[Residential Proxies]
Which Residential Proxy Providers Actually Verify Consent in 2026?
After the FBI seized NetNut in July 2026, 'ethically sourced' became the most abused claim in the proxy industry. This guide compares what eight residential proxy providers actually commit to on their official pages — documented consent mechanisms, KYC policies, and abuse controls — versus who just says the words.
TL;DR: Every residential proxy provider claims "ethically sourced"; few document it. The FBI's July 2026 seizure of NetNut — a network Google tied to 2M+ non-consenting devices — proved the label can be empty. Of the eight providers reviewed here, only Bright Data, IPRoyal, Decodo, and Oxylabs publish verifiable consent and KYC commitments; the rest use the phrase without documenting how.
"Ethically sourced" residential proxies should mean the device owner consented, understands the traffic, gets compensated, and can opt out. In practice, every residential proxy provider claims ethical sourcing. Almost none define what they mean by it. The FBI's seizure of NetNut's domains on July 2–3, 2026 exposed the gap: Google's Threat Intelligence Group identified NetNut's network — also known as PoPa — as an estimated 2 million-device botnet, with SDKs distributed through smart-TV and streaming apps. Alarum Technologies, NetNut's parent company, disputes the botnet characterization and says it is investigating possible third-party misuse.
This is now the second FBI-backed residential proxy takedown in six months, following the January 2026 seizure of IPIDEA and thirteen affiliated storefront brands. The pattern changes how buyers should evaluate the market. This guide compares what eight residential proxy providers' official pages actually commit to — documented consent mechanisms, KYC policies, and abuse controls — as reviewed on July 9, 2026.
For pricing and rankings across these same networks, see the companion guide to the best residential proxy providers in 2026.
What Should "Ethically Sourced" Actually Mean for Residential Proxies?
Ethically sourced proxies should require informed device-owner consent, SDK disclosure, fair compensation, and an accessible opt-out mechanism.
The phrase "ethically sourced" appears on nearly every residential proxy provider's website. It has no industry-standard definition, no certification body, and no enforcement mechanism. After the NetNut seizure, defining it matters because buyers need criteria that distinguish real commitments from empty copy.
A defensible ethical-sourcing program includes four components:
- Informed consent UX. The device owner sees a clear prompt explaining that their bandwidth will be shared, what traffic may pass through, and who operates the network. Synthient researchers analyzed more than 20 PoPa publisher apps and found none presenting a consent prompt — the absence of this single element defined the enforcement line.
- Compensation and disclosure. The user receives payment or a service benefit in exchange for bandwidth. The app or SDK identifies the proxy network operator and its terms of service.
- Opt-out mechanism. The user can revoke consent and stop sharing bandwidth at any time, without losing access to the host app's core features.
- SDK transparency. The proxy operator discloses which apps and device categories carry its SDK. Smart-TV and streaming-box apps merit extra scrutiny — Google's action specifically targeted SDKs in those categories.
No residential proxy provider publishes a consent UX audit by an independent third party. The best available evidence is what providers commit to on their own policy pages. The worst available evidence is a homepage badge that says "ethically sourced" with no supporting documentation.
In short: ethical sourcing requires a consent prompt, compensation, opt-out, and SDK disclosure at minimum. No provider offers independent third-party verification. The gap between what providers publish and what they practice is exactly where enforcement has landed twice in 2026.
Which Providers Document Specific Consent and KYC Commitments?
Bright Data, IPRoyal, Decodo, and Oxylabs publish verifiable ethical-sourcing commitments on their official pages — each with different depth.
These four providers go beyond the phrase "ethically sourced" and describe how consent works, what KYC applies, or both. The commitments vary in depth and verifiability.
Bright Data — The Most Detailed Compliance Stack
Bright Data's residential product page states its 400M+ residential IPs are sourced from peers who have "explicitly agreed to participate." That is a specific consent claim tied to its named bandwidth-sharing program.
