DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
IP Intelligence

VPN Detection: How Websites Tell Whether an IP Uses a VPN

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Websites usually detect VPN use by matching your public source IP with IP-intelligence data. Those databases label addresses associated with VPNs, proxies, Tor exits, relays or hosting providers. The result describes the network address visible to the site; it does not prove who is using it, why they are using it, or that the connection is malicious.

Detection is probabilistic. A provider can miss a VPN, classify it only as a hosting network, or see a normal residential address when a residential proxy is involved. Location signals such as DNS routing, browser permissions, cookies, WebRTC and device services are separate checks.

What a website can actually see

An HTTP server normally receives the public address that reaches its edge or reverse proxy. With a VPN, that address is generally the VPN server’s exit address rather than the user’s ISP address. An IP-intelligence service can then return network ownership, anonymizer categories and recency information.

MaxMind’s IP Risk documentation distinguishes anonymous VPN, hosting provider, public proxy, residential proxy and Tor exit-node fields, and can include a provider name and network last-seen date. IPinfo describes a privacy-detection API covering VPN, proxy, Tor, relay and hosting-provider categories. These are vendor descriptions of their methods, not a universal accuracy guarantee.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

The important distinction is between “this address resembles anonymizer infrastructure” and “this person is using a VPN.” The first is an address classification. The second is an identity claim the IP alone cannot establish.

How IP-based VPN detection works

  1. Capture the correct source address. Read the address supplied by your trusted load balancer or web server. Do not blindly trust an arbitrary X-Forwarded-For value sent by a client.
  2. Normalize it. Parse IPv4 and IPv6, remove surrounding whitespace, and reject malformed values. Keep the original address for audit purposes only when your privacy policy permits it.
  3. Look it up. Query a maintained IP-risk database or API. Inspect separate fields for VPN, proxy, Tor, relay, hosting and residential-proxy classifications rather than reducing everything to one boolean.
  4. Record context. Store the provider or network name, confidence or category supplied by the vendor, and any last-seen date. A recently observed anonymizer range is stronger evidence than an old, indirect listing.
  5. Apply a proportionate decision. Use the result as one input to a challenge, review or rate-limit policy. Do not automatically equate a VPN flag with fraud.

Why hosting-provider results matter

Some VPN services operate on infrastructure registered to hosting companies. MaxMind notes that a provider’s subnets may therefore be flagged as hosting-provider addresses when they are not registered under a recognizable VPN name. Hosting is a useful clue, but it is not proof: a legitimate customer may be connecting from a cloud server, corporate network or privacy relay.

What the classifications mean

Signal What it indicates What it does not prove
VPN The address matches a known or inferred VPN network. The user’s identity, intent or account risk.
Public proxy The address is associated with an openly available proxy. That every request from the address is abusive.
Tor exit node The address is an exit point for Tor traffic. Who originated the request.
Hosting provider The address belongs to data-center or hosting infrastructure. That it is definitely a VPN; ordinary cloud users can have the same classification.
Residential proxy The address appears to come from a residential ISP but is used as an intermediary. A reliable way to separate it from every ordinary household connection.
Relay The vendor associates the address with a relay or privacy service. A specific browser, device or person.

How reliable is VPN detection?

No single flag is definitive. MaxMind says its database identifies only a subset of VPN providers and may fall back to hosting classification when provider networks are not registered under associated names. Databases also change as services add addresses, abandon ranges or rotate infrastructure.

Residential proxies are particularly difficult because their addresses can look like legitimate ISP customers. Conversely, a corporate VPN, university gateway or cloud workstation may be identified as hosting infrastructure even when no consumer VPN app is involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
GL.iNet GL-SFT1200 Opal Travel Router, AC1200 Dual-Band Wi-Fi
  • 【AC1200 Dual-band Wireless Router】Simultaneous dual-band with wireless speed up to 300 Mbps (2.4GHz) + 867 Mbps (5GHz). 2.4GHz band can handles some simple tasks like emails or web browsing while bandwidth intensive tasks such as gaming or 4K video streaming can be handled by the 5GHz band.*Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【Easy Setup】Please refer to the User Manual and the Unboxing & Setup video guide on Amazon for detailed setup instructions and methods for connecting to the Internet.
  • 【Pocket-friendly】Lightweight design(145g) which designed for your next trip or adventure. Alongside its portable, compact design makes it easy to take with you on the go.
  • 【Full Gigabit Ports】Gigabit Wireless Internet Router with 2 Gigabit LAN ports and 1 Gigabit WAN ports, ideal for lots of internet plan and allow you to connect your wired devices directly.
  • 【Keep your Internet Safe】IPv6 supported. OpenVPN & WireGuard pre-installed, compatible with 30+ VPN service providers. Cloudflare encryption supported to protect the privacy.

There is no defensible, general accuracy percentage that applies to all countries, providers and traffic mixes. If an access decision matters, ask the vendor for methodology and error measurements relevant to your geography and use case, then validate the result against your own labeled traffic.

