ProxySocial logo
Guide

Fraud Score vs What Instagram and TikTok Actually Check

Someone running social accounts checks their new mobile proxy on a fraud score site, sees a red badge and a number in the high eighties, and assumes the next login will hit a checkpoint. Then they log in and nothing happens. Or a checkpoint arrives a week later and the score gets the blame. Both reactions come from the same misunderstanding: that Instagram, TikTok and Facebook are looking at the same thing the checker looked at. They are not. This article lays out what a public checker measures, what the platforms actually evaluate, why account problems usually trace back to how fast you act and how well you separate your accounts, and what to do with the proxy when a platform really does object.

Two judges, two rulebooks

A fraud score site is a lookup. You give it a public IP, it returns what it knows about that address from its own history and its own data partners, and it turns that into a single number. It never sees your account, your phone, your browser, or what you do after connecting. Its rulebook is entirely about the address.

A social platform is watching a session. When you log in, it already has an account with a history, a device it has seen before or not, a set of actions you take and the speed you take them at. The IP address is in the file, but it is one line in a long file. Its rulebook is mostly about you.

So both can be right at once. The checker correctly reports that the address is a mixed, changeable carrier gateway, which is what carrier grade NAT produces when a carrier puts many phones behind one public address. The platform correctly notices that your session looks like a normal person on a phone and lets you in.

What Instagram, TikTok and Facebook actually evaluate

The platforms do not publish their detection logic, but the pattern of what triggers action is consistent and well understood by anyone who manages accounts for a living. The signals below are the ones that matter, and none of them is the fraud score.

Notice where the address sits in that list. It is a supporting detail. A carrier mobile address is one that platforms are used to seeing behind a very large number of real users, so on its own it tends to lower the alarm rather than raise it.

Why bans usually trace back to velocity and fingerprints

When an account is checkpointed or disabled, the proxy gets blamed first because the score was the only warning sign anyone measured. When the sequence of events is reconstructed, the cause is nearly always on the operator's side. A new account followed two hundred people in an afternoon. Ten accounts ran from one browser profile with one set of cookies. A batch of DMs went out with the same wording. An account that had already been warned was moved to a fresh proxy and the warning came with it.

Platforms are very good at spotting these things because they see them at enormous scale. A mixed carrier address, by contrast, is what they see from everyone. If the address alone triggered bans, every real subscriber sharing that gateway would be banned too.

This is also why moving to a new address rarely fixes a pattern problem. The address changes; the fingerprint, the cookies, the pace and the account history all come along. The fix is to slow down, separate the accounts properly, and let trust build.

Mobile addresses get more patience, not less

There is a real difference between how platforms treat a hosting address and a carrier address. Traffic from a datacenter range is unusual for a social app and is questioned quickly. Traffic from a carrier gateway is the ordinary condition, so the platforms extend it more patience before acting. A checker, tuned to punish diverse traffic, gets this backwards.

Our proxies are real 4G and 5G modems with AT&T, T-Mobile and Verizon SIMs, in racks we run in New York, Los Angeles, Chicago, Houston, Phoenix, Miami, North Carolina and Boston. Your port is yours alone, so your sessions stay consistent, while the public address is the carrier's shared gateway, so you look like the subscribers around you. That combination is the point.

Reading a checker without being misled

If you want to keep using a checker, use it for what it is good at. Scroll past the headline number to the detail fields. The connection type should say mobile or cellular with a carrier name attached; if it says hosting, something is wrong. The location should be the metro you ordered, allowing for gateways sitting a little way off. A current listing on a named abuse database is a genuine signal; a generic risk band is not.

Then close the tab and do the test that matters: open the app, log in, and behave normally for a few days. Persistent sessions, no checkpoints and no sudden captcha loops are a pass, whatever the number said.

When the platform itself objects

Sometimes the platform does push back, and that is worth acting on. Checkpoints on every login attempt across several accounts, captcha on every Google search, a Cloudflare challenge on every site, or sessions that die within minutes are signs the gateway you are on has a real problem right now.

Before switching anything, check the behaviour side: how many actions per hour, how many accounts per browser profile, whether any account was already under review. If the setup is clean and the platform is still objecting, message support in live chat. We can rotate the address, move you to a different carrier in the same city, or move you to another metro, and a move is free. Then run the same test again on the new address.

Frequently asked

My proxy scored high but Instagram logged in fine. Which one is right?

Both, about different things. The checker described the shared carrier gateway. Instagram evaluated your session and account and found nothing wrong. Trust the platform's behaviour.

Will a lower fraud score reduce checkpoints?

Not by itself. Checkpoints are driven by action speed, device consistency and account history. An address with a lower score and the same aggressive behaviour will hit the same checkpoints.

How many accounts can I run on one mobile proxy?

Fewer than you probably want to. Each account should have its own browser profile or device, its own cookies and its own pace. The proxy gives all of them a consistent carrier address; it does not separate them for you.

I got a checkpoint after a week. Should I rotate?

First, look at what happened in that week: follow bursts, new devices, shared profiles. If the behaviour was steady, ask support to rotate or move you and see whether the checkpoint repeats. Rotating without changing the behaviour usually just delays the next one.

USA mobile proxies on hardware we own

Real 4G and 5G carrier IPs in eight US metros, with unlimited rotation, sticky sessions and HTTP(S) or SOCKS5. Plans start at $5/day.

View plans See all locations

More guides

All ProxySocial resources →