VPN detection is a lookup against known infrastructure, not an inspection of your traffic. Nobody can read an encrypted tunnel from the outside. What a detection service can do is recognise the address on the far end of that tunnel.
Four signals decide the verdict:
Range ownership. Commercial VPN providers lease blocks of addresses and route customer traffic through them. Once a block is mapped to a provider, every address in it is identifiable. This is what produces a provider name in the result.
Network type. The ASN behind an address is classified as HOSTING, ISP, or BUSINESS. Residential broadband sits on ISP networks. A consumer-looking connection arriving from a HOSTING ASN is a server, and servers do not browse.
Tor consensus. The Tor project publishes its exit node list openly. Matching against it is exact, which is why Tor is reported as its own category rather than folded into the proxy count.
Behavioural and abuse history. Addresses that appear across spam feeds, brute-force logs, and scanner traffic carry that history forward into the threat score, independent of whether they are anonymised. The full blacklist and abuse breakdown for any address is on the IP Reputation Check.
Through the IP Reputation API, each VPN and proxy match also carries a confidence score from 0 to 100 and a last-seen date, so you can tell an address observed on a VPN network yesterday from one last seen there months ago. WhoisFreaks rebuilds this classification every 24 hours.
Feature: Flag VPN, proxy, residential proxy, Tor exit, corporate gateway, and datacenter traffic in one lookup
Feature: Identify the provider name for commercial VPNs and anonymizer ranges to separate real privacy tools from masking infrastructure
Feature: Use network classification and threat history together to score transactions, logins, and account creation requests more accurately
Feature: Support fraud prevention, moderation, licensing checks, and user-connection verification with fast IP-level detection
For automated checks in application logic, onboarding flows, and abuse triage, the IP Reputation API returns the verdict, provider, confidence score, and last-seen signal in structured JSON.
The same lookup answers two very different questions: is my own connection doing what I expect, and should I trust this visitor.
Turn a VPN on and the first question is whether it took effect. Load this page with the VPN running: if your provider's name appears, traffic is going through the tunnel. If your home ISP appears instead, it is not. Same check after a reconnect, a client update, or a kill-switch test.
Signup and checkout traffic arriving from anonymizers correlates with chargebacks, multi-account abuse, and bonus farming. Most teams do not block outright. They score, then step up verification above a threshold. The threat_score field is built for exactly that: set one number rather than maintaining rules across a dozen flags. Automate it with the IP Reputation API.
Ban evasion runs on cheap VPNs and proxies. Checking a new account's address against known anonymizer ranges is the fastest way to tell a returning banned user from a genuinely new one.
Content rights are sold by territory, and enforcing them means identifying viewers whose location comes from a VPN exit rather than their actual connection. VPN, residential proxy, and datacenter classification is the control that keeps a licensing agreement enforceable. Platforms screening every session usually load the IP Security Database into their own stack instead of calling out per viewer.
Per-IP lookups suit inline decisions. Screening millions of addresses, backfilling historical logs, or running detection with no outbound call is a different job.
The IP Security Database ships the same classification as a daily snapshot in gzipped CSV, generated at 5 AM UTC for the previous day: VPN and proxy ranges with provider names, Tor exit nodes, cloud and datacenter ranges, spam and known-attacker addresses, and the threat score for each. A status endpoint tells you when the day's snapshot is ready.