On the KYC side, Bright Data made a major policy change effective July 7, 2026: new residential proxy zones now require human-reviewed KYC and are available to verified companies only. No automatic or instant access. KYC may require business details, use-case description, company registration documents, government ID, or a video call depending on risk review. Residential traffic is monitored 24/7 and scoped to the KYC-approved use case.
Bright Data also holds ISO 27001 and SOC 2/3 certifications — compliance infrastructure nobody else in this guide matches.
What it means for buyers: Bright Data publishes the most detailed compliance stack here. The July 7 KYC change adds meaningful friction — which is exactly the point. The trade-off is an $8/GB list price (currently halved by a three-month promo).
IPRoyal — Named First-Party App and Three-Stage KYC
IPRoyal's residential proxy sourcing page specifically names Pawns.app as a direct partner through which users share internet bandwidth, allowing their devices to become residential proxy endpoints. Naming the app matters — it is a verifiable, first-party claim.
IPRoyal's KYC policy describes a three-stage process: pre-purchase checks evaluating IP address, email, and other data against fraud risk; purchase-stage identity verification for unrestricted access; and post-purchase automated monitoring for Acceptable Use Policy compliance. The AUP is Version 5, effective June 30, 2026.
IPRoyal states it does not monitor customer activity directly but that automated systems report suspicious requests and actions. Its sourcing page describes checks including manual and automated reviews, data verification, and monitoring.
What it means for buyers: IPRoyal is the only provider here that names a specific first-party bandwidth-sharing app on its sourcing page. The three-stage KYC is documented. The caveat is that it describes post-purchase monitoring as an "absolute minimum" of data — less aggressive than Bright Data's use-case-scoped access.
Decodo — EWDCI Membership and Partner Verification
Decodo's ethical sourcing page states it is an EWDCI (Ethical Web Data Collection Initiative) member and sources residential proxies ethically and sustainably, emphasizing transparency, user privacy, and a fair ecosystem. Decodo says it partners with providers that verify users willingly participate and understand the data collection involved.
Decodo's buy page confirms a KYC process designed to maintain a clean proxy pool, prevent fraudulent use, and maintain IP reputation quality, described as completable within minutes.
Proxyway's Proxy Market Research 2026 independently measured Decodo's global residential pool at a 2.60 average risk score on Scamalytics, against a 3.47 average computed from the published scores of all 13 providers tested — among the lowest in the benchmark. Low risk scores don't prove ethical sourcing, but they correlate with cleaner IP pools.
What it means for buyers: EWDCI membership is a named, verifiable commitment. Decodo describes partner-level verification rather than a first-party consent app. The Proxyway risk-score data provides independent quality evidence, though it measures output (IP cleanliness) rather than input (consent).
Oxylabs — Risk-Team Review and Compliance Audits
Oxylabs' KYC and safety page states every customer must fill out a KYC form capturing methodology of use, planned use case, necessary documentation, and possible additional risk-team requests. Oxylabs says compliance teams review customer activity regularly and automated internal systems detect suspicious behavior.
Its risk and legal compliance page says Oxylabs relies on certifications, internal governance, KYC procedures, and ethical sourcing standards to promote lawful and responsible use and cooperate with authorities.
What it means for buyers: Oxylabs describes a customer-facing compliance process with risk-team oversight. The gap: its official pages don't detail the device-owner consent mechanism — how residential IPs are recruited and what SDK participants see. The customer KYC is strong; the sourcing-side documentation is thinner than Bright Data's or IPRoyal's.
In short: these four providers publish specific mechanisms — Bright Data's peer consent and human-reviewed KYC, IPRoyal's named Pawns.app and three-stage KYC, Decodo's EWDCI membership and partner verification, and Oxylabs' risk-team review. Each is verifiable from their public pages. None offers third-party consent auditing.
Which Providers Claim "Ethically Sourced" Without Documenting How?
Webshare, Infatica, and DataImpulse use the phrase on official pages but do not document a consent mechanism or sourcing policy.
This is not an accusation. It is a gap in public documentation. A provider may operate an ethical sourcing program internally and simply not publish it. But after two FBI seizures in six months, unpublished means unverifiable — and unverifiable is a risk buyers should price in.
