Proxy Anonymity Levels: Transparent, Anonymous, Distorting and Elite Proxies Explained

Proxy guide · Last reviewed 1 October 2026 · 13 min read

Proxy anonymity levels describe how much a proxy tells the website about you. A transparent proxy passes your real IP address along in a request header, an anonymous proxy hides your IP but admits it is a proxy, a distorting proxy hides your IP behind a made-up one, and an elite proxy sends no proxy headers at all. This guide shows exactly which headers each level sends, how to test your own proxy with one curl command, and why the header level is only part of staying hidden. For the wider picture of how anonymous proxies hide your IP, see our companion explainer.

The short version

The level is decided by three headers: Via, X-Forwarded-For and Forwarded. Transparent proxies put your real IP in them, anonymous and distorting proxies announce a proxy without your real IP, and elite proxies send none of them. Test it by requesting a plain-HTTP header echo through the proxy. Then remember that headers are only the first check: websites also look at what kind of IP you connect from, your browser fingerprint, and WebRTC and DNS leaks.

What are proxy anonymity levels?

A convention, not a standard

Every proxy sits between you and the website. The website always sees the address the proxy connects from; that part never changes. What does change is what the proxy adds to your request on the way through. Some proxies write your original IP address into a header, some write a note saying a proxy was involved, and some add nothing. The anonymity level is simply a label for which of those things happens.

No standards body defines the levels. Proxy anonymity levels come from proxy lists and proxy checkers, which grade proxies by the headers they see. The usual numbering runs backwards, with level 1 as the most anonymous:

LevelHides your IP?Reveals a proxy?Typical use
Level 1: eliteYesNot in headersPrivacy, data collection, testing from other locations
Level 2: anonymousYesYesBasic privacy where being seen as a proxy is fine
DistortingYes, replaced with a fake IPYesRare; mostly a label on free proxy lists
Level 3: transparentNoYesCaching, filtering and access control on networks

Distorting proxies are sometimes counted as a kind of anonymous proxy and sometimes listed on their own. Either way, they sit between levels 2 and 1: your real address is hidden, but the request still announces that it passed through a proxy.

Key takeaways

  • The website always sees the proxy’s IP as the connecting address. The level is about what the proxy adds on top.
  • Transparent: your real IP in X-Forwarded-For or Forwarded. Anonymous: a proxy header without your IP. Distorting: a fake IP. Elite: no proxy headers.
  • Test over plain HTTP. On HTTPS through a normal tunnel, the proxy can’t add headers at all.
  • An elite header profile doesn’t make a datacenter IP look residential, and it doesn’t stop WebRTC or DNS leaks.

The headers that give a proxy away

Via, X-Forwarded-For, Forwarded and Proxy-Connection

Four request headers do almost all the work when a checker grades a proxy. Each has a legitimate job, which is why ordinary proxies send them by default.

Via

Via records the intermediaries a request passed through, similar to the Received lines in an email. RFC 9110, the core HTTP specification, says a proxy must send an appropriate Via header in each message it forwards, and gives Via: 1.0 fred, 1.1 p.example.net as an example. It lets the proxy replace its real host name with a pseudonym, but the header itself still tells the website a proxy was used. Via doesn’t carry your IP address; it reveals the proxy, not you.

X-Forwarded-For

X-Forwarded-For (XFF) lists the address of the client that sent the request, followed by any proxies it passed through: X-Forwarded-For: client, proxy1, proxy2. MDN describes it as a de facto standard that is not part of any current specification. It is the header that leaks your real IP on a transparent proxy. MDN also warns that any part of it not added by a trusted proxy may be spoofed, which is exactly what a distorting proxy does.

Forwarded

Forwarded is the standardised replacement, defined in RFC 7239 in 2014. It carries the same information in named parameters, for example Forwarded: for=192.0.2.43;proto=http. The RFC treats the client’s IP address as privacy-sensitive, recommends that proxies use obfuscated identifiers such as for=_hidden by default, and allows for=unknown when the proxy wants to signal forwarding without identifying the client. MDN notes that it is used much less often than X-Forwarded-For.

