Guide 01 · Select

How to choose a VPS

Spec sheets are marketing. This is how to see through them — pick a box that isn't secretly throttled, judge residential-IP quality, and prove it with a ten-minute benchmark before you pay.

00Start here — a VPN network from China

Building your own VPN or residential-exit network from mainland China? The right order isn't specs or price — it's this, with the actual boxes we have run and measured for each role.

1 · In China, the network comes first

Latency and route quality beat cores and RAM — if the route is bad, no CPU saves it. So the first question for any box is how it reaches China, ideally over the premium CN2 GIA backbone (see the route table below).

2 · The jump host — a GIA datacenter box

Your encrypted entry point (the relay) should be a datacenter box on a real GIA route. The two standout CN2 GIA options are BandwagonHost and DMIT — both confirmed on the premium 59.43 backbone (route table). We run BandwagonHost as our CN2 GIA jump host (~130 ms to China, 0% loss, dependable and always in stock); the cheap DMIT Los Angeles AS3 (~131–155 ms) is the standout value alternative — benchmarked and rated, it undercuts BandwagonHost on price when it's in stock. (DMIT also offers Hong Kong and Tokyo regions that sit even closer to China — worth a look for an Asia-side entry.)

A premium alternative — a private leased circuit (IPLC). Both jump hosts above ride the public internet, just over a premium CN2 GIA backbone. A 沪美 Shanghai–US IPLC (International Private Leased Circuit — the tier we tested is from mkcloud) is a different class of entry: the China↔US hop runs on a dedicated private line that never touches the public internet, so it doesn't cross the GFW the way an ordinary route does. The payoff is the steadiest China route money buys — a consistent ~160 ms round-trip (124–134 ms in-circuit), low jitter and near-zero loss, plus high raw bandwidth (~100 Mbit/s to well-peered targets, roughly double a typical 50M plan). The catch is cost and reach: it runs several times the price of a CN2 GIA jump host, and its ingress is province-locked — only clients on one Chinese province's network (Shanghai Telecom, here) can connect. Reach for it when China-route stability is the axis you're optimizing and the budget allows; the CN2 GIA jump host stays the sensible default.

