PublicIPChecker

Guide

How websites detect VPNs and proxies

6 min read · Updated 2026-09-28

The layered detection: registry ownership, curated IP lists, behavioural signals, protocol fingerprints — and the leaks that give VPN users away even when the IP looks clean.

The core signals

Detection is layered, and the first layer is the cheapest: registry ownership. Every IP block's registration names its owning organisation and ASN — and VPN exit servers live in datacenter blocks. One database lookup separates "residential ISP" from "hosting company" with near certainty. Everything else refines the answer.

Curated IP lists and their limits

On top of ownership, sites query curated lists of known VPN, proxy and Tor exit addresses, updated daily by commercial vendors and open projects. The weakness is lag: a brand-new VPN endpoint may take days to be listed, and free/obscure proxies sometimes never appear at all. So list checks are necessary but not sufficient — which is why the other layers exist.

Behavioural tells

  • Shared endpoints — hundreds of different "users" from one address in an hour is a fingerprint no residential connection produces.
  • Geo mismatch — the IP says Germany, the payment card says Brazil, the language header says neither. Risk engines combine these.
  • Impossible travel — the same account from Tokyo and Toronto within minutes.
  • Traffic shape — request rates, scanning patterns, and the TLS fingerprint of common tunnel clients are all readable to a determined detector.

The leaks that undo a good IP

Sometimes the IP is fine and something else gives the real one away:

  • IPv6 — the tunnel carries v4, the real v6 walks out in the clear. Check both rows on the checker.
  • WebRTC — the browser can expose the local and real public IP to any page (WebRTC leaks).
  • DNS — queries going to the ISP's resolvers instead of the VPN's reveal the domains you visit (DNS leaks).

The full four-point test is in how to check if your VPN actually works.

Test your own setup

  1. Run the checker without the VPN — note IP, ISP, ASN, country.
  2. Connect the VPN and reload — all four must differ.
  3. Check the IPv6 row (VPN address or "not available", never your ISP's prefix).
  4. Run the built-in WebRTC test — expect "No leak detected".

If any step fails, you are detectable — not by magic, but by the exact mechanisms above.

Frequently asked questions

Can a VPN ever be 100% undetectable?

In practice, no — detection is probabilistic and layered. A good setup makes detection expensive; a careless one is identifiable in a single lookup.

Do all websites detect VPNs?

No. Banks, CDNs, streaming and payment systems run heavy detection; most small sites and blogs do not check at all.

Why does my VPN work on some sites but not others?

Different risk models, different thresholds, and per-exit-IP reputations. The same connection that streams fine elsewhere can be a CAPTCHA farm on a stricter site.


Keep reading

Check any other IP address

Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.