Every proxy route ends somewhere, and the last hop is the one the target sees. Its IP address is what the website geolocates, looks up by ASN, scores for reputation and rate-limits. Everything before it is invisible to the site.

Gateway vs exit

With a static proxy the two are the same machine: you connect to an IP and that IP makes the request. With a backconnect proxy they are different: you connect to a gateway, and the provider sends your traffic out through an exit drawn from its pool. On a residential network the exit is a consumer device; in a proxy chain it is the last proxy in the chain.

How to find your exit

Ask an IP echo service through the proxy:

curl -s -x http://USERNAME:PASSWORD@HOST:PORT "https://api.ipify.org?format=json"

Then check that address's network and location with a second lookup, such as https://ipinfo.io/<ip>/json. When you test a provider, record the exit for every request: the number of distinct exits, their locations and their networks tell you more than any headline pool size. How to test a proxy provider has a script that does this.

Common confusion

  • Allowlisting the gateway does nothing on the target. If a partner's firewall must allow your traffic, it has to allow the exit, which on a rotating pool keeps changing. That job needs a static IP.
  • The term comes from Tor, where exit nodes are publicly listed and widely blocked. Proxy exits are not listed that way, but sites build their own lists from the traffic they see.