NeonProxies logo
Use case

hCaptcha, Risk Scores and Mobile Carrier IPs

hCaptcha shows up on forums, sign-up pages, crypto services, Discord flows and a long tail of sites that wanted a privacy-focused alternative to Google. It is also on the Enterprise tier of many larger properties, where it quietly returns risk scores instead of showing images. Builders often assume that a better IP makes the image grids go away. Sometimes it helps a little; often it does not. This page explains what hCaptcha is publicly known to weigh, what a dedicated NeonProxies carrier line changes, and how to wire hCaptcha into automated work honestly.

Before the grid: the passive assessment

When the widget loads, hCaptcha runs checks in the browser and on its servers before deciding whether to show a challenge at all. The free tier leans on showing image tasks; the Enterprise product adds passive and invisible modes, where most visitors never see a puzzle and the site receives a risk score with the token instead. Either way, the first decision is about the environment: is this a real browser, does it behave consistently, has this visitor or this address been involved in abuse across the many sites hCaptcha protects.

Difficulty then scales with risk. A visitor who looks ordinary gets an easy task or none. One who looks automated gets several rounds of harder images, or is refused. That escalation is why automated attempts get stuck in loops: every failure raises the next round's difficulty for that session.

How much the IP moves the needle

hCaptcha sees a lot of traffic, so it knows which addresses have been busy. Data center ranges and IPs recently used for mass sign-ups on other sites start at a disadvantage. A NeonProxies line gives you a carrier address from AT&T, T-Mobile or Verizon, shared through carrier-grade NAT with ordinary phones, and dedicated to you rather than cycled among strangers. For a legitimate user who kept getting difficult grids from a cloud desktop, that often means fewer and easier tasks.

It stops there. The browser checks, the interaction signals and the history of the session all remain. An automated browser that exposes its framework or moves the pointer in straight lines will still escalate, whatever the address.

The rule for unattended jobs

A form behind hCaptcha is a form the owner wants people to fill in. Automation that reads public pages should leave those forms alone, and automation that legitimately needs to submit one, for instance a support request on your own account, should pause and hand the challenge to a human operator. Sending challenges to solving services breaches hCaptcha's terms, the site's terms and ours, and the sites most likely to use hCaptcha are exactly the ones that watch for it.

If a public page that normally loads without a challenge starts showing one to your worker, treat it as feedback: the rate is too high, the profile was reset, or the session moved between addresses. Fix those before running again, and keep a count of challenges per worker per day so a slow rise is visible before it becomes a wall.

Using hCaptcha on your own properties

hCaptcha publishes test site keys and secrets for development that return predictable results, which is what automated end-to-end tests in staging should use. In production, a carrier line in the metros your users live in shows you what real mobile visitors experience. Run your sign-up from a normal phone-like profile through the line and note whether a challenge appears and how hard it is, then compare with a cloud run. If you are on Enterprise, check the risk score your backend receives for each run so you can set thresholds that stop scripted sign-ups without punishing people on cellular connections.

Remember accessibility while you are there. hCaptcha offers an accessibility option for people who cannot complete visual tasks, and your testing should confirm that path works through your form too.

Setting up a hCaptcha proxy on NeonProxies

  1. Buy a line in the metro your users or research targets are in.
  2. Use a persistent browser profile per line so session history is kept.
  3. Keep scheduled jobs on public pages that do not carry the widget.
  4. Send any challenge that appears to a person instead of a script.
  5. Test your own forms with hCaptcha's test keys in staging and a carrier line in production.
  6. Record challenge frequency and risk scores before changing thresholds.

hCaptcha proxy questions

Why do I keep getting harder image rounds?

hCaptcha raises difficulty after each failure in a session and when the environment looks automated. A cleaner IP can lower the starting difficulty, but the browser and interaction signals decide whether it keeps escalating.

Does hCaptcha treat mobile carrier IPs differently?

Carrier addresses are shared by many real phones, so they are rarely treated as hostile outright. Their reputation is still shaped by what traffic comes from them, which is one reason we keep each line dedicated to a single customer.

Can I automate hCaptcha on my own site for testing?

Use hCaptcha's published test keys in development and staging, which are made for automated test suites. In production, sample the real experience manually or with low-volume monitoring through a carrier line.

Real US carrier IPs for hCaptcha

Dedicated 4G and 5G lines in eight US metros. Sticky sessions, unlimited rotation, HTTP(S) and SOCKS5. From $5/day.

View plans See all locations

More NeonProxies use cases

All NeonProxies use cases →