Webshare
Webshare's Germany residential proxy page describes its pool as "80M+ ethically sourced Residential IPs." No dedicated KYC, consent, or residential sourcing policy page was found in the review conducted on July 9, 2026. The phrase appears as marketing copy, not as a link to a documented process.
Infatica
Infatica's residential product page and multiple other pages repeatedly use "Ethically-sourced proxies" as a feature label. No detailed residential sourcing, opt-in mechanism, KYC, or acceptable-use policy was captured from official pages in this review. The 35M+ IP pool is marketed as ethically sourced without a published explanation of what that means.
DataImpulse
DataImpulse's official blog describes the provider as offering "first-party ethical IPs" in its comparative provider content. No dedicated KYC, KYB, acceptable-use, or residential end-user consent page was captured from DataImpulse's official pages in this review.
In short: these three providers claim ethical sourcing but do not publish the mechanism, policy, or KYC process on the pages reviewed July 9, 2026. Buyers should ask them directly for sourcing documentation before committing.
Where Does Proxidize Sit on Ethical Sourcing?
Proxidize claims ethical sourcing with scoped KYC, but the detailed ethics-page text was not captured — placing it between the two tiers.
Proxidize's residential product page and free signup page both state its residential IPs are "ethically sourced" across 195+ countries. The managed cloud proxy service — not self-hosted — is positioned as a consent-based operation.
The pricing FAQ adds specificity: KYC is required only for users who need to access financial, HR, or transactional websites. For web scraping, SEO monitoring, and other non-financial use cases, no KYC is needed. Adult industry sites and .gov domains are prohibited.
An ethics page exists and was reachable on July 9, 2026, but the detailed text was not fully captured in this review. This means the full consent mechanism, SDK disclosure, and opt-in flow may be documented there — but this guide cannot confirm what it says.
What it means for buyers: Proxidize sits in a middle position. It makes ethical-sourcing claims more specific than Webshare, Infatica, or DataImpulse — it names the product category, describes a KYC scope, and publishes an ethics page. But it falls short of Bright Data's peer-consent detail or IPRoyal's named first-party app. Buyers should read the ethics page directly and ask for the consent mechanism in writing.
In short: Proxidize claims ethical sourcing with more specificity than the undocumented providers and less detail than the market leaders. Its KYC is scoped to sensitive target categories. The ethics page exists but needs direct review for the full consent commitment.
How Does the NetNut Seizure Prove "Ethically Sourced" Can Be an Empty Label?
NetNut was marketed as legitimate. Google identified it as a 2M+ device botnet via smart-TV SDKs distributed without meaningful consent.
The facts, attributed to primary sources:
- Google asserts: On July 2, 2026, Google's Threat Intelligence Group announced coordinated action with the FBI, Lumen, and others against the NetNut residential proxy network, "also known as PoPa." Google estimated the network at at least 2 million devices worldwide. In a single week in June 2026, Google observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups.
- Researchers found: Synthient analyzed more than 20 PoPa publisher apps and observed none presenting a user-consent prompt. Lumen's Black Lotus Labs estimated PoPa averaged 1.5–2.5 million distinct IP addresses per day. Nokia Deepfield monitored 26 of at least 359 relay nodes and saw 750,000 unique sources in 24 hours on that subset alone.
- Alarum disputes: Alarum Technologies rejected the botnet characterization, saying its SDKs were for bandwidth sharing and did not compromise devices. Alarum said NetNut maintained KYC, due diligence, and misuse-monitoring procedures.
- Domains seized: As of July 9, 2026, netnut.io, netnut.com, and dashboard.netnut.io all display FBI seizure pages. Alarum paused traffic through affected network services and disclosed a material adverse effect on operations.
The lesson for buyers is not that NetNut was uniquely bad. It is that a provider's marketing page is not evidence of its practices.
In short: NetNut claimed legitimate residential proxy sourcing. Google and multiple security firms tied its network to 2M+ non-consenting devices via smart-TV SDKs. Alarum disputes the characterization. The seizure is the strongest evidence to date that the "ethically sourced" label requires verification, not trust.