Proxy-Connection

Proxy-Connection is different: your browser or client sends it, not the proxy. It was an old attempt to manage keep-alive connections with proxies. RFC 9112 calls it unworkable and encourages clients not to send it, and RFC 9110 lists it among the fields a proxy should remove before forwarding. If a website receives Proxy-Connection, a proxy passed your client’s proxy-only header straight through without cleaning it, which is a strong hint that a proxy is in the path.

Checkers also look for non-standard fields such as X-Real-IP and Client-IP, and at the connecting address itself. On a web server that address is often shown as REMOTE_ADDR, and header values appear with an HTTP_ prefix, such as HTTP_X_FORWARDED_FOR and HTTP_VIA. That naming comes from the CGI specification, RFC 3875, which is why older proxy checkers print it.

Which headers each level sends

What the website receives

The table shows how the proxy anonymity levels differ, header by header. In it, 203.0.113.7 stands for your real address, 198.51.100.20 for the proxy and 192.0.2.99 for a made-up address. All three come from ranges reserved for documentation.

HeaderTransparentAnonymousDistortingElite
Connecting IP (REMOTE_ADDR)Proxy: 198.51.100.20Proxy: 198.51.100.20Proxy: 198.51.100.20Proxy: 198.51.100.20
ViaUsually sentUsually sentUsually sentNot sent
X-Forwarded-ForYour IP: 203.0.113.7Absent, “unknown” or the proxy’s own IPA fake IP: 192.0.2.99Not sent
Forwardedfor=203.0.113.7Absent, for=unknown or for=_hiddenfor=192.0.2.99Not sent
Proxy-ConnectionSometimes passed throughSometimes passed throughSometimes passed throughRemoved
Website learnsYour IP and that you use a proxyThat you use a proxyThat you use a proxy, plus a false IPOnly the proxy’s IP
Figure 1 — the same request, as it arrives from each kind of proxy
# Transparent (level 3)
Via: 1.1 proxy.example
X-Forwarded-For: 203.0.113.7

# Anonymous (level 2)
Via: 1.1 proxy.example
X-Forwarded-For: unknown

# Distorting
Via: 1.1 proxy.example
X-Forwarded-For: 192.0.2.99

# Elite (level 1)
(no Via, X-Forwarded-For, Forwarded or Proxy-Connection)

These are configuration choices, not different kinds of hardware. The Squid proxy’s documentation shows it plainly: its forwarded_for setting defaults to on, which appends the client’s IP to X-Forwarded-For, and its via setting is on by default too. A Squid server left on defaults is therefore a transparent proxy by this grading. Setting forwarded_for off sends X-Forwarded-For: unknown, the anonymous pattern, while forwarded_for delete together with via off removes both headers. Squid notes that turning Via off needs a build with HTTP violations enabled, because the specification requires it.

Transparent proxies (level 3)

Your IP, passed along on purpose

A transparent proxy in the anonymity sense forwards your request and tells the website who you are. It adds Via, and it puts your real address in X-Forwarded-For or Forwarded. That isn’t a fault. Caches, load balancers and company gateways send those headers so the server behind them can still log, rate-limit or geolocate the real client. For privacy, though, a transparent proxy offers nothing: the website gets your IP either way.

The word “transparent” also has a second, unrelated meaning. RFC 9110 uses “transparent proxy” as the common name for an interception proxy: one that the network forces your traffic through without you configuring anything, as found on public Wi-Fi portals and inside corporate firewalls. An interception proxy may or may not forward your IP in headers. If you came here for that meaning, filtering and caching on a network, read our guide to the transparent proxy.

Lists of the “best transparent proxies” mix the two meanings up. Nobody buys a transparent proxy to hide an IP, because it is designed not to. Organisations run them to cache content, filter sites, enforce login on public networks and log usage, and they usually build them from proxy software or firewalls rather than rent them from a proxy provider.

Anonymous proxies (level 2)

Your IP hidden, the proxy visible

An anonymous proxy keeps your real address out of the headers but still signals that it exists. The website sees a Via header, or an X-Forwarded-For with “unknown” or the proxy’s own address, or a Forwarded header with for=unknown. Your IP is safe from that request, but the site knows it is talking to a proxy.

