Referral Program →
HomeGlossaryReverse Proxy
Glossary

Reverse Proxy

A server that sits in front of one or more web servers and forwards incoming client requests to them, hiding the backend from the client.

A reverse proxy is a server that receives requests from clients on behalf of one or more backend servers, then forwards each request to the appropriate backend and returns the response. From the client's point of view, the reverse proxy is the website - the real servers behind it are hidden.

This is the mirror image of a forward proxy. A forward proxy works on behalf of clients to reach the wider internet (hiding the client). A reverse proxy works on behalf of servers to receive traffic from the internet (hiding the servers). Same middleman concept, opposite direction.

Reverse proxies are core web infrastructure. They handle load balancing (spreading traffic across multiple backends), SSL/TLS termination (decrypting HTTPS so backends do not have to), caching (serving repeated responses without hitting the backend), and security filtering (blocking malicious requests before they reach the application). Nginx, HAProxy, and Cloudflare are common reverse proxies.

For anyone doing web scraping, reverse proxies matter because they are often where anti-bot systems live. Cloudflare, Akamai, and similar services act as reverse proxies in front of target sites, inspecting incoming requests and challenging or blocking those that look automated. Understanding this helps explain why requests get blocked before they ever reach the real server.

The proxy that belongs to the website

A forward proxy acts for the client. A reverse proxy acts for the server: it sits in front of an origin, accepts connections from the public, and decides what to do with them before anything reaches the application behind it.

Reverse proxies handle TLS termination, caching, load balancing and, most relevantly here, filtering. Cloudflare, Fastly and similar services are reverse proxies operated as a product, which is why so many of the blocks you meet come from infrastructure rather than from the site itself.

This is why two different sites can block you in exactly the same way, with the same challenge page and the same signals. You are not meeting their rules, you are meeting their vendor's.

What this means for your setup

When the block comes from a reverse proxy, the fix is about signals rather than the site:

Recognising the layer

Challenge page from a known vendor  -> you are being scored, not banned
Same block pattern across sites      -> shared vendor, shared ruleset
Server header naming a CDN           -> a reverse proxy is in front

curl -I https://example.com | grep -i 'server\|cf-ray'
  • A vendor scoring system weighs address class, TLS fingerprint and behaviour. Improving one moves the score, and the address is the one we sell.
  • Because rules are shared across customers, a setup that clears one site often clears others using the same vendor.
  • Rate limits are frequently enforced at this layer too, which is why they feel identical across unrelated sites.
  • None of this is defeated by rotating addresses alone if your client announces itself in the handshake.

Forward and reverse mixed up

A reverse proxy is not something you buy from us

We sell forward proxies. A reverse proxy protects a site you do not own.

It is not the site's own decision

The vendor's default rules block a great deal that the site owner never considered.

Bypassing it is not a product feature

Anyone selling a guaranteed bypass is selling something that stops working the week the vendor updates.

It does explain identical blocks

Meeting the same challenge on unrelated sites means one vendor, not a coordinated ban.

Ready to use reverse proxy?

SotaProxy gives you access to rotating residential, mobile, datacenter, and ISP proxies. No minimum commitment.

Get started