Carrier-grade NAT (CGNAT) is why your mobile traffic looks unidentified even when the visitor is a real prospect on a real device. Mobile carriers route thousands of subscribers through a tiny pool of shared public IP addresses to conserve IPv4 space, so the IP a reverse-lookup tool sees on a cellular session almost never maps to one company, or to any company at all. Most website visitor identification vendors report a single blended accuracy number built on demo traffic that's disproportionately desktop and Wi-Fi. If more than half your engaged sessions come from a phone on cellular data, as is true for most B2B sites today, your real match rate on that traffic is lower than the number on the pricing page, and almost nobody segments their reporting by connection type to catch it.
What CGNAT Actually Does to a Mobile Session
Every major mobile carrier, Verizon, T-Mobile, AT&T, and their international counterparts, ran out of enough public IPv4 addresses to give each subscriber's phone a unique one years ago. Their fix was Carrier-Grade NAT: thousands, sometimes tens of thousands, of devices on the same tower share a small block of public IP addresses at any given moment, with the carrier reassigning them constantly as sessions open and close.
To a website's server, every one of those devices looks like it's arriving from the same handful of IP addresses. A reverse-IP lookup has no way to tell a VP of Sales at a target account apart from a teenager streaming video on the same carrier tower, because as far as the network is concerned, they're the same address. This is not a privacy feature anyone opted into, unlike Apple's Private Relay. It's the plumbing that makes mobile networks work at scale, and it affects Android and iOS traffic alike, on any browser, the moment a device is on cellular data instead of Wi-Fi.
Why This Is a Different Problem Than "Mobile Traffic Is Just Lower Quality"
It's tempting to write off a low mobile match rate as a traffic-quality issue, fewer real buyers browsing on phones. That's not what's happening. The visitor is real. The intent can be real, someone forwarded a case study link into Slack and they opened it on their phone between meetings. What's broken is the identification method, not the visitor. A pure reverse-IP lookup, the same technique most account-level identification is built on, simply cannot resolve a CGNAT'd address to a company, because the address doesn't belong to one company, it belongs to whichever few thousand devices happen to be sharing it that minute.
That distinction matters for how you fix it. Traffic-quality problems get solved with better targeting. A CGNAT identification gap gets solved with a different resolution method entirely, because no amount of better ad targeting changes what IP address a carrier hands a phone.
Exposure by Identification Method
Not every approach to identification is equally blind on cellular traffic. Here's where the exposure actually sits, so you know which part of your stack to fix first.
- 🔴 Very High - Pure reverse-IP lookup as the sole method - the shared CGNAT address resolves to the carrier's network block at best, or nothing at all, with no fallback signal to fall back on.
- 🟠 High - IP-to-company databases tuned on desktop/office traffic - built and benchmarked against corporate IP ranges, these have effectively no coverage for carrier IP pools by design.
- 🟡 Medium - Device or cookie-based tracking without a person-level match - can re-recognize a returning device across sessions on the same carrier connection, but still can't tell you which company that device belongs to.
- 🟢 Low-Medium - Waterfalled, multi-source identification - when the IP signal is useless, a method that doesn't depend on it exclusively still has a path to a match.
- ⚪ Low - Identity graph matching against a consent-based publisher network - resolves a visitor from signals other than the live IP address, so a shared carrier IP doesn't block the match the way it blocks reverse-IP lookup.
The Audit: Find Your Real Mobile Match Rate
You almost certainly already have the data to run this. It takes your analytics platform and about fifteen minutes.
- Step 1: Pull engaged sessions by device type for the last 30 days. Split desktop from mobile (10+ seconds or 2+ pageviews, same engaged-session definition you use everywhere else). Note what share of engaged traffic is mobile before you look at anything else, most B2B sites are surprised it's the majority.
- Step 2: Compare identification match rate for each segment. If your platform can break out match rate by device type, put mobile next to desktop. A double-digit gap is CGNAT showing up in your numbers, not a fluke.
- Step 3: Check whether the mobile sessions that did match came from Wi-Fi-heavy content. Gated PDFs, pricing pages opened from a forwarded link, and return visits from an already-identified account tend to skew Wi-Fi. High-intent top-of-funnel traffic, LinkedIn ad clicks and cold outbound link opens especially, skews cellular. If your matched mobile sessions cluster in the first group, your cellular blind spot is bigger than the blended number shows.
- Step 4: Weight the gap by your actual buying committee. A signal that a champion opened your pricing page on their phone during a commute is exactly the kind of moment sales wants to know about. If your ICP skews toward roles that check email on mobile between meetings, this gap is costing you the highest-intent moments, not just volume.