Whether that matters depends on the site. Many sites don’t care. Others treat any proxy signal as a reason to add a CAPTCHA, limit features or refuse the request. For casual privacy an anonymous proxy is fine; for work where you need to look like an ordinary visitor, the proxy header itself becomes the problem.

Distorting proxies, explained honestly

A fake IP in a real proxy header

A distorting proxy hides your address by writing a false one into X-Forwarded-For or Forwarded, while usually still sending Via. The idea is that a website which trusts the header will log, geolocate or rate-limit the fake address instead of yours.

In practice that buys very little:

  • It still announces a proxy. Via or a forwarding header is present, so the site knows a proxy is involved, exactly as with an anonymous proxy.
  • Careful sites don’t trust the header anyway. MDN’s guidance is to use only the addresses added by proxies you trust, because anything else in X-Forwarded-For can be spoofed. A site following it looks at the connecting IP, which is the proxy’s.
  • A fake address can be a signal. An X-Forwarded-For entry pointing somewhere unrelated to the connecting IP is itself unusual, and the fake address may belong to someone else.
  • It is not a product category. Commercial residential, mobile and datacenter providers sell IP types and targeting, not “distorting” headers. The label comes from free proxy lists and checkers.

Some articles describe distorting proxies as proxies that change your User-Agent, cookies or fingerprint. That isn’t what the term means in proxy grading; it only refers to a false client IP in forwarding headers. Changing a User-Agent or fingerprint is done by the client, for example an anti-detect browser, not by the proxy level.

If your goal is to hide your IP, an elite proxy does the job more cleanly: no fake address to explain and no proxy header to trigger a check. The standards-friendly version of what a distorting proxy tries to do is RFC 7239’s obfuscated identifier, for=_hidden, which hides the client without inventing a false address.

Elite and high-anonymity proxies (level 1)

No proxy headers at all

An elite proxy, also called a high-anonymity proxy and sometimes a hidden proxy, removes every trace of itself from the request. There is no Via, no X-Forwarded-For, no Forwarded and no Proxy-Connection. The website sees a request that looks like it came straight from the proxy’s IP address, with nothing saying another client is behind it.

That is the level you want for privacy, for data collection at scale, for checking prices and ads from other countries, and for any task where you need to look like an ordinary visitor. It is worth being clear about what this involves: RFC 9110 says a proxy must send Via, so an elite proxy deliberately departs from the specification to protect the client. That is normal for commercial proxy services, whose whole purpose is to present a different IP.

The limit is that elite only describes headers. The website can still see what kind of network the proxy’s IP belongs to, and your browser can still give you away. The sections below cover both. If you are choosing a provider, our comparison of the best high anonymity proxy services ranks them on IP type, targeting and price.

How to test your proxy’s anonymity level

One curl command and a header echo

A header echo service returns the request it received, so you can see exactly what your proxy added. httpbin.org is a common one, but it has a detail that trips people up: by default its /headers page hides Via, X-Forwarded-For and a few other fields that its own hosting adds. Its source code lists them and only shows them when you add ?show_env=1 to the URL. Without that, every proxy looks elite.

Figure 2 — testing a proxy with curl and httpbin.org
# 1. Baseline: your own connection, no proxy
curl -s "http://httpbin.org/headers?show_env=1"

# 2. The same request through the proxy (plain HTTP, so the proxy can add headers)
curl -s -x http://USERNAME:PASSWORD@proxy.example:8080 "http://httpbin.org/headers?show_env=1"

# 3. The address the site reports for you
curl -s -x http://USERNAME:PASSWORD@proxy.example:8080 "http://httpbin.org/ip"

curl’s -x (or --proxy) option takes the proxy as protocol://host:port, with an optional user name and password; add -v to see the request curl actually sends. For a ProxyEmpire residential or mobile proxy, the host is v2.proxyempire.io, the port is 5000, and the user name and password come from your dashboard. Our guide to using curl with a proxy covers the other options.