Why Is Reseller Opacity the Proxy Industry's Core Ethical Risk?
Google stated on July 2, 2026 it had "high confidence" many popular residential proxy brands white-labeled NetNut's botnet — and did not name them.
This is the structural risk the NetNut seizure exposed. The residential proxy market is not a collection of independent networks. It is a layered reseller ecosystem where most retail brands sit on top of a small number of upstream suppliers.
Three data points frame the problem:
- Google's white-label warning. Google's Threat Intelligence Group said NetNut had a "robust reseller/white-label program" and that it had high confidence many popular brands white-labeled NetNut capacity. No names were published.
- Market concentration. The Global Cyber Alliance's June 2026 workshop report described roughly 200+ retail proxy brands sitting on a handful of upstream suppliers, with approximately 6–8 relay operators above the device layer. Proxyway's June 30, 2026 market research reached a similar count — only about 10–15 companies run their own networks, and around half of those overlap in sources.
- The IPIDEA precedent. The January 2026 IPIDEA takedown seized thirteen affiliated storefront brands alongside the main network. Buying from a storefront provided no protection because the storefronts shared the seized infrastructure.
For buyers, this means brand reputation alone is not enough. A provider that resells capacity from an unnamed upstream source carries the same risk as that source — and the source could be the next network seized.
In short: Google's white-label warning, market concentration data, and the IPIDEA precedent show that most proxy brands depend on a few upstream networks. Reseller opacity hides sourcing risk. Asking whether capacity is first-party or bought upstream is the single most important due-diligence question.
How Do Documented Ethical Commitments Compare Across Providers?
The table below compares what each provider's official pages commit to on consent, KYC, and abuse controls — reviewed on July 9, 2026.
| Provider | Consent Mechanism Documented | KYC / Abuse Controls Documented | Gaps |
|---|---|---|---|
| Bright Data | Peers explicitly agreed to participate | Human-reviewed KYC for verified companies only (July 7, 2026); use-case-scoped access; 24/7 monitoring; ISO 27001, SOC 2/3 | None major — the most detailed |
| IPRoyal | Named first-party app Pawns.app; users share bandwidth to become endpoints | Three-stage KYC (pre-purchase, purchase, post-purchase); AUP v5 effective June 30, 2026; automated monitoring | Describes post-purchase monitoring as "absolute minimum" data |
| Decodo | EWDCI member; partners verify users willingly participate | KYC process to maintain pool quality and prevent fraud | No first-party consent app named; partner-level verification |
| Oxylabs | Risk/compliance page references ethical sourcing standards | KYC form for all customers; risk-team review; regular compliance audits; automated detection | Device-owner consent mechanism not detailed on public pages |
| Proxidize | Product pages say ethically sourced | KYC required for financial/HR/transactional targets only; adult and .gov excluded | Ethics page not fully captured; consent mechanism not detailed |
| Webshare | "Ethically sourced" label on location pages | Not documented on reviewed pages | No sourcing policy, KYC, or consent mechanism found |
| DataImpulse | "First-party ethical IPs" in blog content | Not documented on reviewed pages | No sourcing policy, KYC, or consent mechanism found |
| Infatica | "Ethically-sourced proxies" on product pages | Not documented on reviewed pages | No sourcing policy, KYC, or consent mechanism found |
What Should Buyers Ask Before Committing to Any Provider?
Buyers should ask every provider for a written sourcing attestation — naming the consent app, compensation, and device categories.
The NetNut seizure stranded customers mid-project with no refund path, no billing access, and no migration plan. The IPIDEA takedown six months earlier did the same. Both times, the providers marketed themselves as legitimate services. A due-diligence process protects against that specific failure mode.
The Sourcing Attestation Checklist
Ask your provider these questions in writing. A provider with genuine consent-based sourcing will answer them readily.
- What is the consent mechanism? Name the app, SDK, or program through which device owners opt in. Describe the consent prompt they see.
