Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The reliable way to tell whether an IP address uses a proxy is to check it against maintained IP-intelligence data. A lookup can classify an address as a VPN, hosting or data-center range, public proxy, residential proxy, or Tor exit node. That result describes the network presenting the address—not the person behind it—and it cannot recover the user’s original IP.

Use a single lookup for an investigation, or an API, downloadable database, or managed security list when you screen traffic continuously. Treat every classification as a signal whose freshness, confidence, coverage, and false-positive cost must be considered.

What “proxy detection” actually checks

Your server normally sees the source IP of the connection that reaches it. An anonymizing intermediary can make that address belong to a VPN gateway, proxy server, cloud host, or Tor relay instead of the user’s access network. A proxy check compares the observed address with records of known or inferred anonymizer networks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The result may include several independent attributes:

  • VPN: an address associated with a virtual private-network service.
  • Hosting provider: a cloud or data-center range commonly used for servers, automation, or VPN infrastructure.
  • Public proxy: an openly reachable forwarding service.
  • Residential proxy: an address that appears to belong to a consumer ISP but is offered as an intermediary.
  • Tor exit node: an address currently or recently observed as the exit point of the Tor network.
  • Anonymous IP: a broad flag indicating that the address is likely masking the origin.

These categories overlap. A VPN may be detected through hosting-provider data when its range is not registered under the VPN company’s name. The field names and definitions differ by provider, so read the provider’s documentation before mapping a result to a business rule.

Fastest method: perform a one-address lookup

  1. Capture the exact address. Preserve whether it is IPv4 or IPv6; do not truncate or normalize it incorrectly. Record the timestamp and the event that produced it.
  2. Choose a lookup that states its categories. A useful service should say whether it detects VPNs, hosting, public proxies, residential proxies, and Tor, rather than returning only an unexplained “risk” score.
  3. Submit the address and save the raw response. Keep the provider name, category fields, confidence or last-seen value (if supplied), and database date. This makes later review possible when classifications change.
  4. Interpret the result as evidence, not identity. A positive flag does not reveal the user’s original address, device, account, or intent.

For a one-off investigation, a reputable web lookup is usually sufficient. Do not paste sensitive internal addresses into an untrusted site; use a contracted API or local database when confidentiality matters.

How to read common results

VPN or hosting-provider flag

This usually means the address belongs to infrastructure associated with a VPN, cloud host, or data center. It may be shared by many unrelated users. Blocking every hosting address can reject legitimate corporate networks, accessibility tools, monitoring systems, and developers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Public-proxy flag

An open proxy can be unstable, abused, or short-lived. A flag is useful for triage, but verify its recency before denying a request. A stale record may describe a service that no longer operates at that address.

Residential-proxy flag

Residential proxies are harder to classify because their addresses can look like ordinary consumer-ISP connections. Addresses may rotate frequently. A confidence value or network-last-seen field is especially useful here; a weak or old signal should lead to a challenge or review rather than an automatic block.

Rank #2

Tor exit-node flag

The flag identifies the exit relay visible to your service, not the Tor user. Tor users can have legitimate privacy or safety reasons, so apply the least restrictive control that meets your threat model.

No flag

“Not detected” means the provider has no current matching evidence. It does not prove that the connection is direct. New, private, misclassified, or rapidly changing proxies can be absent from a database.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a positive result cannot tell you

  • It cannot recover the original IP. The intermediary intentionally hides it.
  • It cannot prove malicious intent. Privacy-conscious people, businesses, researchers, and travelers also use anonymizers.
  • It cannot establish physical location. Geolocation generally describes the intermediary’s host. A VPN endpoint may appear in the country where its data center is located, not where the user is.
  • It cannot reliably identify a person. Addresses can be shared, reassigned, translated through carrier-grade NAT, or used by many customers.

Other privacy systems, including Apple iCloud Private Relay, can also change what an IP-based check can infer. Combine the IP signal with account history, device and session context, rate limits, and behavior only when your legal and privacy obligations permit it.

Screening traffic programmatically

API lookup

An API is appropriate when each request must be evaluated during login, checkout, account creation, or abuse analysis. Store the response fields you actually use, the provider’s data version or timestamp, and your decision. Set a short timeout and define a fail-open or fail-closed policy before deployment: an unavailable intelligence service should not create an accidental outage.