▲ The IPLC trade-off, in numbers
The tier we benchmarked: 2 vCPU / 4 GB / 40 GB, 2 TB/mo traffic, 300 Mbps peak, traffic-billed at ¥698/mo (~$102) — against ~$17–30 for a CN2 GIA jump host (a 1 TB tier runs ~¥428/~$63). One thing to plan for: the IPLC is the entry and route, not a residential IP. Egress on its own datacenter IP and you get the full circuit bandwidth — and, measured properly, chaining a residential exit behind it costs you almost nothing: we clocked 100–102 Mbit/s end-to-end through one residential exit (Frontier LA) and 81–115 through another (Hawaiian Telcom HI) — the circuit's full rate, not some lower exit-side ceiling. The spread on the second one is a measurement lesson in itself — see below. We previously published a ~50–60 Mbit/s ceiling here — that was our own single-stream test under-reading a 200 ms path, not the network. See “your speed test can be the bottleneck”. Need a home IP and the stable route? You still buy a separate residential box.
▲ Two IPLCs aren't equal — check the US exit
We benchmarked a second 沪美 IPLC — a UCloud 8 Mbps dedicated line (~$130/mo) — against the mkcloud tier, and the deciding factor was the US-exit architecture. mkcloud egresses through a route-optimizer (Nearoute): its “US exit” isn't really in the US — every packet routes back through the circuit, so the box pings US targets at ~142–170 ms and peers unevenly (170 ms to Cloudflare vs 142 to Google). The UCloud line gives a genuine LA datacenter exit~1 ms to US targets — on a slightly faster ~124 ms circuit. Net result: the real-US-exit IPLC is ~17–45 ms lower latency end-to-end, and as a jump host to a residential exit it stays ~17–25 ms ahead of every one. The catch is the mirror image of mkcloud's: 8 Mbps dedicated/unmetered vs ~100 Mbps burst, a China-Unicom ingress (not Telecom), and every residential exit's provider must IP-whitelist the IPLC's egress before it can reach them. Quick test: ping 1.1.1.1 from the exit box — ~1 ms = real US exit; ~150 ms = circuit-routed. A clean latency-vs-bandwidth trade — pick per use.
▲ A route-optimizer exit can peer badly to one provider — fix it with a transit
A circuit whose US landing is a route-optimizer (like Nearoute) doesn't peer to every residential ISP equally. We hit a case where the mkcloud IPLC reached one AT&T-LA exit at a fine ~96 Mbit/s up but only ~10 Mbit/s down — a broken US-landing→exit leg, not the circuit and not the exit (both were healthy on their own). The rescue: route the IPLC through a clean LA transit box you control (a cheap datacenter VPS) on the way to the residential exit — swapping the bad US hop for a good one lifted that download ~4× (10 → 37+ Mbit/s), and picking a better-peered exit (Frontier over that AT&T box) took it to ~53 Mbit/s. (All three figures come from the same single-stream test; a parallel-stream re-measure of that repaired path later read 102 Mbit/s. The ratios are what matter here — the absolutes were low.) So if a chained residential exit underperforms, suspect the circuit's US-landing→exit peering before blaming the exit — an interposed LA transit is a cheap, reversible fix.
▲ Chaining a US relay behind the circuit — the network matters, not the box
If your residential exit is IP-restricted or sits on a congested direct path from the circuit's US egress, you slot a small US-side relay VPS (a plain SSH port-forward) between the two. Counter-intuitively, the relay's hardware is irrelevant — an SSH forwarder needs almost none — and a premium network can be worse than a plain one. We tested it: mainstream transit VPS (BandwagonHost, Vultr, DMIT, Akamai/Linode) all hit the circuit ceiling (~40–140 Mbit/s), but two premium anycast/BGP clouds — Google Cloud and Zenlayercollapsed to ~0–12 Mbit/s despite the cleanest idle latency, because the leased circuit's egress peers poorly into their BGP fabrics (a PMTUD/peering issue that idle ping hides). It's not simply “big clouds are bad,” though — we also tested AWS (a giant anycast network) and it peered fine (~130 Mbit/s). The real rule is narrower: a few specific networks (here, GCP and Zenlayer) collapse from a given egress; most don't. So test every candidate with a real throughput run — never judge by brand or by idle ping. And weigh cost separately: a plain, flat-rate LA VPS beats a metered cloud for a bulk-moving transit (AWS bills ~$0.09/GB egress — brutal when moving traffic is the whole job).
US-side relay (transit)NetworkThroughput from the circuit egress
Vultr · Los Angelesplain transit~50–95 Mbit/s✓ works — adopted
BandwagonHost · LAplain transit~50–70 Mbit/s✓ works
DMIT · LAplain transit~40 Mbit/s✓ works
Akamai / Linode · LAplain transit~40–140 Mbit/s✓ works
AWS EC2 · LA Local Zonebig cloud (anycast)~130 Mbit/s✓ works — but metered egress
Google Cloud · us-west2premium anycast BGP~0 Mbit/s✕ fails — both Premium & Standard tiers
Zenlayer · LApremium BGP~12 Mbit/s✕ fails

The punchline, from both premium clouds: Google Cloud benched #2 in our whole fleet on raw hardware (top-tier CPU and disk) yet delivered ~0 on this route, and Zenlayer had the lowest idle latency of any transit we tested (~159 ms) yet still managed only ~12 — the cleanest ping on the board, still a broken route. The box and the ping were never the problem; the peering was. Only a real throughput test under load exposed it. Premium clouds also bill egress by the gigabyte (Google ~$0.12/GB → four figures per month if saturated), so they lose on cost too. For a transit hop, plain and well-peered beats premium every time.