- How are users compensated? What do device owners receive in exchange for sharing bandwidth?
- Which device categories carry the SDK? Specifically: does any capacity originate from smart-TV apps, streaming-box apps, or firmware-level integrations? These were the categories targeted in both the IPIDEA and NetNut enforcement actions.
- Is the capacity first-party or resold? Does the provider operate the bandwidth-sharing program directly, or does it buy capacity from upstream suppliers? If resold, name the suppliers.
- What abuse controls exist? Describe the KYC process, use-case restrictions, and monitoring for prohibited traffic.
- Can users opt out? Describe the opt-out mechanism for device owners and confirm it does not remove access to the host app's core features.
Red Flags
- The provider changes the subject to pool size, country coverage, or pricing when asked about sourcing.
- The answer is "we work with trusted partners" with no named partners.
- The term "ethically sourced" appears only as a badge, not as a link to a policy page.
- The provider cannot confirm whether its pool includes any NetNut, PoPa-linked, or IPIDEA-linked capacity.
In short: ask for the consent app name, the compensation model, the device categories, and whether capacity is first-party or resold. Get the answers in writing. Providers with genuine programs answer these questions on their public pages already — the ones that don't should explain why not.
How Does Residential Proxy Pricing Compare for Ethically Verified Providers?
Pricing for providers with documented ethical commitments alongside those without, all verified on live pricing pages on July 7–9, 2026.
For a full pricing breakdown, see the residential proxy pricing guide.
| Provider | Entry $/GB | Ethical Documentation Level | Pool Size |
|---|---|---|---|
| Proxidize | $1 (flat) | Medium — claims + scoped KYC, ethics page not fully captured | "Millions," 195+ countries |
| DataImpulse | $1 | Minimal — "first-party ethical IPs" in blog copy only | 90M+ |
| Decodo | $3.75 | Strong — EWDCI member, partner verification, KYC | 115M+, 195+ locations |
| Infatica | $4 | Minimal — label only, no policy documented | 35M+ |
| Oxylabs | $6 | Strong — KYC for all customers, risk-team review | 175M+ (third-party cited) |
| IPRoyal | $7.35 | Strong — named app Pawns.app, three-stage KYC, AUP v5 | 32M+, 195+ countries |
| Bright Data | $8 (list) | Most detailed — peer consent, human-reviewed KYC, ISO/SOC | 400M+, 195 countries |
| Webshare | ~$1.40–$7 (conflicting) | Minimal — label only, no policy documented | 80M+ |
In short: documented ethical sourcing currently correlates with higher pricing. Bright Data ($8/GB list), IPRoyal ($7.35/GB), and Oxylabs ($6/GB) charge premium rates and publish the most detailed compliance commitments. The $1/GB tier offers less documented sourcing verification.
The Verdict: What Has the NetNut Seizure Changed for Proxy Buyers?
Two FBI takedowns in six months proved that "ethically sourced" requires verification. Demand written sourcing attestations, not badges.
- "Ethically sourced" is now a verifiable claim, not a marketing badge. Two FBI-backed takedowns in six months — IPIDEA in January and NetNut in July 2026 — established that residential proxy networks with tainted sourcing get seized. Buyers who don't verify sourcing are betting their operations on a provider's marketing page.
- Bright Data publishes the most detailed compliance stack in the residential proxy market: peer consent, human-reviewed KYC effective July 7, 2026, use-case-scoped access, ISO 27001, and SOC 2/3 certifications.
- IPRoyal is the only provider here that names a first-party consent app — Pawns.app — on its sourcing page, with a three-stage KYC process and an AUP updated June 30, 2026.
- Decodo (EWDCI member), Oxylabs (risk-team review), and Proxidize (scoped KYC) provide verifiable commitments with less device-owner detail than Bright Data or IPRoyal — Proxidize's ethics page needs direct review.
- Webshare, Infatica, and DataImpulse use the phrase without publishing a mechanism. This is a documentation gap, not proof of wrongdoing — but it is a gap buyers should close before committing.
