How detection works
An IP address is flagged by combining several signals:
- Known VPN, proxy and Tor exit lists, maintained continuously
- Hosting and data-center ranges: real users rarely browse from AWS or DigitalOcean (see the cloud IP ranges)
- Privacy relays such as iCloud Private Relay, which are legitimate but hide the real address
- Abuse history: addresses seen in attacks, spam or credential stuffing
What to do with a flagged user
| Signal | Typical response |
|---|---|
| Tor exit node | Challenge or block sensitive actions |
| Commercial VPN | Ask for email or phone verification |
| Data center | Treat as likely bot: CAPTCHA, rate limits |
| iCloud Private Relay | Usually allow; it is a mainstream Apple feature |
| Known attacker / abuser | Block or require strong verification |
Adding it to a sign-up form
async function riskCheck(ip) {
const res = await fetch(`https://api.ipbase.com/v2/info?ip=${ip}&fields=security`, {
headers: { apikey: process.env.IPBASE_KEY },
});
const { data } = await res.json();
const s = data.security;
if (s.is_tor || s.is_known_attacker) return "block";
if (s.is_vpn || s.is_proxy || s.is_datacenter || s.threat_score >= 50) return "verify";
return "allow";
}
Try any address in the free VPN and proxy checker.