Residential Flex

How the package works, what each targeting option does, and how your login is built.

Residential Flex is a rotating residential gateway built for precise targeting: country, state or region, city, ASN, US postal code, and a device OS filter. You connect to one host; every connection leaves from a different real home IP unless you ask for a sticky session. All targeting lives inside the username, so the host, ports and password never change.

Connection details

Hosts
euf.geekproxy.net
usf.geekproxy.net
asf.geekproxy.net
Port
8888
Protocols
HTTP, HTTPS, SOCKS5 on the same port
Auth
Login + Password from the panel

Find your Login and Password in the Proxy Access block at the top of the subscription page. Three entry points, one pool: pick the host closest to your servers (Europe, US, Asia); the exit IP is chosen by targeting, not by the host. One port speaks all three protocols and detects which one your client uses; port 1080 works as an alias. UDP is not available on Flex: if your tool needs UDP, use Residential Turbo.

How the login is built

You don't type the username by hand. Pick options in the panel and the Proxy List gives you ready lines. Every option is appended to the login as a -key-value segment. Keys are separated by hyphens, which is why the login itself never contains one.

A fully-loaded username looks like this:

<login>-cc-us-region-california-city-los_angeles-asn-7922-os-windows-session-k3f9a2-ttl-30-speed-3:<password>@euf.geekproxy.net:8888
SegmentMeaning
<login>Your account login (from Proxy Access).
cc-usCountry, ISO-2 code. The base of almost every request; add the narrower options on top of it.
cont-euContinent instead of a country: eunasaasafoc. Use one or the other, not both.
region-californiaState or region, by name or ISO code (region-ca, region-bavaria). Always together with a country.
city-los_angelesCity. Spaces become _ or are dropped; English spelling (rome, not roma). Pair it with the country.
asn-7922Provider network by AS number, with or without the AS prefix. The most exact filter in the package.
zip-90210Postal code, letters and digits only. Exact in the US; outside the US it narrows to the city.
os-windowsOnly exits whose device is a Windows machine (by its TCP fingerprint, the way p0f sees it, not by the browser user-agent). Fewer exits, but the TCP stack matches a Windows browser profile.
os-androidDevices with a Linux-based network stack: Android, macOS and Linux. Use it when the profile is a phone, a Mac or a Linux machine.
session-k3f9a2Sticky session id: letters and digits, your choice. Same id, same exit IP.
ttl-30How long the sticky session holds, in minutes. Default 10, maximum 120.
strict-falseFallback mode: if nothing matches the narrow target, loosen it step by step (ASN, then postal code, then city, then region) but stay inside the country. Default is strict: no match means the connection fails instead of a wrong exit.
speed-3Exit race: when a sticky session starts, that many exits are tried at once and the fastest one is kept for the whole session. 1 to 10, needs session, costs no traffic. See Speed mode below.

Options combine freely, each at most once. A misspelled key or value is rejected at authentication rather than silently ignored, so you are never billed for traffic you didn't target.

Targeting depth

TargetWhat to expect
Country, ASN, continentDrawn from the whole pool. As fast and as available as an untargeted request. The country is always honoured.
CityExact for large metro areas (Berlin, London, New York, Los Angeles, Chicago, Miami). Smaller cities may briefly have no live exits: retry or add strict-false.
State / regionExact for US states and major European regions.
Postal codeExact in the US where inventory exists (a code with no live exits fails rather than drifting). Outside the US treat it as city-level.
os-windowsWindows devices are a part of the pool and the share varies by country, so expect fewer exits than without the filter. os-android selects Linux-based devices: Android, macOS and Linux. Other OS values are not supported.

Sessions

Rotation is the default: every new connection exits from a different IP, with no repeats in practice.

Sticky is opt-in: add session-<id> and every connection carrying that id goes to the same exit, including the dozens of parallel connections a browser opens for one page. The hold is 10 minutes by default and up to 120 with ttl. A session needs at least one targeting option (a country is enough); keep the options identical for the whole session and stay on the same host: a session started on one entry point does not carry to another. Use a fresh id per task: one per account, one per scraping job.

