Guide
How websites detect VPNs and proxies
The layered detection: registry ownership, curated IP lists, behavioural signals, protocol fingerprints — and the leaks that give VPN users away even when the IP looks clean.
On this page
The core signals
Detection is layered, and the first layer is the cheapest: registry ownership. Every IP block's registration names its owning organisation and ASN — and VPN exit servers live in datacenter blocks. One database lookup separates "residential ISP" from "hosting company" with near certainty. Everything else refines the answer.
Curated IP lists and their limits
On top of ownership, sites query curated lists of known VPN, proxy and Tor exit addresses, updated daily by commercial vendors and open projects. The weakness is lag: a brand-new VPN endpoint may take days to be listed, and free/obscure proxies sometimes never appear at all. So list checks are necessary but not sufficient — which is why the other layers exist.
Behavioural tells
- Shared endpoints — hundreds of different "users" from one address in an hour is a fingerprint no residential connection produces.
- Geo mismatch — the IP says Germany, the payment card says Brazil, the language header says neither. Risk engines combine these.
- Impossible travel — the same account from Tokyo and Toronto within minutes.
- Traffic shape — request rates, scanning patterns, and the TLS fingerprint of common tunnel clients are all readable to a determined detector.
The leaks that undo a good IP
Sometimes the IP is fine and something else gives the real one away:
- IPv6 — the tunnel carries v4, the real v6 walks out in the clear. Check both rows on the checker.
- WebRTC — the browser can expose the local and real public IP to any page (WebRTC leaks).
- DNS — queries going to the ISP's resolvers instead of the VPN's reveal the domains you visit (DNS leaks).
The full four-point test is in how to check if your VPN actually works.
Test your own setup
- Run the checker without the VPN — note IP, ISP, ASN, country.
- Connect the VPN and reload — all four must differ.
- Check the IPv6 row (VPN address or "not available", never your ISP's prefix).
- Run the built-in WebRTC test — expect "No leak detected".
If any step fails, you are detectable — not by magic, but by the exact mechanisms above.
Frequently asked questions
Can a VPN ever be 100% undetectable?
In practice, no — detection is probabilistic and layered. A good setup makes detection expensive; a careless one is identifiable in a single lookup.
Do all websites detect VPNs?
No. Banks, CDNs, streaming and payment systems run heavy detection; most small sites and blogs do not check at all.
Why does my VPN work on some sites but not others?
Different risk models, different thresholds, and per-exit-IP reputations. The same connection that streams fine elsewhere can be a CAPTCHA farm on a stricter site.
Keep reading
- What is an IP address?
- Public vs private IP addresses
- IPv4 vs IPv6
- How to hide your IP address
- How to check your IP address on a phone
- What is CGNAT?
- How to change your IP address
- Why does my IP address keep changing?
- How to find a website's IP address
- What is a datacenter IP?
- IPv6 privacy extensions
- What is an ASN?
- How IP geolocation works
- What is a local IP address?
- Why am I getting blocked or stuck on CAPTCHAs?
- What is IP reputation?
- What is a DNS leak?
- What is a WebRTC leak?
- Proxy vs VPN
- How to check if your VPN actually works
- Static vs dynamic public IP
- How to find out who owns an IP address
- IPv6 in 2026
- Check my public IP address
Check any other IP address
Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.