Skip to content
Crafzo
Menu

VPN, proxy and Tor detection

How to Tell if an IP Address Is a VPN or Real User (Checklist)

A checklist of signals that help identify whether traffic is coming from a VPN, proxy, or genuine consumer ISP connection.

Updated
Reading time
2 min read

Checklist: provider and ASN clues

Check the ISP or organization name first. Consumer broadband and mobile carriers usually look different from hosting providers, cloud networks, VPN brands, privacy services, and companies that operate large data center ranges.

Review the ASN and network owner next. A residential-looking IP in a normal consumer ASN is less suspicious than an address announced by a cloud provider, proxy operator, or infrastructure company used for automation.

Checklist: risk and behavior clues

Compare proxy flags, fraud score, abuse history, country mismatch, and whether the IP appears in known VPN or data center ranges. A single flag is helpful, but multiple matching signals are much stronger.

Look at behavior before enforcement: request velocity, login failures, signup bursts, payment attempts, endpoint mix, and account age. Real users can use VPNs, while attackers can sometimes use residential networks.

Checklist: decision path

For low-risk browsing, log the signal and keep the user moving. For account recovery, checkout, admin actions, or repeated automation, require MFA, throttle requests, or route the session to review.

Use Crafzo to inspect the IP quickly, then compare the visible network with your own logs. The goal is to decide whether the session needs more proof, not to punish privacy tools automatically.

Frequently asked questions

Keep reading