NexaProxies describes itself as a “Private proxy network. Access by invitation only.”

That wording made us curious. Does “private” also mean that the underlying residential IPs are unique to NexaProxies, or are the same IPs available through other proxy providers too?
We recently got access and decided to check.
The protocol was quite simple, we just sent a limited number of requests through the residential proxy gateway to an endpoint that returned the IP address used for each connection, then logged and deduplicated the results.
That gave us 1,183 distinct exit IPs.
We were not trying to enumerate the full NexaProxies network or estimate its total size. We only wanted a large enough sample to answer one question: is this a distinct residential proxy pool, or does it substantially overlap with infrastructure already sold elsewhere?
We compared those exits with the proxy infrastructure we track in Castle's IP Intelligence data.
The answer became clear pretty quickly: most of the pool was already visible under other proxy operators.
The same IP, sold by multiple proxy providers
Of the 1,183 exit IPs we collected, 1,002 were already associated with at least one named proxy operator in Castle's IP Intelligence data.
That's 84.7% of the sample.
And the overlap was usually not limited to one other provider. The median attributed exit had been associated with seven different proxy operators, while one IP had been associated with 24.
More importantly, this overlap was recent. Of those 1,002 attributed exits, 966 had also been observed through another proxy operator within the previous seven days.
So this is not just a case of IPs moving from one provider to another over time. A large part of the same residential supply appears to be available through several operators at roughly the same time.

This does not tell us the exact commercial relationship between NexaProxies and the other providers we observed. They may share upstream suppliers, resell access to the same peer pools, or use some combination of both.
For defenders, the important part is that the same exit IP can surface behind several different proxy providers. If an IP has already been identified as part of another proxy network, buying access through a different provider does not make that IP new or unknown again.
There may be dozens of proxy operators in the market, but far fewer truly independent residential pools underneath them.
A few operators cover most of the pool
The overlap becomes even more obvious when we look at how much of the NexaProxies sample can be explained by a small number of proxy operators.
Among the 1,002 exits already attributed in Castle's IP Intelligence data, one operator alone covered 70.2% of them.
- Two operators covered 88.1%.
- Four covered 95.5%.

That is useful because it shows how misleading the number of proxy providers can be. The market may contain many different services, dashboards, pricing models, and gateways, while a large part of the underlying residential IP supply comes from the same shared pools.
For defenders, this means that tracking a relatively small number of large proxy operators can give visibility into traffic that is later resold or exposed through many other providers.
It also means that switching providers does not necessarily mean switching infrastructure. A user can move to a different proxy service and still end up using many of the same residential IPs.
Residential proxies hide in plain sight
The exits we observed were spread across 93 countries and 419 ASNs, including Comcast, AT&T, Verizon, T-Mobile, Deutsche Telekom, Virgin Media, Bell Canada, and Starlink.
That is exactly what makes residential proxies useful. The traffic exits through IP space owned by large consumer ISPs and mobile networks, not through a small set of obvious hosting ranges.
The pool was also very scattered. The 1,183 exits were spread across 1,048 distinct /24s, and only four /24s contained more than one exit.
So there is very little subnet concentration to key on.

From a network metadata perspective, these addresses look like normal customer IPs. The useful signal comes from knowing that the same address has recently been observed acting as an exit for one or more commercial proxy networks.
Residential proxy pools never stand still
The remaining 181 exits, 15.3% of the sample, had no proxy attribution in Castle's IP Intelligence data during our lookback window.
Those addresses still came from the same kind of networks as the rest of the sample: Comcast, Verizon, AT&T, Deutsche Telekom, Charter, T-Mobile, Bell Canada, Starlink, and other residential or mobile providers.
That is a useful reminder that residential proxy infrastructure is highly dynamic.
IPs enter and leave proxy pools over time. Residential subscribers get reassigned addresses, peers come and go, and providers change the supply they rely on. An address that has never appeared in our proxy data before can suddenly start being used as an exit.

This is why proxy intelligence cannot be treated as a static blocklist.
Residential proxy pools change continuously, so there will always be some delay between an IP starting to act as a proxy exit and that activity being observed and attributed. No dataset can guarantee that every newly active residential proxy IP is already known.
And even when an IP is known to participate in a proxy network, blocking it outright is often the wrong response.
Many residential proxy exits are normal consumer IPs that can also be used by legitimate users. The same address may carry proxy traffic at one moment and ordinary residential traffic at another.
Proxy intelligence is therefore most useful as a risk signal rather than a binary verdict. It becomes much stronger when combined with other signals such as device fingerprinting, behavioral analysis, account history, velocity, and session-level patterns.