Skip to main content

VPN & Proxy Detector

Check whether an IP address belongs to a VPN, proxy, Tor exit node, private relay or hosting provider, with a plain explanation of each signal.

Enter a public IP address to check whether it belongs to a VPN, proxy, Tor exit or hosting provider.

A positive result means the address belongs to a service that anonymises traffic. It says nothing about the person using it — VPNs are ordinary privacy tools, and treating a match as proof of wrongdoing is a mistake.

This tool queries an external service to answer your request. Only the value you enter — such as a domain or IP address — is sent. Your other data stays on your device.

This tool reads public records — DNS, WHOIS and certificate data that registries and servers publish openly. It sends nothing to the host you enter and changes nothing there. Use it on infrastructure you own or are authorised to look into.

About the VPN & Proxy Detector

Check whether an IP address belongs to a service that anonymises traffic — a commercial VPN, an open or residential proxy, a Tor exit node, a private relay, or a hosting provider. Each signal is reported separately with an explanation of what it actually means, rather than collapsed into a single number you have to take on trust.

A positive result is a fact about the network, not a verdict about the person. This is worth stating plainly because the whole category of tool invites the opposite reading. VPNs are ordinary software used by tens of millions of people: remote workers connecting to an office, travellers on hotel wifi, journalists and researchers, and anyone who simply does not want their ISP building a profile of their browsing. Apple ships a private relay to every iCloud subscriber. Treating any of that as evidence of wrongdoing means blocking a great many entirely legitimate customers, and the people genuinely committing fraud are the ones most likely to be using an anonymiser your detector has never heard of.

The signals are genuinely not equal, and the difference is the useful part. A commercial VPN or a private relay is mainstream consumer privacy tooling and correlates weakly, if at all, with abuse. A residential proxy is a different matter: it routes traffic through somebody's home connection, frequently without their informed consent, and it is a tool with few uses beyond evading exactly this kind of detection. Known attacker means the address has recently been observed scanning or brute-forcing. Those last two deserve weight; the first two rarely do on their own.

Used well, this is one input among several. It is at its best answering "why is this login coming from a data centre in a country where this customer has never been", and at its worst used as a single automated reason to refuse someone. If you want location and network context alongside these flags, the IP Reputation Report returns both in one lookup.

How to use the VPN & Proxy Detector

  1. Enter the address

    Type any public IPv4 or IPv6 address. A port or CIDR suffix copied from a log is stripped automatically.

  2. Run the check

    Complete the verification check and press Check address. Signals are fetched live rather than from a cached score.

  3. Read the individual signals

    Each detected flag is listed separately with what it means. The overall score is a summary, not the evidence — the flags are the evidence.

  4. Weigh them properly

    Residential proxy and known attacker are strong signals. Commercial VPN and private relay are weak ones on their own, because ordinary people use both every day.

Frequently asked questions

Should I block every visitor using a VPN?

Almost certainly not. VPN use is mainstream — remote workers, travellers on public wifi, privacy-conscious people, and every iCloud subscriber with Private Relay enabled. Blocking on a VPN flag alone means turning away a substantial fraction of ordinary customers, while determined fraudsters simply move to a residential proxy that your detector will not flag. VPN detection is useful as one signal among several, weighted lightly, and rarely as an automatic refusal.

What is a residential proxy, and why does it matter more?

It routes traffic through a real home internet connection, so it looks exactly like an ordinary residential visitor. The addresses usually come from people who installed a free app or VPN that quietly resells their bandwidth, often without any meaningful consent. Because it exists specifically to defeat the detection that catches data-centre and VPN traffic, a residential proxy flag carries far more weight than a commercial VPN flag does.

The result says my own address is a VPN, but it is not. Why?

Address blocks change hands, and these databases lag. A range that hosted a VPN two years ago can be reassigned to a residential ISP while the old classification persists. Mobile carriers using carrier-grade NAT are also frequently misclassified, because thousands of subscribers share one address and the aggregate traffic pattern looks like a proxy. If it matters commercially, most providers accept correction requests.

Does a clean result mean the visitor is definitely not using a VPN?

No. Detection works from known address ranges, and new VPN endpoints, self-hosted servers and freshly rotated residential proxies appear faster than any database tracks them. Anyone who runs their own VPN on a cheap virtual server will show as a hosting provider at most, and often as nothing at all. A clean result means nothing was recognised, which is weaker than nothing being there.

What does the threat score actually represent?

It is the provider's own summary of the individual flags, from 0 to 100, and it is a convenience rather than evidence. We show the flags beneath it precisely because the score compresses several very different findings into one number — an address flagged only as a cloud provider and one flagged as a known attacker can land closer together than their real difference in risk justifies. Read the flags.

Is checking an IP address here legal and private?

Yes. IP addresses and their network classifications are public infrastructure data, not personal records. The address you enter is sent to the lookup service and is not written to our database or our logs — we count that a check happened, with no record of which address, who asked, or what the answer was.