How to read the result

  1. Find the last address in X-Forwarded-For. When we tested on 1 October 2026, httpbin’s own infrastructure appended the address that connected to it to the end of X-Forwarded-For. Through a proxy, that last entry should be the proxy’s exit IP.
  2. Look at anything before it. If your real address from step 1 appears, the proxy is transparent. If a different, unrelated address appears, it is distorting. “unknown” or the proxy’s own address means anonymous.
  3. Check for Via, Forwarded and Proxy-Connection. Any of them means the proxy reveals itself.
  4. Elite means X-Forwarded-For holds only the exit IP, and none of the other proxy headers appear.

The /ip page is a quick cross-check: it reports the X-Forwarded-For value, so two addresses there mean something before httpbin added a forwarding header. Run the test more than once if your proxy rotates, and test each proxy type you use, since a provider’s gateways can be configured differently.

Browser-based checkers work the same way and add browser tests. Our free proxy checker confirms a proxy works and shows the IP, country and ISP that websites see; it doesn’t grade anonymity, so use the header test above for that.

HTTPS, CONNECT and SOCKS5

When the proxy can’t add headers

The header test uses plain http:// on purpose. When you request an https:// page through an HTTP proxy, your client sends the proxy a CONNECT request, and RFC 9110 says the proxy then switches to blind forwarding of data in both directions. The encrypted request, headers included, passes through untouched. The curl project’s documentation puts it the same way: once the tunnel is set up, the proxy cannot see or modify the traffic without breaking the encryption.

Two things follow. First, on HTTPS sites a normal proxy can’t add X-Forwarded-For even if it is configured to, so the header level mostly matters for plain HTTP. Second, testing an https:// echo page shows every non-intercepting proxy as elite, which tells you nothing. The exception is a proxy that decrypts traffic, such as a company gateway doing TLS inspection with its own certificate on your device; that kind can add headers to HTTPS too.

SOCKS5 proxies, defined in RFC 1928, relay connections below HTTP and don’t write HTTP headers at all. A header test therefore grades them elite, which again shows why headers are only one check.

Why the header level isn’t the whole story

IP type, fingerprints and leaks

Modern websites rarely rely on proxy headers alone. A clean, elite header profile removes the easiest signal, but the site still has others.

IP reputation and type

Every IP address belongs to a network, and IP databases record whose. Addresses owned by hosting and cloud companies are easy to recognise as datacenter IPs, and many sites treat them with suspicion or block them outright, whatever the headers say. Residential IPs belong to consumer internet providers and mobile IPs to phone carriers, which is what ordinary visitors connect from. An address that has been used for abuse also carries that history. This is why an “anonymous proxy detected” message usually comes from an IP lookup, not from a header.

Residential vs datacenter

Datacenter proxies are fast and cheap, and fine for sites that don’t screen IP types. For sites that do, residential proxies and mobile proxies matter more than the header level, because they connect from the same kinds of networks as real users. Header level and IP type are separate questions, so check both.

Browser fingerprinting

The W3C’s guidance on browser fingerprinting describes two kinds. Passive fingerprinting uses what arrives with every request, such as the IP address, the User-Agent and other headers. Active fingerprinting runs code in your browser to read details such as screen size and installed fonts. A proxy changes your IP; it doesn’t change your fingerprint. A mismatch, such as a German IP with a browser set to a US time zone and language, is a signal in its own right.

WebRTC leaks

WebRTC, the browser technology behind video calls, can reveal your real address. RFC 8828, the IETF’s rules for how WebRTC handles IP addresses, notes that when a browser is behind a configured proxy but direct internet access is allowed, WebRTC’s connectivity checks bypass the proxy and reveal the client’s public IP. A web page can start these checks without a permission prompt. The fix is a browser setting or extension that forces WebRTC through the proxy or disables it. ProxyEmpire’s Proxy Manager extension for Chrome includes WebRTC leak protection and matches the browser’s time zone, language and geolocation to the proxy’s location.

DNS leaks

Before connecting to a site, something has to look up its address. With an HTTP proxy, your client passes the host name to the proxy, and the proxy does the lookup. With SOCKS5 it depends on the client: curl’s documentation says socks5:// resolves the host name locally, while socks5h:// lets the proxy resolve it. A local lookup goes to your own provider’s DNS resolver: that resolver learns which site you are visiting, and a DNS leak test will show lookups coming from your real network instead of the proxy’s.