MaxMind explicitly cautions that “Many VPN users are privacy-conscious web users who are not necessarily engaged in any malicious activity.” A privacy tool should therefore increase scrutiny only when other signals justify it.

Why a site can infer location while a VPN is connected

VPN-IP classification and location inference answer different questions. A service may still receive or infer other signals:

  • DNS routing: DNS requests may use a resolver or route different from the VPN path.
  • Browser location permission: If a user grants permission, the browser can provide a location estimate from device services.
  • Cookies and cached data: Previous visits, account settings or stored geolocation can reveal a familiar region.
  • WebRTC: RFC 8828 describes conditional cases in which connectivity checks expose additional addresses. In a split-tunnel setup, WebRTC can reveal both a VPN public address and an ISP public address; STUN can also bypass a classical proxy when direct Internet access is allowed.
  • Device location services: Operating-system signals can be independent of the address used for HTTP.

These mechanisms do not all mean the site has successfully classified the public IP as a VPN. They should be logged and evaluated as separate evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
ASUS RT-AX1800S Dual Band WiFi 6 Extendable Router, Subscription-Free Network Security, Parental Control, Built-in VPN, AiMesh Compatible, Gaming & Streaming, Smart Home
  • New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
  • Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
  • Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
  • 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
  • Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.

Build a basic detector without unsafe proxy trust

The following Python service is a runnable demonstration. It classifies addresses against CIDR lists supplied in environment variables. In production, replace those lists with a licensed, maintained feed or API response; do not treat this small list as comprehensive.

Python example

import json, os
from http.server import BaseHTTPRequestHandler, HTTPServer
from ipaddress import ip_address, ip_network

VPN_NETS = [ip_network(x) for x in os.getenv("VPN_CIDRS", "").split(",") if x]
HOSTING_NETS = [ip_network(x) for x in os.getenv("HOSTING_CIDRS", "").split(",") if x]
TRUSTED_PROXIES = [ip_network(x) for x in os.getenv("TRUSTED_PROXY_CIDRS", "").split(",") if x]

def in_any(addr, nets):
    return any(addr in net for net in nets)

def source_ip(handler):
    peer = ip_address(handler.client_address[0])
    forwarded = handler.headers.get("X-Forwarded-For", "")
    # Accept forwarded data only when the immediate peer is your proxy.
    if forwarded and in_any(peer, TRUSTED_PROXIES):
        candidate = forwarded.split(",")[0].strip()
    else:
        candidate = str(peer)
    return ip_address(candidate)

class Handler(BaseHTTPRequestHandler):
    def do_GET(self):
        try:
            addr = source_ip(self)
            result = {
                "ip": str(addr),
                "vpn": in_any(addr, VPN_NETS),
                "hosting": in_any(addr, HOSTING_NETS)
            }
            body = json.dumps(result).encode()
            self.send_response(200)
        except ValueError:
            body = b'{"error":"invalid source address"}'
            self.send_response(400)
        self.send_header("Content-Type", "application/json")
        self.send_header("Content-Length", str(len(body)))
        self.end_headers(); self.wfile.write(body)

HTTPServer(("127.0.0.1", 8080), Handler).serve_forever()

Start it with, for example, VPN_CIDRS=203.0.113.0/24 TRUSTED_PROXY_CIDRS=127.0.0.1/32 python detector.py. The address ranges in that command are documentation examples, not a real provider list. Feed the service with current ranges from your chosen intelligence source and add independent fields such as proxy, Tor and residential-proxy results.

Test the endpoint with cURL

curl -i http://127.0.0.1:8080/

Call it from Python

import requests
r = requests.get("http://127.0.0.1:8080/", timeout=5)
r.raise_for_status()
print(r.json())

Call it from Node.js

const res = await fetch('http://127.0.0.1:8080/');
if (!res.ok) throw new Error(`HTTP ${res.status}`);
console.log(await res.json());

Choose an action instead of a blunt block

Situation Reasonable response
VPN or hosting flag only Allow normal access, or request a low-friction verification for sensitive actions.
VPN flag plus impossible travel, payment mismatch or repeated abuse Step up authentication, slow the action or send it to review.
Tor or public proxy on a high-value transaction Require stronger verification and explain the requirement clearly.
Known corporate or education egress Provide an appeal path; shared gateways can represent many legitimate users.

Keep the policy purpose-specific. A news site, a banking transfer and an account-recovery flow have different tolerances. Record the category and decision reason, not more personal data than necessary.