- Step 5: Ask every vendor for a device-segmented number, not a blended one. "Accuracy" benchmarked mostly on desktop office traffic tells you nothing about what you'll actually see on the roughly half of your engaged sessions arriving from a phone.
What to Do About the Gap, Not Just How to Measure It
The fix isn't writing off mobile traffic, it's the same principle behind waterfall enrichment for website visitor identification: don't rely on one method that fails completely the moment the IP signal is useless. When a reverse-IP lookup hits a CGNAT wall, a second identification path that isn't purely IP-dependent still has a shot at resolving the visitor. Teams running a single-source, IP-only tool get nothing from that session. Teams running a waterfalled stack recover a meaningful share of it.
The reporting fix matters just as much as the tooling fix. Stop treating "unidentified" and "not your ICP" as the same bucket for mobile sessions specifically. A session your platform can't resolve to a company because of CGNAT, not because the visitor isn't a fit, deserves a lower-confidence nurture track rather than getting discarded, and it's worth re-checking that visitor's next session, since a device on Wi-Fi at their next login often resolves cleanly where the cellular session didn't.
In conversations with prospects evaluating identification vendors, a pattern comes up often enough to be worth naming directly: teams get quoted a single accuracy number in a demo, one that's rarely disclosed as having been measured against desktop-heavy, office-network traffic, and then are surprised when their own results, on a traffic mix that's often majority mobile, land meaningfully lower. That gap isn't the vendor lying. It's the vendor not being asked the right follow-up question. Segmenting by device type before you sign is the fix.
How This Affects Knock2's Own Numbers, and Why CGNAT Isn't Going Away
On mechanism: Knock2's person-level identification works by matching visitors against an identity graph built from a consent-based publisher network, not by depending solely on reading the visitor's live IP address. That's why it sits in the low-exposure tier above. It's not immune, though. Company-level resolution still benefits from a clean IP signal when the identity graph doesn't return a match, so CGNAT is a real headwind on that side even in a waterfalled approach, just a smaller one than for a single-method tool.
Knock2 publishes two identification rates, both measured against engaged sessions: 93%* for account and company-level identification, and 62%* for person-level identification (name, email, title), US traffic only. Both carry the same footnote: identification rates are measured against engaged sessions, and results vary by traffic profile, geography, and industry, device and connection type included. If you want a real read on your own mobile-segmented match rate against a waterfalled identity graph instead of a blended vendor average, that's worth fifteen minutes of your team's time before your next renewal conversation.
CGNAT is also structural, not a bug that gets patched. IPv4 address space isn't expanding, and mobile data usage keeps climbing every year, so carriers have every incentive to pack more devices behind fewer public addresses, not fewer. Treat a mobile identification blind spot as a permanent feature of how you build match-rate reporting, the same way you'd treat the single-page-app virtual pageview problem or a Safari-specific dip, not a temporary gap that resolves itself. Once you've got a real, device-segmented read on your match rate, our guide to vetting a vendor's accuracy claims and our breakdown of why no two match-rate numbers ever agree are the natural next reads.
FAQ
Does website visitor identification work on mobile traffic?
Partially, and less reliably than on desktop. Mobile traffic on cellular data routes through carrier-grade NAT (CGNAT), which shares a small pool of public IP addresses across thousands of devices, so pure reverse-IP lookups usually can't resolve it to a company. Identification methods that don't depend solely on the live IP address, like an identity graph, hold up better.
What is CGNAT and why does it break B2B visitor identification?
Carrier-Grade NAT is how mobile carriers conserve IPv4 addresses by having many subscriber devices share the same small set of public IPs at once. A reverse-IP lookup can't tell which of thousands of devices behind that shared address made a given visit, so IP-to-company matching effectively fails on that traffic.
Is a low mobile match rate a sign of bad-quality traffic?
No. The visitor is usually real; the identification method is the limiting factor, not the visitor's fit or intent. Don't route unidentified mobile sessions out of your funnel by default, treat them as a lower-confidence match worth a second look rather than a disqualification.
Does mobile Wi-Fi traffic have the same problem as cellular?
Generally no. A phone on home or office Wi-Fi uses that network's IP, which behaves like any other broadband or corporate connection for identification purposes. The CGNAT problem is specific to cellular data connections, not to mobile devices as a category.
How do I ask an identification vendor about their mobile accuracy?
Ask for match rate segmented by device type or connection type, not a single blended accuracy figure. A vendor that can't produce that breakdown is likely benchmarking on desktop-heavy demo traffic that won't reflect your actual mobile-majority results.
Want a real read on your mobile-segmented match rate instead of a blended vendor average? Book a Knock2 demo and find out how much of that traffic is actually recoverable.
*Identification rates measured against engaged sessions. Results may vary by traffic profile, geography, and industry.




