Networking · Network & IP
How VPN detection actually works
VPN detection looks easy from the outside — you paste an IP and get a yes/no answer. Behind the scenes, the tool queries VPN provider IP lists, checks ASN ownership, and cross-references commercial databases that specialize in connection-type classification. The accuracy is high but not perfect, and the failure modes are interesting.
TL;DR
Services identify VPN traffic using IP ranges, ASN lookups, and known relay lists. Here is the data they correlate and how accurate the check really is.
The three sources a detector consults
First, public IP lists maintained by VPN providers (Mullvad, ProtonVPN, NordVPN all publish their ranges). Second, commercial databases that track anonymous traffic (IP2Proxy, IPinfo, MaxMind's anonymous IP flag). Third, ASN ownership — if the IP belongs to a known hosting provider and not a residential ISP, it is more likely to be a VPN endpoint, even if the exact provider is not on any list.
What the detector cannot see
It cannot see whether a user is actually using a VPN. If a user is on a residential IP with no commercial database hit, the detector says "not a VPN" even if they are. The check is connection-type inference, not wire-level inspection. Encrypted VPN protocols (WireGuard, OpenVPN) look identical to HTTPS to a network observer. Only the destination IP reveals a VPN — and only if the destination is on a known VPN range.
Tor and proxy detection
Tor exits are published every hour by the Tor project, so any IP on the exit list is detectable. Public HTTP proxies are tracked similarly — there are crowdsourced lists of open proxies that anyone can query. The hard part is private or self-hosted proxies; those are essentially invisible to a reputation check, because the IP belongs to a residential range and is not on any list.
When detection is wrong
False positives happen when a residential IP was previously used as a VPN (the database takes time to update) or when an IP belongs to a small hosting provider that has been incorrectly flagged. False negatives happen with self-hosted VPNs, corporate proxies, or any IP not on a public list. The check is a strong signal but not a guarantee.
Try it →
Run the VPN detector tool on sitetrace.it.com — paste a value and get an instant answer.
Open VPN detector