A cheaper third class — two boxes on one cloud's own private backbone. An IPLC is not the only way to get off the public internet. Buy a pair of VMs from the same Chinese cloud — one in a China region, one in a US region — and the hop between them can ride that cloud's internal backbone (Tencent calls it CCN / 云联网) instead of the open internet. We tested a Tencent 华东 + T1 美国 pair from the reseller po0, and on the private path it measured 135 ms in-circuit with 0.02 ms jitter and 0% loss, at ~1.2 Gbit/s — faster and steadier than the leased circuit, for a fraction of the price. The same two boxes over their public IPs managed only 170–185 Mbit/s at 156 ms with 20% ICMP loss, so the private path is the entire product: if a provider offers this, make sure you are actually on it.

▲ Where this one actually costs you: traffic, not speed
The entry tier we ran is ¥159.99/mo (2 vCPU / 2 GB, 200 Mbps) plus ¥98.99/mo for the US side — about ¥259/mo (~$36) all-in, against ¥698 for the IPLC tier above. But it ships only 100 GB/month on the China box, which at full rate is roughly two and a half hours. That quota, not bandwidth, is the real limit.

And here the pricing inverts in a way worth knowing: because the chain is capped by the residential exit (~100 Mbit/s), paying for a faster tier buys nothing — you need more traffic, not more Mbps. The annual plans deliver exactly that and cost less than the monthly one: ¥999/yr (200 GB, 200 Mbps) works out to ¥83/mo — half the monthly price for double the traffic — and ¥1,618/yr (600 GB) is ¥135/mo, six times the traffic and still under the monthly tier. If you buy this class of line, buy it annually and buy it for the traffic.

Two more things to plan for: the China box blocks 80/443 in both directions (so the entry cannot live on a standard TLS port, and even apt needs a proxy through the US side), and the product requires real-name registration.

Two resellers, and the spec sheet that decides between them. This cloud-backbone product is sold by several Chinese resellers of the same underlying Tencent service — we have run po0 and guguyun. Both carry the identical port restriction (80/443/1080/8000/8080/8443 blocked in both directions) and both deliver the private backbone, so the choice comes down to the two numbers on the spec sheet that are easiest to misread.

▲ 单向 vs 双向 — the allowance comparison that traps people
Chinese hosts quote traffic as either 单向 (one direction billed) or 双向 (both directions billed). A relay box carries your payload twice — in on one interface, out on the other — so a "double" allowance is not double the usable transfer. po0 quotes 200 GB 单向 at ¥83/mo; guguyun quotes 888 GB 双向 at ¥388/mo. Those are not 4.4× apart in usable terms, and depending on how the provider counts the private-backbone leg they can land far closer than the sticker suggests. Always convert to "GB of payload I can actually move" before comparing price.

The tiers, for reference. Shanghai BGP entry: ¥139 (200 Mbps / 233 GB) · ¥268 (500 / 399) · ¥388 (500 / 888) · ¥888 (1000 / 3888) · ¥2,333 (4 vCPU, 1000 / 9999) · ¥4,399 (1000 / 18888). US T1 exit: ¥89 (200 Mbps / 1314 GB) · ¥178 (1000 / 4399). The same seller also lists Guangdong, Hong Kong, Shenzhen, Xiamen CN2, an IPLC line, and overseas regions including Los Angeles, Tokyo, Seoul, Singapore and Frankfurt.
■ Corollary: buy the traffic tier, not the bandwidth tier
These entries scale bandwidth and traffic together, which tempts you upward. But if your chain ends at a residential exit, that exit is your ceiling — we measure ours at ~100 Mbit/s. A 500 or 1000 Mbps entry cannot deliver more than the exit will accept, so every yuan spent above ~200 Mbps is wasted while the traffic allowance is the thing you genuinely run out of. Pick the cheapest tier that clears your exit's speed, then buy as much traffic as you can on top of it — and prefer an annual plan, which on the seller we measured cost less per month than the monthly one while carrying more transfer.
■ The rule this taught us: stop buying circuit once the exit is the limit
That pair does ~1.2 Gbit/s between China and the US, and yet end-to-end through a residential exit it delivers 96–104 Mbit/s — which is 96% of what that exit can do on its own. The circuit contributes nothing to the ceiling. Two independent tools agreed on the figure to within 12%, whereas on our slower lines the same two tools disagreed by up to 4.5×: when a line is exit-bound, its number stops depending on how you measure it. So once your circuit outruns your exit, more circuit is wasted money — the next upgrade is a faster residential exit, or nothing at all.