What keeps you anonymous on a large proxy network

A practical checklist
  • Clean headers. Test each proxy type over plain HTTP as shown above, and repeat after any provider change.
  • The right IP type. Use residential or mobile IPs for sites that screen out datacenter addresses.
  • Matching location. Target the country, city or ISP your task needs, and set the browser’s time zone and language to match.
  • Sensible sessions. Rotate IPs for large-scale collection, and use sticky sessions when a site expects one visitor to keep one address, such as while logged in.
  • No WebRTC or DNS leaks. Force WebRTC through the proxy or turn it off, and let the proxy resolve host names.
  • A consistent fingerprint. Keep one browser profile per identity; an anti-detect browser helps when you run several.
  • Credentials, not your own IP. Authenticate with a user name and password. IP allowlisting ties your own address to the proxy account; credentials work from any connection.

ProxyEmpire’s rotating mobile proxies and residential proxies support that setup: targeting by country, region, city, ZIP, ISP or carrier, ASN and OS fingerprint at no extra charge, rotating or sticky sessions, and user name and password authentication. ProxyEmpire’s gateways don’t forward your own IP address in X-Forwarded-For or any other forwarding header, so the site only sees the exit IP. You can confirm it with the test above; the $1.97 trial is enough to do it.

Which anonymity level do you need?

Match the level to the job
TaskLevel neededAlso check
Caching or filtering on your own networkTransparent is fine, and often wantedNothing: the point is to keep the client visible
Casual browsing privacyAnonymous or eliteWebRTC and DNS leaks
Price, ad and search checks from other countriesEliteIP type and location targeting
Large-scale data collectionEliteRotation, residential or mobile IPs, request rate
Managing accounts in a browserEliteSticky sessions, fingerprint, time zone and language
Security testing of your own siteAny, one at a timeHow your server treats each header

Across these tasks, the proxy anonymity levels mostly decide one thing: whether the site gets an easy signal. That last row is worth a note for site owners. If your application reads X-Forwarded-For to decide who a visitor is, test it with each level. MDN’s advice applies: trust only the entries added by your own proxies or load balancer, or a distorting proxy can make any visitor look like anyone.

Proxy anonymity FAQ

Short answers
What are the proxy anonymity levels?

Level 1 is elite (no proxy headers), level 2 is anonymous (proxy visible, your IP hidden) and level 3 is transparent (your IP forwarded). Distorting proxies, which send a fake IP, are sometimes listed separately.

What is a hidden proxy?

An informal name for an elite or high-anonymity proxy: one that sends no Via, X-Forwarded-For or Forwarded header, so the website sees only the proxy’s IP and no sign of a proxy in the request.

What is the difference between an elite proxy and an anonymous proxy?

Both hide your IP. An anonymous proxy still announces itself with Via or a forwarding header; an elite proxy removes those headers, so the request doesn’t reveal a proxy.

Is a distorting proxy better than an anonymous proxy?

Not in practice. Both reveal a proxy. The fake IP only helps against sites that trust X-Forwarded-For, and careful sites use the connecting address instead.

Are residential proxies always elite?

Not automatically. The header level depends on how the provider configures its gateways, and the IP type is a separate question. Test the headers yourself over plain HTTP.

Does HTTPS stop a transparent proxy from sending my IP?

Through a normal CONNECT tunnel, yes for headers: the proxy can’t add X-Forwarded-For to encrypted requests. A proxy that decrypts TLS with its own certificate can still add them.

What does “anonymous proxy detected” mean?

The site has decided your connection comes from a proxy or VPN, usually because the IP appears in a database of hosting or proxy ranges, sometimes because of proxy headers.

Can I trust the anonymity labels on free proxy lists?

Only as a snapshot. The label reflects one checker’s test at one moment, and a proxy’s configuration can change. Test any proxy yourself before relying on it.

Is using an elite proxy legal?

Using a proxy is legal in most countries. What you do through it is what matters: follow the law and the terms of the sites you use.

