Phishing pages choose who they show — a hosting IP only ever gets the decoy
Email protection and phishing link analysis
Phishing infrastructure routinely fingerprints the visitor: requests from hosting ranges get a harmless decoy, while the real credential-harvesting page is reserved for local broadband users. ZapIP detonates links and captures landing pages through genuine residential exits in 195 countries, so email security teams see the page the recipient saw.
- 90M+ residential exits
- 195 countries and regions
- HTTP(S) + SOCKS5
- KYC-consented sourcing
How it works
The first gate on a phishing page is the visitor's network type
Attackers blocklist security vendors by ASN and geofence campaigns by country. Analyse a link from a hosting IP and the sample you archive is usually the decoy, which reads back to the analyst as a false positive.
- Native broadband ASNs — reverse WHOIS and ASN both resolve to residential
- Pick the exit country and city to reproduce a geofenced landing page
- Fresh exits per detonation so your analysis nodes do not get fingerprinted
- SOCKS5 drops straight into sandboxes and automated forensics pipelines
How it works
Check delivery from where the recipient actually sits
Whether a redirect chain resolves the same way everywhere, how an impersonation page renders in the target market, where a tracking pixel phones home — all of it shifts with the network you look from. One office exit will never surface a regional difference.
- Trace redirect chains in parallel to find the hop that only fires in one country
- Verify how a brand-impersonation page actually renders in the target market
- Long-term static IPs give fixed observation points for tracking infrastructure over time
- City and ASN targeting reproduces the path a specific carrier's users take
How it works
Security work has boundaries too
Threat analysis is legitimate use; a proxy network is not an attack tool. ZapIP's acceptable use policy states that plainly, and it is the reason the network stays viable long-term.
- No DDoS, credential stuffing, carding or unauthorised intrusion testing
- Residential IPs are consented and the sourcing chain stays auditable
- Sub-accounts isolate usage and permissions so each team keeps its own trail
- 24/7 support in English and Chinese, with an engineer on the integration
Coverage
One network behind all four products — changing the billing model does not change how you connect or how you target.
All 33 markets- 195 countries & regions
- Available
- All 50 US states
- Available
- City-level targeting
- Precise
- ISP & ASN targeting
- Supported
4 billing models
How this is billed
All four billing models share one network. Short bursts go per GB, pipelines that run continuously go per Mbps, and anything tied to an account identity goes per IP-day or per IP-month.
FAQ
Questions about this solution
Why does phishing link analysis need residential proxies instead of data center IPs?
Because the attacker is running detection too. A standard trick is to keep an ASN list of security vendors and cloud providers, serve them a benign page, and reserve the real credential flow for consumer broadband ranges. Detonate from a hosting IP and the sample you archive looks clean, which lands on an analyst's desk as a false positive. A residential exit reproduces the victim's view.
Will attackers fingerprint our analysis exits over time?
They will, if you keep reusing the same addresses. Run detonation on rotating residential so each analysis leaves from a different exit, and reserve long-term static IPs for cases where you deliberately want a fixed vantage point — kept separate from the detonation pool. ZapIP also monitors reputation continuously and retires flagged addresses rather than passing them to the next job.
Can we use this to test our own mail gateway and spam placement?
Yes, as long as the system under test is yours or you hold written authorisation. The usual pattern is to reach delivery-result pages and redirect chains from residential exits in each target market and compare how they render. Unauthorised testing against third-party systems is explicitly prohibited by the acceptable use policy.
Rotating or static, and how much traffic will this use?
Detonation and landing-page capture fit the traffic plan — $0.8/GB and up, with a balance that never expires, which matters more than unit price when security workloads spike and then go quiet. Add a handful of long-term static IPs, from $3.8 per IP per month, wherever you want a fixed vantage point. Both run from one account.
Get one request working. Scale after that.
Test before you commit, with an engineer on your integration.