3 · The residential exit — pick by what you need

Roster note: this list is deliberately every box we have bought, not just the ones still running — a purchase guide is more useful with the discards in it. SolaDrive, the VirVM box, the old Frontier exit and the leased-IPLC entry have since been dropped; their numbers stay because what they measured is still true. Anything we bought purely to test and then deleted is in the network builder under Tested & rejected.

The second box is the residential exit, where you egress on a real home IP. All five we have run are genuinely clean residential IPs (purity table); they differ on speed and route:

If you want…PickWhy
Best all-round performanceSolaDriveExcellent all-round — near-top disk, ties the datacenter boxes on multicore, clean IP, 0% loss to China. The default exit for a fast, reliable route.
Lowest latency / best routeVirVMClean IP, 0% loss, slightly faster to China than SolaDrive — and 8 GB RAM.
Just a clean IP, speed irrelevantAaITRGenuinely residential and clean, but low I/O and lossy routes — pick it only when throughput and latency don't matter.
Strongest hardware, or a Hawaii / Pacific egressQQ.pwFastest single-core CPU, memory and disk read IOPS in the fleet, and a clean IP (Netflix + ChatGPT native), but a higher-latency, lossier China route (no CN2, ~190–240 ms). A niche or geo pick — not a latency play.
An exit nobody can expire on youOwn hardware, colocated (we run a Mac mini on a T-Mobile line)Every rented residential box eventually lapses, gets recycled to a new tenant, or IP-whitelists your new upstream out. Hardware you own does none of that. It costs more per month once you add colo, connectivity and a KVM — and mind the ISP-class caveat below: ours is cellular, not wired.

That chain — BandwagonHost jump host → SolaDrive or VirVM exit — is the whole recommendation. QQ.pw (Hawaii) has the strongest hardware and a clean IP but the weakest China route of the four, so it's a niche add, not the default. Everything below is how to verify each of these choices for yourself.

▲ Ask how the “home broadband” is actually delivered
A colocation provider offering a US residential line may hand it to you as a phone with a data SIM, tethering — not a home gateway. Ours was, and the difference is not cosmetic: a leased line shrugs off a speed test, a phone hotspot does not. We ran one ordinary ~100 Mbit/s benchmark and the link died 13 minutes later, for 21 hours. Over the following days it measured 74.9% uptime and its exit IP rotated four times in two days. Before buying, ask three questions: what device terminates the line, is there any SLA, and can I reach that device myself to restart it. Ours was sold “with ADB access” and the phone turned out to be unreachable from our own machine — so every outage needed the vendor.
▲ Test the exit from a client, never from the box itself
If you run a proxy on a remote machine and then open an IP-checker in that machine’s own browser, you will usually see the wrong address. A proxy is not a system-wide VPN: the browser on the host does not use it and takes the machine’s default route instead. We lost real time to this — the residential pin looked broken for days while it was working perfectly, because every check was measuring a different path. On a dual-homed box, verify with curl --interface <iface> for the link itself, and from an actual VPN client for the chain.
▲ “Residential” and “cellular” are not the same purchase
A 5G / fixed-wireless home line (T-Mobile Home Internet and friends) feels like a residential exit and is not filed as one. IP2Location returns MOB (Mobile ISP) rather than ISP (Fixed Line ISP), and MaxMind lists cellular as a value separate from residential. Any rule that literally tests “is this residential” therefore will not match it — a class difference, not a rounding error. Two more things to price in before buying: these lines are CGNAT, so thousands of strangers share your address and its reputation — Cloudflare’s own published measurements show CGNAT IPs are rate-limited roughly 3× more often despite scoring lower on bot signals — and a mobile subscriber IP can re-home between towers, which breaks anything that assumes a stable address. It is a fine general-purpose egress, and a poor choice for banking step-up, account-recovery flows or streaming home-location checks. If you need “looks like a house”, buy a wired ISP.
▲ You don't always need a residential exit
If you want a clean datacenter IP and the lowest possible latency rather than a US home address, you can skip the residential hop entirely: a low-latency box like DMIT can be your direct exit — you connect to it and egress right there on its own datacenter IP (a two-hop client → box → internet instead of the three-hop residential chain). It's a datacenter IP, flagged as hosting, so pass on it when you specifically need residential trust — but for a fast, clean, geo-specific exit it's the simpler route (DMIT's Asia regions sit especially close to China).

