12CE Proxy Lens中文

About 12CE Proxy Lens

Independent diagnostic tools

12CE combines proxy quality checks with browser/network observations. It is based on xykt/IPQuality and is not affiliated with Whoer or the risk providers. It does not certify safety or anonymity. Contact: [email protected].

Manual checks also report allowlisted project and entry-point names, result categories, explicit retries and timing, never scores, target IPs or diagnostic contents. Statistics respect opt-out and DNT/GPC and are retained for 30 UTC days. Dedicated access logs use fixed route categories, status codes and timing without query strings or raw IP addresses.

Privacy and data flow

Proxy credentials are submitted in the request body to our server to establish the connections you request. Do not put credentials in links. Risk providers receive the IP being queried. Provider API keys stay on the server.

DNS checks use random names on our authoritative node; resolver country enrichment uses an external provider. WebRTC contacts Google STUN without requesting a camera or microphone. Browser fingerprint observations are not uploaded or stored by the site. Precise location requires permission; sending coordinates to a map provider requires a separate click.

Both home pages automatically load the same basic overview and risk information. The 24 browser checks are available in both languages; WebRTC runs automatically on the home page and whenever Recheck is clicked, using Google STUN without camera or microphone access. Other deep network and location probes require a click. Standalone DNS, WebRTC and risk pages run only after a click. Hosting, reverse proxy and CDN services may keep access logs. This is not a promise of zero logging.

Exports are generated locally and omit IPs, credentials, locations, raw fingerprints and headers. Quota counters store provider, period and count—not credentials or visitor IPs. General rate-limit state is held in bounded memory. The single-IP lookup also persists HMAC-derived visitor/network and daily target identifiers, timestamps and counters, never raw addresses in its quota tables. IPv6 visitors share a /64 allowance; users behind a shared public exit may share limits. Previous-day records are cleaned on subsequent queries after the cross-day one-minute window. These identifiers are pseudonymous, not absolutely anonymous. Valid lookup results are cached in memory for one hour, failures for 60 seconds. Historical caches and infrastructure logs are separate. Historical result caches, when used, are labeled and must not be mistaken for current data.

First-party usage statistics

From September 11, 2026 (UTC) we collect page views, visible-page heartbeats and manual diagnostic start/end states. We do not store raw IP addresses, proxy credentials, reports, fingerprints, referrers or URL query strings in analytics. Daily rotating keyed IP identifiers estimate visitors; these are pseudonymous, not absolutely anonymous. Shared exits may merge visitors and network changes may count them twice. Data is restricted to administrators and retained for 30 UTC days. Aggregate overview request counters are separate from manual usage and do not identify visitors.

No identity cookies are used. Local storage only saves your opt-out preference. We honor DNT and GPC; the button cannot override those signals. Closing a page or blocking analytics can cause missing events. Infrastructure access logs are separate.

Methods and limits

Enter a single public IPv4 or IPv6 address on the homepage to query selected risk databases only. No proxy connectivity, streaming or browser-leak tests are performed in this mode. Limit: 2 requests per minute. The first 30 distinct targets per visitor per UTC day remain eligible for official APIs; additional targets use public endpoints only, without official-key consumption. Revisiting one of the first 30 retains eligibility. Public-only queries still share the site-wide budget. Per provider, this route has a site-wide cap of 20 cache misses/hour and 60/day; official attempts are capped at 10/hour and 30/day, including key rotation, in addition to existing global budgets. Concurrent identical lookups are merged. Retries do not bypass caches. Domain names, private addresses and batch lookups are rejected. Human verification is not configured; strict server-side rate limits and hard budgets apply.

Diagnostic reports (rule version v1) are generated locally without AI. They include evidence, remediation steps, retesting instructions and untested capabilities. JSON and text exports exclude raw addresses, credentials and fingerprints. Priority review thresholds are site rules: IPQS 90, Scamalytics 60, AbuseIPDB 75, or explicit recent-abuse / external-blacklist flags. These are not universal blocking thresholds. A score difference of 40 points prompts a provider-disagreement note, not a combined safety score.

The leak-check preset selects web exit, DNS, WebRTC, TLS, QUIC, IPv6 capability, JavaScript and privacy signals. It does not run until Start is clicked. Same-run public exits are compared only within one address family. Differences can reflect split routing or proxy rotation, not confirmed leakage. HTTP/2 fallback does not verify a UDP exit. IPv6-specific paths, kill switches, throughput, packet loss, long-term stability and playback remain unverified. Rerun the full group after changing settings.

Risk results may come from official APIs, public endpoints or historical caches. Different providers measure different signals. Missing scores stay unknown. Commercial proxy classification does not by itself prove abuse.

Media checks inspect connections and page features; they do not establish playback or subscription eligibility. DNS observes recursive resolver exits. WebRTC observes ICE candidates. Our current node does not validate IPv6. The domestic exit card queries myip.ipip.net (IPIP); the overseas exit card queries ipwho.is (IPWhois), both directly from the browser. Source details are kept here instead of repeated on the cards. Actual routes depend on your device and proxy settings; the overseas card does not establish the exit used for every overseas site.

Manual requests are rate-limited. Each risk/media worker has a 24-second network budget; proxy discovery runs first. The proxy page stops waiting after 45 seconds. Provider budgets may cause fallback to public endpoints, which can also reject or limit requests.

Updates

2026-09-09: the English interface now uses the same layout, controls and detection logic as the Chinese interface, including the complete environment overview, 24 browser checks, progressive results, individual retries and redacted reports. Original provider data and fingerprint probe inputs are preserved.

2026-09-08: private-address protection, visitor admission limits, persistent official API budgets, separate automatic/manual concurrency, DNS/WebRTC/risk pages and explanatory result summaries.