CGNAT Explained: Why One Mobile IP Looks Like Thousands of Users

Carrier-grade NAT packs thousands of real subscribers behind a single mobile IP. That one fact is why a mobile proxy is the hardest exit for a website to block — and why platforms treat mobile traffic differently.

Here is the counterintuitive fact at the heart of mobile proxies: an IP address that is shared by thousands of strangers is more trusted than one you have all to yourself. That is not a quirk — it is the direct consequence of how mobile networks assign addresses, a system called carrier-grade NAT (CGNAT). Once you understand CGNAT, the whole logic of "why are mobile proxies so hard to block?" falls into place. This guide explains what CGNAT is, why it exists, and why it turns a mobile IP into the single hardest exit for a website to ban.

What CGNAT actually is

Your home router already does network address translation: it hides the private addresses of your devices behind one public IP. Carrier-grade NAT is the same idea, one level up. The mobile operator inserts an additional translation layer that puts many subscribers — households, phones, unrelated devices — behind a single public IPv4 address. From the outside, all of that traffic appears to come from one address. The individual devices are invisible behind the carrier's translation layer, and crucially, the users have no idea it is happening. Unlike a VPN or proxy, which people choose, CGNAT is configured silently by the ISP inside its own network.

The technical marker is the Shared Address Space defined in RFC 6598 — the 100.64.0.0/10 range — which carriers use between your device and the public internet. Its presence in a traceroute is a reliable fingerprint of CGNAT.

Why carriers do it: IPv4 simply ran out

The driver is arithmetic. IPv4's 32-bit design allows about 4.3 billion unique addresses, a number that once seemed limitless and was completely outpaced by the internet's growth. By the early 2010s the regional registries had depleted their pools of unallocated IPv4 addresses, leaving ISPs unable to simply buy more. CGNAT was the practical workaround: instead of one public address per customer, place many customers behind each address. The pressure is worst on mobile networks, where a decade ago most connections were smartphones and today the same infrastructure also carries payment terminals, cameras, routers, sensors and countless other devices. IPv6 is the long-term fix, but as the old line goes, nothing is more permanent than a temporary solution — and CGNAT remains common on both 4G and 5G. A newer generation of mobile tech did not eliminate it, because the shortage was never a 4G problem.

Stats panel showing thousands of users per mobile IP, 4.3 billion total IPv4 addresses, and the 100.64/10 CGNAT range
IPv4 exhaustion forced carriers to pack many subscribers behind each public address — mobile networks most of all.

The collateral-damage problem that protects mobile IPs

Most abuse defences on the web — blocklists, rate limits, anomaly detection — were built on one assumption: that an IP address maps to a single accountable entity, roughly one user. CGNAT shatters that assumption. When hundreds or thousands of unrelated subscribers share one public IP, blocking that IP because of one bad actor punishes everyone behind it. As far back as 2015, the UK regulator Ofcom warned that blacklisting a CGNAT address could affect "an entire subscriber base." The IETF documented the same tension years earlier in RFC 6269 and RFC 7021: traditional block-the-IP mitigation breaks down when the IP is shared.

This is such a real problem that Cloudflare built a machine-learning classifier specifically to detect CGNAT so it can avoid over-blocking those addresses — training it on a labelled set of more than 200,000 CGNAT IPs, 180,000 VPN and proxy IPs, and close to 900,000 single-subscriber addresses, using traceroutes from over 9,000 measurement probes worldwide. The whole point of that effort is to treat shared mobile addresses gently, because banning them causes disproportionate harm — and disproportionately affects users in developing regions, where CGNAT is most common.

Why this makes mobile proxies the hardest to block

Now put the two facts together. A mobile proxy routes your request through a real carrier IP that already sits behind CGNAT, sharing space with thousands of genuine phone users. To the target site, your traffic is statistically indistinguishable from the ordinary mobile customers on that same address. Blocking it means blocking all of them — exactly the collateral damage that platforms and anti-bot vendors work hard to avoid. That is the trust advantage in one sentence: a mobile IP is not trusted because it is clean, but because banning it is too expensive.

Compare the tiers directly and the ranking is about collateral damage, not cleanliness. A datacenter IP has one tenant and its own hosting ASN, so banning it harms no innocent bystander — cheap to block, lowest trust. A residential IP is a real home line shared by a handful of people — some ban cost, high trust. A mobile CGNAT IP carries thousands of real users — blocking it is mass collateral damage, so sites avoid it, which is the highest trust of all.

Get mobile proxies on real carrier IPs

Comparison of datacenter, residential and mobile CGNAT IPs ranked by how much collateral damage a ban would cause
The more real users share an address, the costlier it is to block — which is exactly why mobile IPs earn the most trust.

When to actually reach for a mobile proxy

Trust is not free — mobile bandwidth is the most expensive tier, so mobile proxies earn their cost on the hardest targets, not everywhere. Use them where IP reputation is the wall: managing multiple accounts on platforms that aggressively fingerprint IPs, verifying mobile ad delivery, or scraping sites that block residential ranges. For lenient targets, a residential proxy is the better value. Our guides on mobile vs residential vs ISP proxies and why mobile IPs are becoming the standard map which tier fits which job, and IP reputation vs device fingerprinting covers the other half of staying unblocked.

Frequently asked questions

What is CGNAT?

Carrier-grade NAT is a technique where an internet provider places many subscribers behind a single shared public IPv4 address, using an extra translation layer inside its network. It exists because IPv4 addresses ran out, and it is especially common on mobile networks. Users are not aware of it — unlike a VPN, it is configured silently by the carrier.

Why are mobile proxies harder to block?

Because CGNAT puts thousands of real users behind each mobile IP, blocking that address would lock out all of them — unacceptable collateral damage for most sites. Your proxied traffic blends into that crowd of genuine subscribers, so per-IP defences struggle to isolate you and the cost of banning the IP is far higher than for a datacenter range.

What is the CGNAT IP range?

The Shared Address Space reserved for carrier-grade NAT is 100.64.0.0/10, defined in RFC 6598. Carriers use it between the subscriber's device and the public internet. Spotting an address in that range inside a traceroute is a strong indicator that the connection sits behind CGNAT.

Does 5G get rid of CGNAT?

No. Shared addressing was never a 4G limitation — it exists because connected devices grew far faster than the pool of available IPv4 addresses. CGNAT remains common on both 4G and 5G networks. Broader IPv6 adoption may reduce reliance on it over time, but for now it is still standard on mobile.

CGNAT is the quiet reason mobile proxies command a premium: they inherit the trust of the thousands of real subscribers who share each carrier IP. Sites cannot ban that address without harming their own users, so they mostly do not. When IP reputation is the obstacle standing between you and a target, that is the edge a mobile IP buys.

Start with QuantumProxies mobile proxies