References

Primary documentation
  1. IETF — RFC 9110, “HTTP Semantics” (2022): section 7.6.3 Via, section 7.6.1 Connection, section 9.3.6 CONNECT, section 3.7 on interception proxies. rfc-editor.org/rfc/rfc9110
  2. IETF — RFC 7239, “Forwarded HTTP Extension” (2014). rfc-editor.org/rfc/rfc7239
  3. MDN Web Docs — X-Forwarded-For header. developer.mozilla.org
  4. IETF — RFC 9112, “HTTP/1.1” (2022): appendix C.2.2 on Proxy-Connection. rfc-editor.org/rfc/rfc9112
  5. IETF — RFC 3875, “The Common Gateway Interface (CGI) Version 1.1” (2004). rfc-editor.org/rfc/rfc3875
  6. Squid 7 configuration reference — forwarded_for. squid-cache.org
  7. Squid 7 configuration reference — via. squid-cache.org
  8. httpbin source — helpers.py (headers hidden unless show_env is set). github.com/postmanlabs/httpbin
  9. curl — command line manual (–proxy, –socks5, –socks5-hostname). curl.se/docs/manpage
  10. Everything curl — HTTP proxy and HTTPS through CONNECT. everything.curl.dev
  11. IETF — RFC 1928, “SOCKS Protocol Version 5” (1996). rfc-editor.org/rfc/rfc1928
  12. IETF — RFC 8828, “WebRTC IP Address Handling Requirements” (2021). rfc-editor.org/rfc/rfc8828
  13. W3C — “Mitigating Browser Fingerprinting in Web Specifications” (Group Note). w3.org/TR/fingerprinting-guidance

Test it on real residential and mobile IPs

30M+ residential IPs in 179 countries and territories and 4M+ mobile IPs in 174 countries, with targeting by country, city, ISP and ASN at no extra charge, rotating or sticky sessions, and 24/7 support from real people. The $1.97 trial includes 100 MB of residential and 50 MB of mobile traffic, enough to run the header test yourself.

Flexible Pricing Plan

logo purple proxyempire

Our state-of-the-art proxies.

Experience online freedom with our unrivaled web proxy solutions. Pioneering in collecting location specific data at scale, our premium, ethically-sourced network boasts a vast pool of IPs, expansive location choices, high success rate, and versatile pricing. Advance your digital journey with us.

🏘️ Rotating Residential Proxies
  • 30M+ Premium Residential IPs
  •  170+ Countries
    Every residential IP in our network corresponds to an actual desktop device with a precise geographical location. Our residential proxies aare fast and reliable, with 99.9% uptime, and work for a wide range of use cases. You can use Country, Region, City and ISP targeting for our rotating residential proxies.

See our Rotating Residential Proxies

📍 Static Residential Proxies
  • 19 Countries
    Buy a dedicated static residential IP from one of the 19 countries that we offer proxies in. Keep the same IP for a month or longer, while benefiting from their fast speed and stability.

See our Static Residential Proxies

📳 Rotating Mobile Proxies
  • 4M+ Premium Mobile IPs
  •  170+ Countries
    Access millions of clean mobile IPs with precise targeting including Country, Region, City, and Mobile Carrier. Get far fewer IP blocks and CAPTCHAs with our 4G and 5G proxies.

See our Mobile Proxies

📱 Dedicated Mobile Proxies
  • 5+ Countries
  • 50+ Locations
    Get your own dedicated mobile proxy in one of our supported locations, with unlimited bandwidth and unlimited IP changes on demand. A great choice when you need a small number of mobile IPs and a lot of proxy bandwidth.

See our 4G & 5G Proxies

🌐 Rotating Datacenter Proxies
  • 197,000+ IPs Premium IPs
  •  62 Countries
    On a budget and need to do some simple scraping tasks? Our datacenter proxies are the perfect fit! Get started with as little as $2

See our Datacenter Proxies

proxy locations

30M+ rotating IPs

99% uptime - high speed

99.9% uptime.

dedicated support team

24/7 Dedicated Support.

fair price

Fair Pricing.

🏠 Residential Proxies Rotating / Static / Unlimited
📱 Mobile Proxies Rotating and Dedicated
🖥️ Datacenter Proxies Rotating
🌍 IP Pool 30M+ residential + 4M+ mobile IPs
📶 Uptime 99.9% · Live status
💳 Payment Card · PayPal · Crypto · Bank transfer
💬 Support 24/7 live chat · sales@proxyempire.io