Warm the session up. The exit is pinned when the first request of a new id completes. Connections opened before that moment can land on other exits. Send one request alone, wait for the answer, then open your parallel load; a browser does this naturally because it fetches the page before its resources.

Speed mode. Add speed-N to a sticky session and the gateway tries N exits on the first connection, keeping the fastest. The session then starts on the fastest of the exits tried. The losers are dropped before any data is sent, but the target does see their TCP handshakes, several short connections from several home IPs. Harmless for scraping and browsing; for accounts on sensitive platforms keep speed at 1–3. Defaults: 3 for sticky sessions, 1 for account profiles, up to 10 for downloads.

Exits are real home connections and can go offline. When a session expires or its exit drops, the next connection under the same id silently gets a new IP. If an IP change would break your task, check the exit IP and start a new session id yourself.

Limits and ports

Parallel connectionsNo limit.
Speed per exitSet by the home connection behind the exit and differs from one exit to the next. With speed mode a sticky session starts on the fastest of several exits.
Open portsEverything, including 80, 443, 8080, 8443, 3306, 3389, 25565 and the mail inbox ports 143, 993, 110, 995.
Closed ports22, 25, 465, 587, 5060. Mail can be read through Flex but not sent.
DNSNames are resolved by the gateway, not on your machine. In clients that distinguish them, use socks5h:// rather than socks5://.
Traffic meteringCounted in both directions against your package balance. When the balance hits zero, new connections stop authenticating; open transfers are never cut mid-way.

Errors

ResponseMeaningWhat to do
407 (SOCKS5: auth failure)Login or password wrong, a typo in a targeting option, package balance exhausted, or account disabled.Check the username segment by segment; check the balance in the panel.
502 (SOCKS5: 0x04)No live exit matched the target, or the exit could not be reached.Loosen the target, add strict-false, or simply retry: the next connection is a different household.
504The exit did not answer in time.Retry. Treat 502 and 504 in scrapers as "next IP".
400An https:// URL sent as plain forwarding.Use CONNECT for HTTPS; any normal HTTP client does this by itself.

A small share of residential exits accept the connection and then stall. If a connection opens but nothing arrives, drop it and retry rather than waiting.

Quick start

  1. Pick a country. Add a state, city, ASN or US postal code only if the task needs it.
  2. Device type? Turn on the OS filter: Windows for Windows profiles, Android for Android, macOS and Linux profiles.
  3. Rotation or Sticky. For Sticky, set the session time (up to 120 min) and the speed level: 3 by default, 1 for accounts, up to 10 for downloads.
  4. Connection type, Format, Quantity. HTTP or SOCKS5, choose a format, set how many lines.
  5. Copy from Proxy List and paste the lines into your software.

Common mix-ups

"The country is right but the city is not."

Narrow targets depend on which exits are online right now. Retry, or add strict-false so the gateway falls back to the state and then the country instead of failing.

"My session changed IP."

Either the ttl ran out, or the home connection behind the exit went offline. Check the IP before the critical step and rotate to a new session id when it changes.

"The first requests of a session came from different IPs."

They were opened before the session was pinned. Make the first request alone and start the parallel work after it returns.

"407 with the right password."

A targeting typo fails authentication by design. Compare your line with the Proxy List output, and check that the package still has traffic.

Flex vs Turbo

Residential FlexResidential Turbo
Hosteuf / usf / asf.geekproxy.netrst.geekproxy.net
HTTP / SOCKS58888 (one port)8989 / 1080
Targetingcountry, continent, state/region, city, ASN, US postal code, device OS, strict/fallbackcountry, city
Stickyup to 120 min, by session id, optional exit race1–1440 min
UDPnot availablebuilt in (SOCKS5 port)
Portsall except mail sending (25, 465, 587), SSH and SIPall ports open

Pick Flex when the exit has to be exact: a specific ASN, a city, a US postal code, a Windows or a Linux-based device. Pick Turbo when you need UDP, open ports or raw throughput.

We use cookies to improve user experience. By clicking "Yes, I agree", you consent to this use of cookies.

Early Adopter Privilege: To mark our launch, we’re offering a [50%+ discount] on all datacenter subscriptions. Limited-time offer for our first partners.