01The first fork: residential or datacenter?

Before any spec, answer one question: does your traffic need to look like a home user, or just be fast? That single fork decides everything else.

NeedPickWhy
Websites, APIs, apps, backupsDatacenterFar more compute, memory, disk and bandwidth per dollar. The IP being flagged as "hosting" is irrelevant — nobody's checking.
Look like a real person (scraping, ad verification, social ops, region-locked access)Residential exitA genuine consumer-ISP address (Comcast, Spectrum, Verizon, Cox…) that anti-fraud systems trust. Weak hardware, but that's not the point.
Both — speed and a clean home IPBoth, chainedA fast datacenter relay in front of a residential exit. That's the whole second half of this guide.
▲ The trap
People buy an expensive residential VPS expecting datacenter performance, or a cheap datacenter VPS expecting a clean residential IP. Decide which axis you're paying for first, then optimize only that one.

02Reading the spec sheet — what matters, what's a lie

Providers list numbers that sound impressive and hide the ones that hurt. Here's what each line actually tells you.

The spec saysWhat it really means
vCPU countA share of cores, not cores. "4 vCPU" on an oversold host can be slower than "2 vCPU" elsewhere. Count means nothing without a per-core benchmark.
CPU modelOften masked (a generic "QEMU Virtual CPU" or bare "Skylake"). A masked CPU can be secretly great or a decade-old Xeon — you can't tell without running it.
"NVMe SSD"The device is fast; your allowance may not be. Many budget tiers cap you to a few thousand IOPS regardless of the disk underneath.
Bandwidth ("1 Gbps port")The port speed, not your sustained throughput. Real transfer is set by peering, contention, and sometimes a soft per-VM cap.
RAMThe one number that's usually honest. Still worth confirming the bandwidth if you do memory-heavy work.
Location / "Los Angeles"Where the company is, not always where the IP geolocates. Registrant-address artifacts routinely put a box on the map a few states from where it physically sits.
✕ Don't trust
vCPU count, "NVMe", "1 Gbps", and marketing CPU names — in isolation. Every one of them can be true on paper and useless in practice.
✓ Do trust
Numbers you measured, on that box, with the same method every time. The next section is how.

03Residential-IP quality (if you're buying an exit)

For an exit, the hardware barely matters — the IP's reputation is the product. Two boxes on the same "residential" plan can be night-and-day. Check four things:

  • Real ISP, real ASN. Look up the IP's autonomous system. A genuine eyeball ISP — a big consumer broadband/cable/fiber network (Comcast, Charter/Spectrum, Verizon, Cox, CenturyLink…) — is what you want. A hosting ASN dressed up as "residential" is not.
  • "Residential VPS" ≠ home line. Some providers rent VPS on IP blocks that register as an ISP but are really datacenter allocations (netname hints like *-CGNT, registrant under a transit carrier). Sophisticated anti-fraud detects these as non-residential.
  • Reputation score. Run the IP through a fraud/abuse scorer. A low abuse score and no "proxy/hosting/mobile" flags is the goal. A brand-new residential IP that's already flagged has been abused by whoever had it before you.
  • Geo sanity. Confirm the IP geolocates where you expect. MaxMind-based lookups lag reality and inherit registrant addresses — verify with more than one source.
▲ Ranking rule of thumb
Large consumer ISPs blend in best (huge, clean subscriber pools). Regional ISPs are fine. A "residential VPS" on a transit-owned block is the weakest — usable, but detectable.

IP purity — our residential IPs, checked

The reputation checks above, run on our own residential boxes (2026-07-02, aggregating Scamalytics / IPQS / AbuseIPDB / IPinfo / IP2Location). The question that matters: does the IP read as a real home line, and is it clean?