Common implementation failures and fixes

Every visitor appears to have the proxy’s address

Cause: Your application is reading the reverse proxy rather than the original client address. Fix: Configure the framework’s trusted-proxy setting and accept forwarded headers only from known proxy networks.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
GL.iNet GL-BE3600 Slate 7 Wi-Fi 7 Travel Router Touchscreen 2.5G
  • 【DUAL BAND WIFI 7 TRAVEL ROUTER】Products with US, UK, EU, AU Plug; Dual band network with wireless speed 688Mbps (2.4G)+2882Mbps (5G); Dual 2.5G Ethernet Ports (1x WAN and 1x LAN Port); USB 3.0 port.
  • 【NETWORK CONTROL WITH TOUCHSCREEN SIMPLICITY】Slate 7’s touchscreen interface lets you scan QR codes for quick Wi-Fi, monitor speed in real time, toggle VPN on/off, and switch providers directly on the display. Color-coded indicators provide instant network status updates for Ethernet, Tethering, Repeater, and Cellular modes, offering a seamless, user-friendly experience.
  • 【OpenWrt 23.05 FIRMWARE】The Slate 7 (GL-BE3600) is a high-performance Wi-Fi 7 travel router, built with OpenWrt 23.05 (Kernel 5.4.213) for maximum customization and advanced networking capabilities. With 512MB storage, total customization with open-source freedom and flexible installation of OpenWrt plugins.
  • 【VPN CLIENT & SERVER】OpenVPN and WireGuard are pre-installed, compatible with 30+ VPN service providers (active subscription required). Simply log in to your existing VPN account with our portable wifi device, and Slate 7 automatically encrypts all network traffic within the connected network. Max. VPN speed of 100 Mbps (OpenVPN); 540 Mbps (WireGuard). *Speed tests are conducted on a local network. Real-world speeds may differ depending on your network configuration.*
  • 【PERFECT PORTABLE WIFI ROUTER FOR TRAVEL】The Slate 7 is an ideal portable internet device perfect for international travel. With its mini size and travel-friendly features, the pocket Wi-Fi router is the perfect companion for travelers in need of a secure internet connectivity on the go in which includes hotels or cruise ships.

Users are blocked after switching VPN servers

Cause: The new exit range is classified as hosting or VPN infrastructure, or your rule treats any hosting result as a hard block. Fix: separate categories, use a challenge or review path, and refresh the provider data.

A known VPN is not detected

Cause: Coverage is incomplete, the provider rotates addresses, or the subnet is registered under a hosting company. Fix: treat a miss as possible, not exculpatory; combine the IP result with account and transaction context.

The site still shows the user’s home region

Cause: DNS, permissions, cookies, WebRTC or device-location signals are independent of the VPN exit IP. Fix: audit those channels separately and test split-tunnel and permission-granted configurations.

IPv4 works but IPv6 decisions differ

Cause: Your feed, parser or CIDR rules cover only one address family. Fix: normalize and test both IPv4 and IPv6, and verify that your provider supplies coverage for both.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
TP-Link Dual-Band AX3000 Wi-Fi 6 Wireless Gigabit Internet Router for Home
  • Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
  • A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
  • Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
  • Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
  • Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Performance, freshness and privacy

  • Latency: Cache lookups briefly by normalized IP when your policy allows it; a synchronous remote lookup on every request can slow page loads.
  • Availability: Decide what happens when the intelligence service times out. For low-risk pages, fail open; for a sensitive action, defer or step up verification rather than silently making a permanent block.
  • Freshness: Track the feed version or last-seen value so analysts can explain why a decision changed.
  • Data minimization: IP addresses can be personal data in some jurisdictions. Set retention limits, restrict access and document the purpose of the check.
  • Cost: Database licensing, API calls, storage and review operations all contribute to cost. Measure your request volume and cache hit rate before selecting an integration model.

Or skip the browser setup

If you need a visual record of a page that displays your detection result, ScreenshotNeo can capture it through one request. It accepts cookie and consent banners like a visitor, removes more than 60 known consent platforms, newsletter popups and chat widgets before the capture, and bills only clean shots. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed; response headers identify the page verdict and billing result. Its MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients.

Example (see the ScreenshotNeo API documentation):

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

There are 1,000 free shots per month with no card. Paid plans start at $5 for 3,000 shots; Growth is $15 for 15,000, Pro $39 for 60,000, Scale $99 for 250,000 and Business $249 for 1,000,000. Yearly billing gives two months free, and every feature is included on every plan. Create a free ScreenshotNeo account to try it.

FAQ

Can an IP lookup identify the exact VPN app?

Only when the intelligence provider supplies a provider or network name. Otherwise the result may be limited to a category such as hosting or anonymous proxy.

Should a VPN result be kept forever in an account profile?

No. It is a time-sensitive network observation. Retain only what your documented security purpose requires, with an expiration or recheck policy.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should I ask an IP-intelligence vendor before buying?

Ask which categories are returned, how provider coverage and freshness are represented, whether local database and API options exist, and for error measurements relevant to your traffic and geography.

Frequently Asked Questions

Can an IP lookup identify the exact VPN app?

Only when the intelligence provider supplies a provider or network name; otherwise it may return only a category such as hosting or anonymous proxy.

Should a VPN result be kept forever in an account profile?

No. Treat it as a time-sensitive network observation and apply an expiration or recheck policy.

What should I ask an IP-intelligence vendor before buying?

Ask about returned categories, coverage and freshness indicators, local-database versus API integration, and error measurements for your traffic and geography.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.