comes from a provider that can answer operational questions specifically, and that treats sourcing as documented practice rather than marketing language.

Strategic Insights: Where Provider Evaluation Is Heading

Sourcing disclosure becomes a procurement requirement. Enterprise legal teams are already adding supply-chain questions to vendor reviews for data collection tooling. Expect written sourcing statements and consent documentation to become standard attachments rather than special requests.

Performance guarantees shift from uptime to outcomes. As buyers get more sophisticated, the pressure is on providers to commit to measurable success rates against defined target classes. Contracts that specify how success is counted will differentiate serious suppliers from the rest.

Detection moves further up the stack. With scoring increasingly based on ASN reputation, TLS fingerprints, and behavioural signals, raw IP volume matters less each year. Diversity, reputation hygiene, and clean routing will carry more weight in evaluations than pool totals.

Observability becomes a differentiator. Teams running data pipelines at scale want per-request telemetry, per-country success dashboards, and alerting on pool degradation. Providers who expose that data make themselves easier to trust and easier to keep.

Conclusion

A good provider evaluation replaces vendor-supplied numbers with your own measurements. Treat pool size as a question about concurrent availability and country depth, treat ethical sourcing as a documentation exercise with named consent mechanisms, and read the SLA for what it defines rather than what it promises. Then run a trial against your real targets, at your real concurrency, and measure bandwidth per successful record rather than cost per gigabyte in isolation.

Do that work once and it pays back on every renewal, because you end up with a scoring framework instead of a hunch. Providers such as EnigmaProxy that can speak to pool composition, geo-coverage, and sourcing in specific terms tend to make that framework straightforward to apply, which is usually a fair indicator of how the relationship will run after the contract is signed.