ProviderClassified as Fraud score/100 AbuseNetflix
SolaDriveResidential ISP · 4/5 sources00% · cleanNative
VirVMResidential ISP · 5/5 sources180% · cleanNative
AaITRResidential ISP · 5/5 sources130% · cleanNative
QQ.pwResidential ISP · 5/5 sources70% · cleanNative

All four read as a genuine residential ISP line (not hosting-in-disguise), with near-zero fraud and abuse scores and native Netflix — exactly what an exit needs (QQ.pw also unlocks ChatGPT natively). One caveat: a single scanner (IPQS) flags "proxy" on the boxes we run a proxy service on — the underlying IP reputation is clean. And a clean IP isn't enough on its own: AaITR's address is spotless, yet its route (below) drops 40–70% of packets, and QQ.pw's Hawaii line is clean but higher-latency. Check purity and route together.

04Benchmark before you buy — the ten-minute method

Most providers rent an hourly or trial box. Spin one up, run the same four tests on every candidate, then destroy it — identical commands each time is what makes numbers comparable. Four axes are worth measuring:

  • CPU, single- and multi-core. sysbench events/second — one thread, then all cores.
  • Memory bandwidth. A sysbench read + write pass, in GB/s.
  • Disk, 4K random IOPS. Where the caps hide — test fio against a temp file, never a raw device.
  • Network throughput. Pull 500 MB+ so TCP slow-start can't under-report exactly the fast links you're ranking — and on a high-latency path (a China↔US route, an IPLC), size the transfer to the bandwidth-delay product or use parallel streams, or you will measure your test tool instead of the link.
▲ The exact commands live in the skill
The sysbench, fio and curl one-liners — with the OpenVZ fallback and safe nice/ionice deprioritization — are all in the deploy skill's benchmarking section, ready to hand to your agent. This page stays command-free on purpose.
✓ Turn it into one number
Score each metric as a percentage of the best box you've tested, then average them. A single 0–100 rating makes "which VPS is better overall" a glance instead of an argument. The score tool does this for you.

Example: a real fleet, every axis

The same uniform pass on the boxes we have run — CPU, memory, network and disk, one row per box, real measured numbers (only the IPs are withheld). Stronger values tint blue, weaker red; scroll sideways for every axis.

ProviderTier Overall/100 Price$/mo Valuept/$ CPU 1-coreeps CPU all-coreeps Mem readGB/s Mem writeGB/s Net ↓Mbps Disk readIOPS Disk writeIOPS
QQ.pwresidential · 2C · 2GB85$35.002.432,2904,5107241300130,000108,000
SolaDriveresidential · 4C · 4GB70$40.001.751,3235,3444426569109,775113,304
BandwagonHostdatacenter · 4C · 4GB66$56.991.161,3775,35243242,28057,31848,246
BandwagonHostdatacenter · 3C · 2GB59$30.001.971,3764,20641221,77455,49951,469
DMITdatacenter · LA · 2C · 2GB42$16.902.49 ★ best value1,4302,791382096423,00017,000
VirVMresidential · 4C · 8GB29$65.990.444311,72223199438,81346,692
AaITRresidential · 2C · 2GB12$21.900.5529058117131022,0182,018

Overall is the equal-weight 0–100 average of all seven columns, each scored against the best box (exactly what the score tool does). Adding QQ.pw — the fastest single-core CPU, memory and disk read IOPS in the fleet — re-based every column, so the numbers shifted: QQ.pw tops the balance score at 85, but that is a hardware figure. It is a weaker exit than SolaDrive or VirVM, because the axis that matters most for China — route and latency (the route table below) — is the one it loses on. Among the rest, SolaDrive still wins on disk (110k IOPS) for a strong all-round 70; AaITR is pinned near a ~2,000-IOPS cap and starved on network; BandwagonHost is the balanced datacenter pick. DMIT (Los Angeles) lands mid-table at 42 — strong CN2 CPU and route but deliberately modest disk and bandwidth, the lean profile a relay actually needs. Read Overall as a hardware balance, not an exit ranking — fast hardware isn't a fast route.