- Reseller opacity is the industry's core risk. Google's warning that many brands white-labeled NetNut means every buyer should ask whether capacity is first-party or resold, and get the answer in writing.
- The due-diligence checklist matters more than any ranking. Ask for the consent app, the compensation model, the device categories, and the reseller chain. Providers with genuine programs publish these answers. Providers without them change the subject.
In short: verify sourcing in writing — the label alone proved worthless twice in 2026.
For full pricing, rankings, and feature comparisons across these same nine networks, see the best residential proxy providers in 2026.
Frequently asked questions
- What does 'ethically sourced' mean for residential proxies?
- Ethically sourced means the device owner gave informed consent to share bandwidth, understands what data routes through their connection, receives compensation, and can opt out at any time. A consent-based app or SDK with clear disclosure is the minimum mechanism. The July 2026 NetNut seizure showed that the label alone guarantees nothing without a verifiable process.
- Which proxy providers have documented consent mechanisms?
- As of July 9, 2026, Bright Data documents that peers explicitly agree to participate and requires human-reviewed KYC. IPRoyal names its first-party app Pawns.app and publishes a three-stage KYC process. Decodo is an EWDCI member and says partners verify willing participation. Oxylabs describes risk-team review and regular compliance audits on its official pages.
- Is it legal to use residential proxies in 2026?
- Residential proxies remain legal when IPs are sourced with informed user consent and used for lawful purposes. The 2026 FBI actions against IPIDEA in January and NetNut in July targeted networks tied to non-consensual device enrollment — not the product category itself. Buyers should verify sourcing documentation before committing to any provider.
- What happened to NetNut in July 2026?
- The FBI seized NetNut's domains on July 2–3, 2026. Google's Threat Intelligence Group identified the network as PoPa, estimated it at 2 million-plus devices, and reported 316 threat clusters using its exit nodes in a single June week. Parent company Alarum paused network traffic and disclosed a material adverse effect on operations.
- How do I know if my proxy provider resells NetNut capacity?
- Ask your provider in writing whether any portion of its residential pool originates from NetNut, PoPa-linked infrastructure, or unnamed third-party bandwidth-sharing SDKs. Google stated on July 2, 2026 it had high confidence many popular proxy brands white-labeled NetNut. Providers with genuine first-party sourcing will name their consent app and document the opt-in flow.
- Why did the FBI seize NetNut?
- Google's Threat Intelligence Group said NetNut's residential proxy network, also known as PoPa, distributed SDKs through smart-TV and streaming apps to enroll devices without meaningful consent. Researchers at Synthient analyzed more than 20 PoPa publisher apps and found none presenting a consent prompt. Alarum disputes the botnet characterization.
- What is the safest way to buy residential proxies after the NetNut seizure?
- Demand a written sourcing attestation naming the consent app or SDK, the opt-in flow, user compensation terms, and whether capacity is first-party or bought from resellers. Run a trial, verify IP ASN classification, and ask specifically whether any pool component uses smart-TV or streaming-app SDKs. Brand reputation alone proves nothing.
- Does Proxidize verify consent for its residential proxies?
- Proxidize's product pages state its residential IPs are ethically sourced across 195-plus countries, and its pricing FAQ describes KYC requirements scoped to sensitive target categories like financial and HR sites. However, the detailed ethics-page text was not captured in the review conducted on July 9, 2026, so the full consent mechanism is not documented here.
Related guides
- [Residential Proxies]July 27, 2026
What Do Residential Proxies Cost Per GB in 2026?
Seven residential proxy providers compared on real list price — entry rates, full tier ladders, cost at 100GB and 1TB, expiry rules, and the minimums that inflate the effective rate. Every figure read from official pricing pages on July 26, 2026.
Read the review - [Residential Proxies]July 23, 2026
What Are the Best Residential Proxies for Web Scraping in 2026?
Seven residential proxy providers ranked for web scraping by per-GB cost at real crawl volumes, pool size, and session control — every rate read from official pricing pages on July 23, 2026. Proxidize leads on scraping economics at a flat $1/GB with non-expiring bandwidth.
Read the review