Run an IP VPN check on any address to detect commercial and residential VPN connections. Identify the provider, track when VPN activity was last observed, and protect your platform from anonymous traffic.
IP Trust VPN detection checks whether an IP belongs to a known VPN service, which provider operates it, and when VPN activity was last observed.
| JSON Field | Description | Plans |
|---|---|---|
| { | ||
| "vpn": { | ||
| "detected": true, | Whether this IP has been identified as part of a VPN service. | Premium |
| "provider": "nord_vpn", | optional Identifier of the VPN provider, if known. | Premium |
| "last_detected": "2025-11-15" | optional Date (ISO 8601) when VPN activity was last observed for this IP. | Premium |
| } | ||
| } |
| Field | Value | Description | Database Package |
|---|---|---|---|
| vpn | true | Whether this IP has been identified as part of a VPN service. | Anonymisation |
| vpn_provider | nord_vpn | Identifier of the VPN provider, if known. | Anonymisation |
| vpn_last_detected | 2025-11-15 | Date (ISO 8601) when VPN activity was last observed for this IP. | Anonymisation |
Identify users hiding behind VPN services to prevent fraud, enforce access policies, and improve risk assessment.
Flag or challenge transactions from VPN connections where the apparent location doesn't match expected patterns. Add VPN detection as a signal in your fraud scoring models to catch account takeovers and payment fraud.
Detect users bypassing geographic content restrictions with VPN services. Enforce licensing agreements and regional access controls even when users attempt to mask their true location.
Apply stricter authentication requirements for VPN users, such as additional verification steps or MFA challenges. Reduce risk without blocking legitimate users outright.
IP Trust sources entry and exit nodes IPs from top VPNs as well as scoring ASNs to identify networks that host a high concentration of VPN traffic.
We collect VPN endpoint data directly from 10+ of the largest commercial VPN providers. By scanning both entry and exit node IPs on a regular basis, we maintain an accurate and up-to-date picture of the VPN landscape.
Beyond individual IP scanning, we also identify ASNs that host a high percentage of VPN traffic. This gives you extra coverage for detecting VPN usage even when specific endpoint IPs rotate or change.
When we detect a VPN connection, we identify the specific provider wherever possible. This lets you make nuanced decisions based on the type of VPN rather than treating all VPN traffic the same.
Choose the integration model that works best for your use case.
| Network | VPN | VPN Provider | VPN Last Detected |
|---|---|---|---|
| 185.159.156.28/32 | true | protonvpn | 2026-02-24 |
| 89.187.162.0/24 | true | nord_vpn | 2026-02-20 |
| 198.54.131.0/24 | true | surfshark | 2026-02-22 |
| 2.36.214.116/32 | false | ||
| 104.16.54.163/32 | false |
IP Trust collects VPN endpoint data directly from 12 of the largest commercial VPN providers by regularly scanning both entry and exit node IPs. We also analyse ASN-level traffic patterns to identify networks that host a high concentration of VPN traffic. When you run an IP VPN check, we match the address against this continuously updated dataset.
Each IP VPN check returns whether a VPN was detected, the name of the VPN provider (when identifiable), and the date VPN activity was last observed on that IP. This lets you make nuanced decisions - for example, treating a recently active NordVPN exit node differently from an IP with no VPN history.
IP Trust actively scans endpoints from 12 major commercial VPN providers including NordVPN, ProtonVPN, Surfshark, and others. Beyond individual provider scanning, ASN-level analysis provides additional VPN detection coverage for smaller or less well-known services.
Yes. VPN detection is included in the Anonymisation database package, which is available for download in MMDB, CSV, JSON, and Parquet formats. Once downloaded, you can perform IP VPN checks locally on your own infrastructure with zero external calls and unlimited volume. See our database downloads page for details.
VPN detection identifies connections through commercial VPN services like NordVPN or Surfshark, while proxy detection covers open internet proxies and residential proxy networks. An IP can be flagged for both. IP Trust provides separate detection for VPNs, proxies, and Tor as part of its anonymisation data, giving you granular control over how you handle each type of anonymous traffic.