Downloadable database

A local database avoids a network round trip and can support high request volume. MaxMind describes daily updates and IPv4/IPv6 coverage for its Anonymous IP database. Schedule updates, verify the downloaded file, and retain the previous known-good copy so a failed update does not remove protection.

Managed security list

A managed list can feed a firewall or edge rule without building your own lookup pipeline. Cloudflare documents managed lists for known open proxies, anonymizers, and VPNs. Confirm the list’s update behavior and whether your product edition supports the required rule action.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to choose a data source

Compare providers on the dimensions below; no single field guarantees accurate classification.

Criterion Questions to ask Why it matters
Categories Are VPN, hosting, public, residential, and Tor separated? Different risks require different responses.
Recency and confidence Is there a last-seen date, confidence score, or evidence age? Fresh, high-confidence signals deserve more weight.
Coverage Are both IPv4 and IPv6 covered? How often are records refreshed? IPv6-only visitors and changing proxy ranges otherwise escape detection.
Integration Is there a web lookup, API, database, or managed list? Choose the operating model that fits latency and volume.
False-positive cost Will a match block access, trigger a challenge, or only alert? The same signal has different consequences for login, fraud, and analytics.

MaxMind documents fields such as is_anonymous, is_anonymous_vpn, is_hosting_provider, is_public_proxy, is_residential_proxy, and is_tor_exit_node. IPinfo documents privacy-detection API and database options. Product specifications and coverage can change, so verify current documentation before implementation.

Designing a decision policy

Allow

Use when the action is low risk or the signal is weak, stale, or unconfirmed. Continue monitoring rather than silently denying a legitimate visitor.

Challenge

Require stronger authentication, email verification, rate limits, or an additional fraud check when the address is a high-confidence anonymizer but the account or transaction is otherwise plausible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review

Queue high-value actions for manual review when several independent signals agree. Preserve the evidence and decision reason so an analyst can reverse an error.

Block

Reserve automatic denial for narrowly defined, high-confidence abuse patterns. Document an appeal path and avoid blocking entire countries, ISPs, or hosting providers solely because one address was classified as a proxy.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting inaccurate or confusing results

The lookup says “VPN,” but the user says they are not using one

Check whether the address belongs to a corporate gateway, cloud-hosted browser, mobile carrier NAT, or security product. Compare the last-seen and confidence fields, then corroborate with account and session evidence.

The address changes between requests

Mobile networks, rotating residential proxies, Tor, and VPN pools can change egress addresses. Evaluate a short-lived session identifier and behavior, not IP equality alone.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An IPv6 address is not classified

Confirm that the source covers IPv6 and that your application passes the complete address. If IPv6 coverage is absent, treat “not detected” as unknown rather than clean.

A known proxy is not flagged

Check the database update time, whether the service distinguishes residential proxies, and whether the address was recently reassigned. Submit current evidence to the provider if its correction process allows it.

Blocking causes legitimate users to fail

Change the action from block to challenge, narrow the rule to a category or confidence threshold, and measure appeals and successful challenges. Reassess the policy whenever the provider changes its data or your abuse pattern changes.

Or skip the browser setup

If you need a clean visual record of a public lookup or documentation page, ScreenshotNeo provides a website screenshot API. It is not an IP-intelligence database; it captures the page after handling common consent and clutter elements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

One GET request returns an image or PDF:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for options and adapt the target URL to the page you are allowed to capture. The same request in Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Cookie banners, popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed. An MCP server lets AI agents take screenshots. The Free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

Privacy, logging, and governance

IP addresses can be personal data. Publish the purpose and retention period for proxy screening, restrict raw-address access, encrypt stored responses, and document automated decisions. Keep only the fields needed for the stated purpose. Revisit retention and regional obligations with your privacy counsel, especially when an external provider receives visitor addresses.

Frequently Asked Questions

Does detecting a proxy reveal the user’s real IP address?

No. It classifies the address visible to your service and cannot recover an address hidden by the intermediary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should every detected proxy be blocked?

No. Use confidence, recency, context, and the cost of false positives; a challenge or review is often safer than an automatic denial.

Can proxy detection determine a user’s exact location?

No. Geolocation usually describes the intermediary’s host, such as a VPN data center, rather than the end user.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.