Guide · fraud prevention

Detect VPN, proxy and Tor users

VPN detection is a signal, not a verdict. How it works and how to use it without locking out legitimate privacy-conscious users.

Updated October 1, 2026 · 1 min read

How detection works

An IP address is flagged by combining several signals:

What to do with a flagged user

SignalTypical response
Tor exit nodeChallenge or block sensitive actions
Commercial VPNAsk for email or phone verification
Data centerTreat as likely bot: CAPTCHA, rate limits
iCloud Private RelayUsually allow; it is a mainstream Apple feature
Known attacker / abuserBlock or require strong verification

Adding it to a sign-up form

async function riskCheck(ip) {
  const res = await fetch(`https://api.ipbase.com/v2/info?ip=${ip}&fields=security`, {
    headers: { apikey: process.env.IPBASE_KEY },
  });
  const { data } = await res.json();
  const s = data.security;
  if (s.is_tor || s.is_known_attacker) return "block";
  if (s.is_vpn || s.is_proxy || s.is_datacenter || s.threat_score >= 50) return "verify";
  return "allow";
}

Try any address in the free VPN and proxy checker.

Frequently asked questions

Can you detect every VPN?

No. Commercial VPNs use known data-center addresses and are detected reliably; residential proxies and self-hosted VPNs on home connections are much harder.

Is it legal to block VPN users?

Generally yes, websites may decide whom to serve. Make sure your privacy policy covers the IP lookup, and avoid blocking people who rely on VPNs for safety where you can offer an alternative check.

IP geolocation API

Get this data in your app

ipbase returns location, ISP, ASN, time zone and security flags (VPN, proxy, Tor, data center) for any IPv4 or IPv6 address, up to 100 addresses per request.

150 free requests every month. No credit card required.

GET https://api.ipbase.com/v2/info?ip=1.1.1.1

{
  "data": {
    "ip": "1.1.1.1",
    "type": "v4",
    "connection": {
      "asn": 13335,
      "organization": "APNIC and Cloudflare DNS Resolver project",
      "isp": "Cloudflare, Inc",
      "range": "1.1.1.0/24"
    },
    "location": {
      "country": { "alpha2": "AU", "name": "Australia" },
      "zip": "4000"
    },
    "security": { "is_vpn": false, "is_tor": false, "threat_score": 0 }
  }
}

Keep reading

Start using the IP Geolocation API for free today!

Get 150 requests / month for free