Value = Overall ÷ list $/mo (points per dollar), each box against its own plan's price. DMIT's $16.90 Los Angeles AS3 — a cheap CN2 GIA jump — is the new value leader at 2.49 pt/$ when it's in stock (that AS3 tier sells out fast), just ahead of QQ.pw (2.43) and BWH 3C·2GB (1.97); a jump host barely touches disk or bandwidth, so its weak numbers there cost it nothing in the role that matters. VirVM lands last at 0.44 pt/$ — a flat $65.99/mo for its 100 Mbps tier. But value here is hardware per dollar — for a China exit, weigh the route table just as heavily.

Network quality — routes to China

Raw throughput isn't the whole story for China access — the route is. Measured from each box (ping + nexttrace, 2026-07-02): the path class to China's three networks and the round-trip latency + packet loss. Lower latency tints blue; loss is red.

ProviderRoute to China 电信 CTms 联通 CUms 移动 CMms Lossworst net
BandwagonHostCN2 · 59.43 backbone1291561540%
DMIT · LACN2 · 59.43 backbone1311551990%
mkcloud · IPLC沪美 · private leased circuit160low
SolaDrive163 · direct (AS4812)1751991950%
VirVM163 · direct (AS4812)1581662010%
AaITR163 · unstable13728522040–70%
QQ.pw163 · Hawaii, via US west coast18823923613–20%

BandwagonHost rides CN2 (the 59.43 backbone) — ~130 ms and zero loss, the premium China route. DMIT (Los Angeles) shares that CN2 backbone, matching BandwagonHost at ~131–155 ms with 0% loss to Telecom and Unicom (the Mobile figure is unreliable — that test anchor rate-limits ICMP — so read the CN2 path as clean). The mkcloud 沪美 IPLC is a different animal entirely — the Shanghai↔US hop rides a private leased circuit rather than public transit, so it holds a steady ~160 ms (124–134 ms in-circuit) with near-zero loss and none of the usual GFW-crossing jitter; the dashes flag its one hard limit — ingress is province-locked to Shanghai Telecom, so Unicom and Mobile clients simply can't reach it. The residential boxes take standard 163 peering: workable latency, and SolaDrive/VirVM hold 0% loss — but AaITR drops 40–70% of packets to Unicom and Mobile. QQ.pw's Hawaii line looks geographically closer to Asia, but its transit hairpins back through the US west coast (Cogent / HE / Lumen) before crossing — so it lands at ~190–240 ms with 13–20% loss to Telecom and Mobile, the slowest of the four despite the strongest hardware. A cheap residential IP can have genuinely broken network quality, so a clean address isn't enough — test the route and loss, not just bandwidth.

05Red flags the benchmark exposes

  • The ~2,000-IOPS wall. Disk read and write landing on the same suspiciously round number (~2,000) is a provider QoS cap, not a slow disk. Budget residential tiers love this. Real NVMe does tens of thousands.
  • Oversubscription. A CPU score far below the model's spec, or that swings run-to-run, means you're sharing a packed host. Test at a few different hours.
  • Bandwidth throttle. A "1 Gbps" box that tops out at a suspiciously flat ~50 or ~100 Mbps has a soft per-VM cap.
  • Burst vs. sustained. A short disk test can flatter a box that's fast for two seconds then collapses. If it matters, run 60–120s.
  • Geo mismatch. The IP maps somewhere you didn't expect — a problem for region-locked use cases.
✕ The lesson
A cheap VPS and a pricey one can differ 50× on the axis you care about — and the spec sheet will show them as near-identical. Only your own numbers tell the truth.

06Decision checklist

  • Decided the axis I'm paying for: speed (datacenter) or clean IP (residential) — or both, chained.
  • Benchmarked a trial box with the identical four tests (CPU, memory, disk IOPS, network).
  • Confirmed disk isn't capped (IOPS not pinned to a round number).
  • Confirmed CPU is stable across a couple of hours (not oversold).
  • For an exit: verified a real consumer ISP/ASN, a clean reputation score, and sane geolocation.
  • Turned the numbers into one 0–100 score and compared candidates side by side.

Got your box? The next guide wires it into a real network.